Courseiva

AZ-400 Develop a security and compliance plan Practice Question

Your company uses Azure DevOps and must comply with SOC 2. The auditor requires proof that all production deployments went through a change management process with approval. What should you implement?

⚠ Common exam trap

AZ-400 often tests the difference between code review approvals (branch policies) and deployment approvals (release gates), and candidates may incorrectly choose branch policies for deployment change management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure release approval gates in Azure Pipelines

Release approval gates in Azure Pipelines allow you to define approvers who must approve a deployment before it proceeds. This enforces a change management process with documented approval, providing an audit trail that satisfies SOC 2 requirements. Approval gates can be configured for specific environments or stages, ensuring that all production deployments are reviewed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use branch policies to require pull request approvals

    Why it's wrong here

    Branch policies that require pull request approvals govern when code is merged into a branch, not when a build or release is deployed to an environment; they cannot insert a manual authorization step in the CD release pipeline, so they fail to meet SOC 2 change-management approval requirements for production deployments.

  • ✗

    Set pipeline retention policies to keep deployment records

    Why it's wrong here

    Pipeline retention policies determine how long runs, logs, and artifacts are stored, which supports audit evidence but does not enforce or require a human approval before a deployment proceeds; without an actual approval gate, SOC 2's authorization control is not satisfied.

  • ✗

    Enable audit logging for all pipelines

    Why it's wrong here

    Enabling audit logging records user and pipeline activities for later investigation, but it is a passive, detective control; it does not prevent or require approval of a deployment, so SOC 2's preventive control for deployment authorization remains unmet.

  • ✓

    Configure release approval gates in Azure Pipelines

    Why this is correct

    Release approval gates in Azure Pipelines require designated approvers to explicitly approve a release stage before it continues, directly enforcing a formal sign-off step for production deployments—this aligns with SOC 2's change-management and authorization requirements by making approval a mandatory precondition.

About these practice questions

One of 696 original AZ-400 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.