← All AZ-400 Flashcard Decks

Compliance & Governance Flashcards

7 cards from real AZ-400 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Compliance & Governance flashcards as text
  1. Which Azure DevOps feature allows administrators to enforce code review requirements before merging to protected branches?

    Answer: Branch policies

    Branch policies in Azure Repos allow administrators to enforce requirements such as minimum reviewer counts, work item linking, and build validation before code can be merged.

  2. What is the primary purpose of Azure Policy in a DevOps governance model?

    Answer: To enforce organizational standards and assess compliance at scale

    Azure Policy enforces organizational standards and helps assess compliance at scale by evaluating Azure resources against defined policy rules.

  3. Which Azure service provides a centralized hub for applying governance controls including policies, role assignments, and resource templates as a repeatable package?

    Answer: Azure Blueprints

    Azure Blueprints allows organizations to define a repeatable set of governance tools — including policies, role assignments, and ARM templates — for consistent and compliant environment setup.

  4. In Azure DevOps, which feature provides an immutable audit log of all actions performed within an organization?

    Answer: Audit Logs

    Azure DevOps Audit Logs provide an immutable record of all events and changes within an organization, supporting compliance investigations and security reviews.

  5. What is the purpose of 'Environment Approvals and Checks' in Azure Pipelines?

    Answer: To require human approval or automated validation before deployments proceed to an environment

    Environment approvals and checks require designated approvers or automated validations to complete before a deployment can proceed to a specific environment.

  6. Which Azure feature allows organizations to restrict which Azure regions resources can be deployed to for data residency compliance?

    Answer: Azure Policy with the Allowed Locations definition

    Azure Policy's built-in 'Allowed locations' policy definition restricts where resources can be deployed, supporting data residency and regulatory compliance requirements.

  7. What is the role of Service Connections in Azure DevOps from a governance perspective?

    Answer: They securely store credentials for external services, limiting direct credential exposure in pipeline code

    Service Connections securely store and manage credentials for accessing external services and resource managers, preventing direct credential embedding in pipeline code.