Finance wants every resource created in one production resource group to receive the tag CostCenter=FINSVC automatically, but deployments should not be blocked if a template omits the tag. Existing resources should be updated when possible. Which two actions should the administrator take? Select two.
A Modify policy with an addOrUpdate effect appends or overwrites the CostCenter tag during create and update operations, so resources receive CostCenter=FINSVC automatically without blocking deployments that omit the tag. This matches the requirement for automatic tagging without denial.
Why this answer
Option A is correct because an Azure Policy with the Modify effect can automatically add or update the CostCenter=FINSVC tag on resources created in the production resource group, and its remediation capability allows existing resources to be brought into compliance without blocking deployments. Option B is correct because after assigning a Modify policy, a remediation task is required to apply the tag to existing noncompliant resources, satisfying the requirement to update existing resources when possible. Option C is incorrect because a ReadOnly lock prevents modifications, including tag updates, and does not enforce tagging.
Option D is incorrect because Reader only grants read access and has no effect on tag creation or enforcement. Option E is incorrect because an Audit policy only reports noncompliance and does not automatically add the tag or update existing resources.
Exam trap
The trap here is that candidates often confuse Audit and Modify effects, thinking Audit can automatically fix tags, or they mistakenly believe a ReadOnly lock is needed to enforce consistency, when in fact Modify with remediation is the correct approach for automatic tag application without blocking deployments.
Why the other options are wrong
Applying a ReadOnly lock prevents any modifications to resources, including adding or updating tags, which contradicts the requirement to automatically apply tags to new resources and update existing ones.
Assigning the Reader role to the resource group ensures tag visibility but does not automatically apply or enforce the CostCenter tag. The requirement is to automatically add the tag to new resources and update existing ones, which requires a policy with a Modify effect, not a role assignment.
An Audit policy only reports noncompliance but does not automatically add or update tags. The requirement is to automatically apply the CostCenter tag to new and existing resources, which requires a Modify policy with a remediation task, not just auditing.