AZ-400 Develop a security and compliance plan Practice Question
Your team uses Microsoft Defender for Cloud to monitor Azure resources. You need to ensure that all Azure DevOps pipelines are scanned for security misconfigurations before deployment. Which integration should you enable?
⚠ Common exam trap
Test-takers frequently confuse Microsoft Sentinel (a SIEM) with Defender for Cloud's DevOps scanning capabilities, or assume that a data governance tool like Purview can perform security configuration scanning, when in fact only the dedicated Defender for DevOps integration provides this specific pipeline scanning functionality.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the 'Defender for DevOps' integration in Microsoft Defender for Cloud.
Microsoft Defender for Cloud includes a 'Defender for DevOps' integration that allows you to connect Azure DevOps environments and scan pipelines for security misconfigurations, such as Infrastructure as Code (IaC) template issues or exposed secrets, before deployment. This integration provides built-in security posture assessments and actionable recommendations directly within the Defender for Cloud dashboard, enabling shift-left security practices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Connect Azure DevOps to Microsoft Sentinel.
Why it's wrong here
Microsoft Sentinel is a cloud-native SIEM/SOAR that ingests security logs and alerts across resources for incident detection and response, but it does not natively integrate with Azure DevOps pipelines to scan pipeline definitions or infrastructure-as-code for misconfigurations. Connecting Azure DevOps to Sentinel would only enable security event correlation, not pipeline security scanning.
- ✓
Enable the 'Defender for DevOps' integration in Microsoft Defender for Cloud.
Why this is correct
Microsoft Defender for Cloud's Defender for DevOps integration provides actionable security recommendations for Azure DevOps and GitHub environments, scanning repositories and pipelines for misconfigurations, exposed secrets, and vulnerabilities in infrastructure-as-code templates. Enabling this integration directly addresses the need to monitor and harden Azure DevOps pipelines against security issues.
- ✗
Deploy Microsoft Intune policies to Azure DevOps agents.
Why it's wrong here
Microsoft Intune is a Unified Endpoint Management service that manages and secures devices such as Windows, iOS, Android, and macOS through configuration profiles and compliance policies. Azure DevOps agents are build/run infrastructure for pipelines, not managed endpoints, so Intune policies cannot be applied to them nor do they scan pipeline definitions for security misconfigurations.
- ✗
Configure Microsoft Purview to scan Azure DevOps repositories.
Why it's wrong here
Microsoft Purview is a unified data governance and compliance solution that catalogs, maps, and classifies data across your estate, focusing on data lineage and sensitivity labels. It does not perform code-level or pipeline configuration security scanning, lacking the capability to identify misconfigurations in Azure DevOps pipeline definitions.
Go deeper
Related to this question
Learn chapter
Introduction to DevOps and Azure DevOps
Key term
Azure DevOps
Azure DevOps is a Microsoft service that provides development tools for planning, building, testing, and deploying software applications using automated pipelines and collaboration features.
Key term
IaC
Infrastructure as Code (IaC) manages and provisions IT infrastructure through machine-readable definition files, rather than manual hardware configuration.
About these practice questions
This AZ-400 question is part of Courseiva's 823-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.