Microsoft Certified: DevOps Engineer ExpertDesign and implement source controlHard
A company uses Azure DevOps for its source control, utilizing Git. They want to enforce specific quality and security standards for all code merged into the `main` branch. This includes requiring at least two reviewers, successful completion of a build validation pipeline, and approval from a security scan. These rules must be applied automatically to all pull requests targeting the `main` branch. Which Azure DevOps feature should they configure?
- AService hooks
- BBranch policies
- CGit hooks
- DPipeline triggers
Show answer & explanationAnswer & explanation
Correct answer: B. Branch policies
Branch policies in Azure DevOps are designed to enforce specific standards and workflows on branches, especially critical ones like `main`. They allow configuration of requirements such as minimum number of reviewers, mandatory build validation, and external service checks (which can include security scans), all applied to pull requests before merging.
Why the other options are wrong
- A. Service hooks send notifications to external services, but they don't directly enforce merge policies or block pull requests within Azure DevOps.
- C. Git hooks are client-side or server-side scripts for Git, but Azure DevOps provides a more integrated and user-friendly way to manage branch policies.
- D. Pipeline triggers initiate pipelines based on events, but they don't enforce merge policies or approvals.
Azure Repos Branch Policies
A set of configurable rules in Azure DevOps Git repositories that enforce quality and workflow standards on branches, typically applied to pull requests before merging.
- Enforce minimum number of reviewers.
- Require successful build validation.
- Integrate with external services for status checks (e.g., security scans).
- Can require linked work items or comment resolution.
- Configured per branch or branch pattern.
Memory trick: Branch policies are the guardians of the main branch.