Courseiva

AZ-400 Develop a security and compliance plan Practice Question

You are a DevOps engineer at a company that uses Azure DevOps. The security team requires that all code commits to the main branch are signed and verified. You need to enforce this using branch policies. Which policy should you configure?

⚠ Common exam trap

A common mix-up: candidates confuse commit signing with other branch policies that provide security, such as required reviewers or linked work items, but these do not verify signatures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Require signed commits.

The 'Require signed commits' branch policy is the only policy that enforces cryptographic signing of commits. It ensures that every commit to the protected branch is signed and verified, providing authenticity and integrity. Other policies focus on review, work item linking, or approvals, none of which verify signatures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Require approval from a specific user or group.

    Why it's wrong here

    Requiring approval from a specific user or group adds an extra layer of authorization but does not verify commit signatures. This policy is about who approves changes, not about the cryptographic verification of commit authorship. It does not enforce signed commits.

  • ✗

    Require a minimum number of reviewers.

    Why it's wrong here

    Requiring a minimum number of reviewers ensures that pull requests are reviewed by a certain number of people, but it does not verify commit signatures. This policy does not enforce that commits are signed, so it fails to meet the requirement for signed and verified commits.

  • ✗

    Check for linked work items.

    Why it's wrong here

    Checking for linked work items ensures that every pull request is associated with a work item, which helps with traceability but does not address commit signing. This policy is unrelated to verifying the cryptographic signature of commits, so it does not satisfy the security requirement.

  • ✓

    Require signed commits.

    Why this is correct

    The 'Require signed commits' branch policy ensures that all commits pushed to the protected branch have a valid GPG or SSH signature. This directly enforces that commits are signed and verified, meeting the security team's requirement. It prevents unsigned commits from being merged, ensuring integrity and authenticity.

About these practice questions

One of 696 original AZ-400 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.