Microsoft Certified: DevOps Engineer ExpertDevelop a security and compliance planHard
A global e-commerce company uses Azure DevOps for its CI/CD pipelines. They have multiple development teams working on different microservices, each with its own Azure subscription. The company's security policy mandates that all production deployments must be reviewed and approved by a separate security operations team before being released. This approval process should be integrated directly into the deployment pipeline and prevent any unapproved changes from reaching production. Additionally, the security team needs to be able to manually trigger a rollback or hold a deployment if a critical vulnerability is discovered post-approval but pre-release. Which Azure DevOps feature should the company implement to meet these requirements?
- AAzure Policy with 'Deny' effect
- BService Connections with dedicated security accounts
- CRelease Gates with automated security scans
- DEnvironments with Approvals and Checks
Show answer & explanationAnswer & explanation
Correct answer: D. Environments with Approvals and Checks
Azure DevOps Environments with Approvals and Checks provide the granular control needed for manual review and approval gates, as well as the ability for security teams to intervene. This feature specifically supports pre-deployment approvals and post-approval interventions like holding or rolling back a deployment.
Why the other options are wrong
- A. Azure Policy can enforce configurations but doesn't directly provide manual approval workflows within a deployment pipeline or the ability to manually hold/rollback a specific deployment instance.
- B. Service Connections manage access to external services but do not provide the workflow for manual approvals or interventions within the pipeline itself.
- C. Release Gates automate checks (like security scans) but do not inherently provide a manual approval step or the capability for a security team to manually intervene to hold/rollback a deployment after an automated gate has passed.
Azure DevOps Environments Approvals
Azure DevOps Environments allow defining deployment targets with integrated approval gates and automated checks, ensuring controlled and secure deployments.
- Integrates manual approvals directly into CI/CD pipelines.
- Supports pre-deployment and post-deployment checks.
- Enables granular control over who can approve deployments.
- Provides a mechanism to pause or reject deployments.
Memory trick: Environments Guard Production's Gate with Approvals.