Courseiva

AZ-400 Develop a security and compliance plan Practice Question

You are a security engineer for a large financial institution. The organization uses Azure DevOps with multiple projects, each containing hundreds of pipelines. The security team recently discovered that several pipeline variables marked as 'Secret' were inadvertently printed to logs due to a custom script task that echoed the variable. Consequently, the compliance officer requires that all secrets used in pipelines must be centrally managed in Azure Key Vault, and any pipeline that references a variable not from Key Vault must be blocked from running. Additionally, the solution must minimize administrative overhead and provide real-time enforcement across all projects in the organization. You have the following options:

Option A: Develop a custom pipeline task that checks at runtime whether all secret variables originate from Key Vault, and add it to every pipeline YAML file manually.

Option B: Create an Azure Policy definition that audits pipelines for the use of non-Key Vault variables and attach it to the management group containing the Azure DevOps resources.

Option C: Use Azure DevOps Audit Logs to periodically review pipeline runs and manually identify pipelines that use non-Key Vault secrets.

Option D: Configure a pipeline decorator in the organization settings that injects a task at the beginning of every pipeline to validate that all secret variables are linked to Key Vault, and fail the pipeline if any are not.

Which option meets the requirements most effectively?

⚠ Common exam trap

AZ-400 often tests whether candidates confuse Azure Policy (which governs Azure resources) with Azure DevOps governance mechanisms (decorators, checks, approvals), so options invoking Azure Policy for pipeline control are classic distractors.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a pipeline decorator in the organization settings that injects a task at the beginning of every pipeline to validate that all secret variables are linked to Key Vault

A pipeline decorator is an organization-level extension that automatically injects tasks into every pipeline across all projects without modifying individual YAML files. By injecting a validation task at the start of each pipeline that checks whether secret variables are linked to Azure Key Vault and fails the run otherwise, it provides real-time enforcement, central management, and minimal administrative overhead — exactly matching the requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Develop a custom pipeline task that checks at runtime whether all secret variables originate from Key Vault

    Why it's wrong here

    A custom task must be added to every pipeline YAML manually, so it cannot enforce across hundreds of pipelines and is easily omitted. It is tempting because runtime validation catches non-Key Vault secrets, but a pipeline decorator injects the check organisation-wide without per-pipeline edits.

  • ✗

    Create an Azure Policy definition that audits pipelines for the use of non-Key Vault variables

    Why it's wrong here

    Azure Policy audits Azure resources, not Azure DevOps pipeline variable definitions, and auditing alone does not block a pipeline from running. It is tempting because policy gives central governance, but the requirement is real-time enforcement at pipeline execution, which a decorator provides.

  • ✗

    Use Azure DevOps Audit Logs to periodically review pipeline runs

    Why it's wrong here

    Audit Logs record events after pipelines have already run, so secrets can still be echoed before any manual review occurs; enforcement is neither real-time nor automatic. It is tempting because audit logs are organisation-wide, and would be correct for retrospective compliance reporting rather than blocking non-compliant runs.

  • ✓

    Configure a pipeline decorator in the organization settings that injects a task at the beginning of every pipeline to validate that all secret variables are linked to Key Vault

    Why this is correct

    A pipeline decorator injects a validation task into every pipeline across all projects automatically, failing runs whose secrets are not Key Vault-linked. This enforces centrally managed secrets organisation-wide with minimal administrative overhead, unlike per-pipeline YAML edits or periodic audit reviews.

About these practice questions

This AZ-400 question is part of Courseiva's 696-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.