AZ-400 Develop a security and compliance plan Practice Question
Your organization requires compliance with SOC 2 and needs to audit all changes to Azure Pipelines. What should you enable?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure DevOps audit logs
Azure DevOps audit logs capture all changes to pipelines and can be exported for compliance with SOC 2. Option A is incorrect because Azure Policy enforces governance rules on Azure resources, not pipeline changes. Option B is incorrect because Microsoft Purview is a data governance service, not for auditing DevOps changes. Option C is incorrect because Azure Blueprints (now deprecated) were used to define repeatable Azure environments, not for audit logging.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Policy
Why it's wrong here
Azure Policy enforces organizational standards and evaluates resource compliance, but it does not record who made specific pipeline changes or when, so it cannot satisfy SOC 2's requirement for audit trails of DevOps activities. Its compliance data is about Azure resource configuration, not operational actions within Azure DevOps.
- ✗
Microsoft Purview
Why it's wrong here
Microsoft Purview is focused on data governance, classification, and lineage across data estates, not on tracking user actions or configuration changes in Azure DevOps pipelines. SOC 2 audit requirements for DevOps specifically need activity logs, which Purview does not ingest or surface.
- ✗
Azure Blueprints
Why it's wrong here
Azure Blueprints orchestrates the deployment of Azure resources by packaging ARM templates, policies, and role assignments, but it only provisions the environment. It produces no ongoing audit trail of pipeline modifications or approvals, so it is irrelevant for auditing DevOps changes.
- ✓
Azure DevOps audit logs
Why this is correct
Azure DevOps audit logs capture security-relevant events such as pipeline run changes, permission modifications, and user access updates, and they can be exported to Log Analytics or SIEM tools for SOC 2 compliance. They provide the immutable, timestamped record of who did what and when, directly meeting the audit requirement.
Go deeper
Related to this question
Learn chapter
Introduction to DevOps and Azure DevOps
Key term
Azure Pipelines
Azure Pipelines is a cloud-based CI/CD service from Microsoft that automatically builds, tests, and deploys code to any platform or cloud.
Key term
Azure DevOps
Azure DevOps is a Microsoft service that provides development tools for planning, building, testing, and deploying software applications using automated pipelines and collaboration features.
About these practice questions
This AZ-400 question is part of Courseiva's 823-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.