Courseiva
Develop a security and compliance planmediumMultiple ChoiceObjective-mapped

AZ-400 Develop a security and compliance plan Practice Question

Your company uses Azure DevOps and must enforce that all pipelines use approved agent pools. The security team wants to prevent the use of the default agent pool. What should you do?

⚠ Common exam trap

Candidates often confuse 'requiring authorization' (which still allows use after approval) with 'denying permissions' (which blocks use entirely), or they mistakenly think the default agent pool can be removed or disabled like a custom pool.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Set agent pool permissions to deny the default pool for all projects

Setting agent pool permissions to deny the default pool for all projects explicitly blocks its use across the organization. This enforces the security policy by preventing any pipeline from selecting the default agent pool, while still allowing administrators to manage the pool if needed. In Azure DevOps, agent pool permissions control which users, teams, or projects can use a pool, and setting 'Deny' overrides any inherited 'Allow' permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use pipeline settings to require authorization for the default pool

    Why it's wrong here

    The 'authorization' setting in pipeline settings applies to YAML pipeline resources such as service connections, variable groups, and secure files, requiring manual approval before use, but it does not restrict or deny any project from using the default agent pool.

  • Set agent pool permissions to deny the default pool for all projects

    Why this is correct

    Setting agent pool permissions to deny the 'Use' permission for the default pool across all projects explicitly prevents any pipeline in those projects from queuing jobs on that pool, making it the correct way to enforce the restriction.

  • Remove the default agent pool from the organization

    Why it's wrong here

    Removing the default agent pool from the organization would break existing pipelines that reference it by default, and Azure DevOps does not allow deleting this system-managed pool, so it cannot be used as a viable enforcement mechanism.

  • Disable the default agent pool in project settings

    Why it's wrong here

    Disabling the default agent pool in project settings is not an actual option, and it would only affect a single project if it were possible, lacking the organization-wide granularity needed to enforce a consistent policy across all projects.

About these practice questions

This AZ-400 question is part of Courseiva's 823-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.