AZ-400 Develop a security and compliance plan Practice Question
You are a DevOps engineer at a company that uses Azure DevOps. The security team requires that all code commits to the main branch are signed and verified. You need to enforce this using branch policies. Which policy should you configure?
⚠ Common exam trap
A common mix-up: candidates confuse commit signing with other branch policies that provide security, such as required reviewers or linked work items, but these do not verify signatures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require signed commits.
The 'Require signed commits' branch policy is the only policy that enforces cryptographic signing of commits. It ensures that every commit to the protected branch is signed and verified, providing authenticity and integrity. Other policies focus on review, work item linking, or approvals, none of which verify signatures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Require approval from a specific user or group.
Why it's wrong here
Requiring approval from a specific user or group adds an extra layer of authorization but does not verify commit signatures. This policy is about who approves changes, not about the cryptographic verification of commit authorship. It does not enforce signed commits.
- ✗
Require a minimum number of reviewers.
Why it's wrong here
Requiring a minimum number of reviewers ensures that pull requests are reviewed by a certain number of people, but it does not verify commit signatures. This policy does not enforce that commits are signed, so it fails to meet the requirement for signed and verified commits.
- ✗
Check for linked work items.
Why it's wrong here
Checking for linked work items ensures that every pull request is associated with a work item, which helps with traceability but does not address commit signing. This policy is unrelated to verifying the cryptographic signature of commits, so it does not satisfy the security requirement.
- ✓
Require signed commits.
Why this is correct
The 'Require signed commits' branch policy ensures that all commits pushed to the protected branch have a valid GPG or SSH signature. This directly enforces that commits are signed and verified, meeting the security team's requirement. It prevents unsigned commits from being merged, ensuring integrity and authenticity.
Go deeper
Related to this question
Learn chapter
Implementing Work Item Management and Agile Planning
Key term
DevOps
DevOps is a set of practices that combines software development (Dev) and IT operations (Ops) to shorten the development lifecycle and deliver high-quality software continuously.
Key term
Work item
A work item is a digital record in Azure DevOps that tracks a single unit of work, such as a task, bug, or user story, helping teams manage and monitor their progress.
About these practice questions
One of 696 original AZ-400 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.