Courseiva

Two Actions That Enforce Security Scans and Compliance Approval on Every Build

You are designing a compliance strategy for Azure DevOps pipelines that deploy to production. The company policy requires that all production deployments must be reviewed by a security lead. Additionally, the deployment must use a specific release pipeline that has been pre-approved. How should you implement this?

⚠ Common exam trap

Test-takers frequently confuse branch policies (which control code changes) with deployment approvals (which control release execution), leading them to choose Option A instead of the environment-based approval check in Option B.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Define a 'production' environment in Azure DevOps and configure an approval check that requires the security lead. Have the pipeline deploy to that environment.

Azure DevOps environments allow you to define approval checks that must be satisfied before a deployment proceeds. By creating a 'production' environment and adding a pre-deployment approval check requiring the security lead, you enforce the mandatory review. The pipeline then deploys to that environment, ensuring only the pre-approved release pipeline is used.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a branch policy that requires the security lead to approve the pull request before merging.

    Why it's wrong here

    Branch policies control code changes entering a branch, not runtime deployments. Even with a security lead's PR approval, the pipeline can still deploy without a separate post-merge review, so it fails to gate the actual production release.

  • ✓

    Define a 'production' environment in Azure DevOps and configure an approval check that requires the security lead. Have the pipeline deploy to that environment.

    Why this is correct

    Environment approval checks in YAML pipelines create a standardized, auditable manual gate before any deployment to the production environment. This integrates directly with pipeline runs, ensures the security lead explicitly approves each release, and provides full traceability, fulfilling the compliance requirement.

  • ✗

    Use a Classic release pipeline with a pre-deployment approval gate for the production stage.

    Why it's wrong here

    While Classic release pipelines do support pre-deployment approvals, Microsoft recommends YAML-based pipelines for new projects and they lack the same level of integration with modern features like environment checks and multi-stage YAML. Using a legacy pipeline would not align with current Azure DevOps best practices for compliance.

  • ✗

    Store the approved pipeline definition in a variable group and reference it in all pipelines.

    Why it's wrong here

    Variable groups in Azure DevOps are key-value stores used for configuration, not for enforcing workflow controls. Storing pipeline definitions in a variable group doesn't create any mandatory approval check, and pipelines referencing it can still run without a security review or deployment gate.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

This AZ-400 question is part of Courseiva's 696-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on AZ-400

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. You have a release pipeline that deploys to multiple stages. You want to ensure that a manual approval is required before deploying to the production stage. Which approach should you use?

medium
  • ✓ A.Add a pre-deployment approval on the production stage.
  • B.Add a post-deployment approval on the staging stage.
  • C.Configure a deployment gate with a manual intervention task.
  • D.Use a pipeline decorator to inject approval step.

Why A: Pre-deployment approvals in Azure Pipelines allow you to require manual sign-off before a release proceeds to a specific stage. By adding a pre-deployment approval on the production stage, the pipeline will pause and wait for designated approvers to approve the deployment, ensuring that no code reaches production without explicit authorization.

Variation 2. You maintain a classic release pipeline that deploys to multiple environments. You need to ensure that a deployment to the Production environment only proceeds after a manual approval from a specific group of users. Which feature should you configure?

medium
  • A.Post-deployment approvals on the Production environment
  • B.Deployment queue settings on the Production environment
  • C.Deployment gates on the Production environment
  • ✓ D.Pre-deployment approvals on the Production environment

Why D: Pre-deployment approvals are configured on an environment to require manual sign-off before a release is deployed to that environment. In a classic release pipeline, this ensures that the deployment to Production only proceeds after a specific group of users has approved it, meeting the requirement for manual approval before deployment.

Variation 3. Your team uses Azure Pipelines to deploy to multiple environments. The compliance team requires that all deployments to the production environment are approved by a security officer. Which feature should you use?

easy
  • ✓ A.Configure approvals and checks on the production environment in Azure Pipelines.
  • B.Create a branch policy that requires approval for pull requests.
  • C.Use a service connection with a managed identity that requires approval.
  • D.Store the production credentials in a variable group with approval required.

Why A: Approvals and checks in Azure Pipelines allow you to require manual approval before a deployment to a specific environment, such as production. By configuring an approval on the production environment, you ensure that a designated security officer must approve the deployment before it proceeds, meeting the compliance team's requirement.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.