Courseiva
Develop a security and compliance planmediumMultiple ChoiceObjective-mapped

AZ-400 Develop a security and compliance plan Practice Question

Your organization requires compliance with SOC 2 and needs to audit all changes to Azure Pipelines. What should you enable?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Azure DevOps audit logs

Azure DevOps audit logs capture all changes to pipelines and can be exported for compliance with SOC 2. Option A is incorrect because Azure Policy enforces governance rules on Azure resources, not pipeline changes. Option B is incorrect because Microsoft Purview is a data governance service, not for auditing DevOps changes. Option C is incorrect because Azure Blueprints (now deprecated) were used to define repeatable Azure environments, not for audit logging.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Azure Policy

    Why it's wrong here

    Azure Policy enforces organizational standards and evaluates resource compliance, but it does not record who made specific pipeline changes or when, so it cannot satisfy SOC 2's requirement for audit trails of DevOps activities. Its compliance data is about Azure resource configuration, not operational actions within Azure DevOps.

  • Microsoft Purview

    Why it's wrong here

    Microsoft Purview is focused on data governance, classification, and lineage across data estates, not on tracking user actions or configuration changes in Azure DevOps pipelines. SOC 2 audit requirements for DevOps specifically need activity logs, which Purview does not ingest or surface.

  • Azure Blueprints

    Why it's wrong here

    Azure Blueprints orchestrates the deployment of Azure resources by packaging ARM templates, policies, and role assignments, but it only provisions the environment. It produces no ongoing audit trail of pipeline modifications or approvals, so it is irrelevant for auditing DevOps changes.

  • Azure DevOps audit logs

    Why this is correct

    Azure DevOps audit logs capture security-relevant events such as pipeline run changes, permission modifications, and user access updates, and they can be exported to Log Analytics or SIEM tools for SOC 2 compliance. They provide the immutable, timestamped record of who did what and when, directly meeting the audit requirement.

About these practice questions

This AZ-400 question is part of Courseiva's 823-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.