Courseiva
Develop a security and compliance planeasyMultiple ChoiceObjective-mapped

AZ-400 Develop a security and compliance plan Practice Question

Your organization uses Microsoft Purview to classify and protect sensitive data. You need to ensure that source code in Azure DevOps repositories containing credit card numbers is detected and flagged. What should you configure?

⚠ Common exam trap

Test-takers frequently confuse Microsoft Purview Data Classification (which can scan Azure DevOps repositories) with Microsoft 365 DLP policies (which are limited to Microsoft 365 workloads), leading them to select Option A incorrectly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure a Microsoft Purview Data Classification scan for Azure DevOps repositories.

Microsoft Purview Data Classification scans can be configured to scan Azure DevOps repositories for sensitive data types, such as credit card numbers, using built-in or custom sensitive information types. This allows the organization to detect and flag source code containing credit card numbers directly within the repository, aligning with the requirement to classify and protect sensitive data under a compliance plan.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create a Data Loss Prevention (DLP) policy in Microsoft 365.

    Why it's wrong here

    Microsoft 365 DLP policies are scoped to Microsoft 365 workloads such as Exchange, SharePoint, OneDrive, and Teams, and cannot scan or classify content stored in Azure DevOps repositories. Azure DevOps is not a valid location for DLP content matching, so this option does not address source code classification.

  • Set up Microsoft Sentinel to monitor Azure DevOps logs.

    Why it's wrong here

    Microsoft Sentinel is a cloud-native SIEM/SOAR tool that ingests and correlates security logs for threat detection and incident response; it does not perform content-based data classification on Azure DevOps repositories. While it can ingest Azure DevOps activity logs, it lacks the ability to scan source code for sensitive data.

  • Configure a Microsoft Purview Data Classification scan for Azure DevOps repositories.

    Why this is correct

    Microsoft Purview provides data governance and classification capabilities, and its data map can register and scan Azure DevOps repositories to automatically classify sensitive data such as credentials, connection strings, and personal information. This directly aligns with the requirement to classify and protect sensitive information in your organization's code repositories.

  • Enable Microsoft Defender for Cloud to scan repositories.

    Why it's wrong here

    Microsoft Defender for Cloud is a cloud security posture management (CSPM) solution that assesses Azure resources for misconfigurations, vulnerabilities, and regulatory compliance, but it does not scan repository contents to classify sensitive data. Its workload protection and recommendations focus on security hardening, not data classification within code.

About these practice questions

This AZ-400 question is part of Courseiva's 823-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.