Courseiva

AZ-104 · topic practice

Azure Policy practice questions

Practise AZ-104 Azure Policy practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Azure Policy

What the exam tests

What to know about Azure Policy

Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.

IaaS, PaaS and SaaS responsibilities and examples.

Public, private, hybrid and community cloud deployment models.

On-premises vs cloud trade-offs: cost, control, scalability.

How cloud connectivity options (VPN, Direct Connect, ExpressRoute) work.

Watch out for

Common Azure Policy exam traps

  • IaaS gives you infrastructure control; SaaS gives you only the application.
  • Hybrid cloud combines on-premises and public cloud — not two public clouds.
  • Cloud does not automatically mean cheaper or more secure.
  • Management responsibility shifts with each service model (IaaSPaaSSaaS).

Practice set

Azure Policy questions

20 questions · select your answer, then reveal the explanation

Question 1hardmulti select
Read the full Policy explanation →

A policy initiative is assigned at the Corp management group to enforce allowed locations and required tags. A new subscription is added under Corp later. Which two statements are true? Select two.

Question 2mediummulti select
Read the full Policy explanation →

Your organization has an Azure Active Directory (Azure AD) tenant with 500 users. You need to ensure that users can reset their own passwords without IT support, but only if they have registered for multi-factor authentication (MFA). Additionally, you want to prevent users from reusing their last 10 passwords. Which three of the following should you configure? (Choose three.)

Question 3mediummulti select
Read the full Policy explanation →

A department has 10 subscriptions and wants the same two governance rules applied to all current and future subscriptions. One rule audits missing tags, and the other denies unapproved locations. Which two actions should the administrator take? Select two.

Question 4hardmultiple choice
Read the full Policy explanation →

A container group runs a one-time import job that writes data to an external system. If the job succeeds, the container must stop and stay stopped. If the job fails, it should automatically retry by restarting. Which restart policy should the administrator choose?

Question 5hardmultiple choice
Read the full Policy explanation →

A company uses Azure Blob Storage for legal documents. The documents must not be modified or deleted for seven years after upload, even by administrators. What should you configure?

Question 6hardmultiple choice
Read the full Policy explanation →

The platform team wants to block deployment of virtual machines that use any size except a small approved list. Operators already have Contributor access and should keep that access for other tasks. Which Azure control should the administrator use to enforce the size restriction?

Question 7easymultiple choice
Read the full Policy explanation →

A container group runs a one-time import task and should stop after the task completes successfully. Which restart policy should you use?

Question 8easymultiple choice
Read the full Policy explanation →

A company wants to group several subscriptions for Finance, HR, and Engineering so that the same governance settings can be applied above the subscription level. What should the administrator create?

Question 9easymulti select
Read the full Policy explanation →

A company wants to stop users from creating resources in regions that are not approved and also require a Department tag on new resources. Which two tasks are best handled by Azure Policy? Select two.

Question 10hardmultiple choice
Read the full Policy explanation →

A finance team wants every resource created in one production resource group to carry CostCenter=PRD automatically. They do not want deployments blocked if a team forgets the tag, but they do want existing resources and future resources in that resource group to converge on the correct tag value. What should the administrator configure?

Question 11hardmulti select
Read the full Policy explanation →

A subscription already grants Contributor to an application team. The organization wants to prevent deployments in unsupported Azure regions and ensure every new resource has an Environment tag. Which two controls should be implemented with Azure Policy rather than RBAC? Select two.

Question 12mediummultiple choice
Read the full Policy explanation →

A team can already deploy virtual machines, but they want to prevent users from creating VMs unless the deployment includes an approved tag. They also want to see which existing resources do not meet the rule. What should the administrator use?

Question 13easymultiple choice
Read the full Policy explanation →

Based on the exhibit, what should the administrator change if the business wants backups to be kept for 30 days instead of 7 days?

Exhibit

Azure Backup policy
- Schedule: Daily at 01:00
- Retain instant recovery snapshots: 2 days
- Retain daily backup points: 7 days
- Retain weekly backup points: Not configured
Business requirement: Keep daily backups for 30 days
Question 14easymultiple choice
Read the full Policy explanation →

A container group runs a one-time import job in Azure Container Instances. After the job finishes successfully, it should not restart. Which restart policy should you choose?

Question 15hardmultiple choice
Read the full Policy explanation →

Your application stores regulatory records in Azure Blob Storage. The records must remain in a write-once-read-many state for four years and must not be altered or deleted during that time. What should you configure?

Question 16easymultiple choice
Read the full Policy explanation →

Based on the exhibit, what should the administrator use to temporarily allow the legacy storage account to remain noncompliant without changing the policy for everyone?

Exhibit

Policy compliance report:
- Assignment: Deny public network access on storage accounts
- Scope: MG-Platform
- Noncompliant resource: stlegacy01 in RG-Legacy
- Business note: The legacy application must stay publicly reachable for 30 days during migration.
Question 17mediummulti select
Read the full Policy explanation →

A compliance team wants to identify all resources in a department that are missing an Environment tag, but they do not want to stop users from creating or changing resources. Which two choices should the administrator make? Select two.

Question 18easymultiple choice
Read the full Policy explanation →

A developer already has permission to create resource groups. The company wants to allow deployments only in the East US and West US regions. Which service should enforce this rule?

Question 19mediummultiple choice
Read the full Policy explanation →

A company wants development and production workloads for the same application to have separate budgets, separate subscription administrators, and different access controls. The central IT team still wants to apply the same security policies to both environments. What is the best design?

Question 20mediummultiple choice
Read the full Policy explanation →

An enterprise wants to enforce three governance controls for all subscriptions under a management group: allowed locations, required tags, and permitted VM sizes. The team wants a single place to assign and track compliance for all three controls. What should the administrator use?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Azure Policy sessions

Start a Azure Policy only practice session

Every question in these sessions is drawn from the Azure Policy domain — nothing else.

Related practice questions

Related AZ-104 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the AZ-104 exam test about Azure Policy?
Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Azure Policy questions in a focused session?
Yes — the session launcher on this page draws every question from the Azure Policy domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other AZ-104 topics?
Use the topic links above to move to related areas, or go back to the AZ-104 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the AZ-104 exam covers. They are not copied from any real exam or dump site.