AZ-400 Develop a security and compliance plan Practice Question
Which TWO practices should you follow to ensure compliance with regulatory requirements (e.g., PCI DSS) when using Azure DevOps? (Choose two.)
⚠ Common exam trap
Test-takers frequently confuse 'audit logging' with a cost-saving measure (Option D) or think manual tracking (Option A) is acceptable, while the exam expects you to recognize that automated, immutable audit trails and enforced branch policies are the only reliable ways to meet regulatory compliance in a DevOps context.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Azure DevOps audit logging to track changes to pipelines and policies.
Option C is correct because enabling Azure DevOps audit logging captures a tamper-evident trail of events such as pipeline modifications, policy changes, permission updates, and user access, which is essential for demonstrating compliance with regulatory frameworks like PCI DSS that require monitoring and traceability of changes to systems handling cardholder data. Option E is correct because branch policies enforce mandatory code reviews, minimum approver counts, and build validation before changes merge, providing the segregation of duties and change-control evidence that PCI DSS requires for modifications to production pipelines and code. Option A is not appropriate because manually tracking pipeline changes in a spreadsheet is error-prone, unauditable, and lacks the integrity and automation of native Azure DevOps audit logs. Option B is incorrect because unrestricted pipeline creation and modification violates the principle of least privilege and PCI DSS change-control requirements. Option D is incorrect because disabling audit logging removes the very evidence needed for compliance and directly contradicts regulatory monitoring obligations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Manually track changes to pipelines in a spreadsheet.
Why it's wrong here
Spreadsheets are not tamper-evident and cannot generate the immutable audit trail PCI DSS requires; Azure DevOps already logs pipeline changes natively. Manual tracking is tempting for small teams documenting approvals, but it fails the automated, verifiable evidence regulators demand.
- ✗
Allow all users to create and modify pipelines without restrictions.
Why it's wrong here
Unrestricted pipeline creation lets any contributor alter build and release definitions, so a single commit could inject code that bypasses PCI DSS change-control and segregation-of-duties evidence. It is tempting because frictionless self-service pipelines suit fast-moving internal teams with no audit scope, where every engineer already holds production rights.
- ✓
Enable Azure DevOps audit logging to track changes to pipelines and policies.
Why this is correct
Audit logging records every change to pipelines, policies and permissions, producing the tamper-evident trail PCI DSS requires for accountability and forensic review. It satisfies the stem's regulatory compliance constraint by evidencing who altered build definitions and when, which access reviews and branch policies alone cannot demonstrate.
- ✗
Disable audit logging to reduce storage costs.
Why it's wrong here
Disabling audit logging removes the evidence trail PCI DSS mandates for change tracking and access monitoring, directly violating requirements. Cost-saving appeals to teams with tight budgets, yet logging is precisely what compliance frameworks require retained and reviewable.
- ✓
Use branch policies to enforce code reviews and approvals for all changes.
Why this is correct
Branch policies enforce mandatory reviewer approval before code merges, creating an auditable segregation-of-duties control that PCI DSS change-management requirements demand. Every pull request records who approved what and when, producing the tamper-evident trail auditors expect. This directly satisfies the stem's regulatory compliance constraint by preventing unreviewed changes reaching production.
Go deeper
Related to this question
Learn chapter
Implementing a Build Pipeline
Key term
Pipeline
A pipeline is an automated series of steps that takes code from development to production, ensuring quality and speed.
Key term
Branch
A branch is a pointer to a specific commit in a version control system that allows you to work on features or fixes in isolation from the main codebase.
About these practice questions
This AZ-400 question is part of Courseiva's 696-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.