AZ-400 Develop a security and compliance plan Practice Question
Your organization uses Azure DevOps Services. The compliance team requires that all code changes to the main branch of a critical repository must be reviewed by at least two members of the security team before they can be merged. You need to configure this requirement with the least administrative effort. What should you do?
⚠ Common exam trap
The trap here is thinking that build validation or status checks can enforce human approvals, when only branch policies with required reviewers can do that.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a branch policy on the main branch that requires a minimum number of reviewers, and specify the security team as required reviewers.
The requirement is to enforce that at least two security team members approve changes to the main branch. Azure Repos branch policies provide a built-in way to require a minimum number of reviewers and to specify required reviewers. Configuring a branch policy with the security team as required reviewers and a minimum count of two directly satisfies this with minimal effort.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a required template to enforce that pull requests include a note listing two security team members.
Why it's wrong here
Required templates ensure that pull requests contain certain information, but they do not enforce that specific people approve. A note listing names does not guarantee those individuals reviewed the code. This does not meet the compliance requirement for actual approvals.
- ✗
Configure a build validation policy on the main branch that runs a script to check the number of approvers.
Why it's wrong here
Build validation policies run a build or script when a pull request is created, but they do not enforce reviewer requirements. A script could check approvals, but it cannot block the merge based on approver count; only branch policies can enforce that. This approach is ineffective and overly complex.
- ✓
Create a branch policy on the main branch that requires a minimum number of reviewers, and specify the security team as required reviewers.
Why this is correct
This is correct because branch policies in Azure Repos allow you to enforce a minimum number of reviewers and designate specific users or groups as required. By setting the security team as required reviewers and requiring at least two approvals, you ensure that two security team members must approve each pull request to main.
- ✗
Set up a status check policy that requires a successful status from an external service that tracks security team approvals.
Why it's wrong here
Status check policies require an external service to post a status, but they do not inherently enforce that two security team members approve. You would need to build and maintain a custom service, which is more effort than using built-in branch policies. This is not the least administrative effort.
Go deeper
Related to this question
Learn chapter
Managing Infrastructure as Code Using Azure
Key term
Branch policy
A branch policy is a set of rules and conditions enforced on a Git branch to control how code changes are proposed, reviewed, and merged, ensuring code quality and protecting critical branches.
Key term
Repository
A repository is a central storage location where software packages, code, or configuration files are kept, managed, and distributed for use by IT systems.
About these practice questions
This AZ-400 question is part of Courseiva's 696-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.