← All AZ-400 Flashcard Decks

Compliance & Governance Flashcards

7 cards from real AZ-400 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Compliance & Governance flashcards as text
  1. Which Azure Pipelines feature allows platform teams to define reusable, standardized pipeline definitions that other teams must extend from to enforce organizational compliance?

    Answer: Pipeline templates

    Pipeline templates allow organizations to define reusable, standardized pipeline stages or jobs that teams must use, enforcing consistent security and compliance controls across projects.

  2. In the context of AZ-400, what does 'Shift Left' security mean in a DevOps pipeline?

    Answer: Integrating security testing and checks earlier in the development lifecycle, starting at coding and CI

    'Shift Left' security means introducing security testing and vulnerability scanning as early as possible — during coding and CI — rather than only validating security at the end of the pipeline.

  3. Which Azure DevOps feature allows teams to require specific external validation checks (such as SonarQube or security scans) to pass before a pull request can be completed?

    Answer: Branch policies with status checks

    Branch policies with status checks allow teams to require external tools to report a passing status before a PR can be merged, enforcing quality and compliance gates.

  4. What is the purpose of 'Protected Resources' in Azure Pipelines?

    Answer: To control which pipelines are authorized to use sensitive resources like environments and service connections

    Protected Resources allow administrators to control which specific pipelines are authorized to use sensitive resources like environments, service connections, agent pools, and variable groups.

  5. In Azure DevOps, where would you configure mandatory human approvals before deploying to a production environment in a YAML pipeline?

    Answer: In the Environment settings under Approvals and Checks

    Production deployment approvals are configured in the Environment settings within Azure Pipelines under 'Approvals and Checks,' where specific approvers can be assigned per environment.

  6. Which Azure service provides a Secure Score and a regulatory compliance dashboard to help organizations track adherence to standards like PCI DSS and ISO 27001?

    Answer: Microsoft Defender for Cloud

    Microsoft Defender for Cloud (formerly Azure Security Center) provides Secure Score and a built-in regulatory compliance dashboard to assess posture against frameworks like PCI DSS, ISO 27001, and NIST.

  7. What does Azure DevOps' SOC 2 Type II attestation primarily provide to enterprise customers?

    Answer: Third-party assurance that Azure DevOps service controls meet security, availability, and confidentiality criteria

    Azure DevOps' SOC 2 Type II attestation provides third-party assurance that Microsoft's service controls for security, availability, processing integrity, confidentiality, and privacy meet the AICPA Trust Services Criteria.