AZ-305 Practice Question: Design identity, governance, and monitoring solutions
A company is designing a governance solution for a large Azure environment with multiple subscriptions. They need to ensure that all resources are deployed only in approved Azure regions and that all resources have a specific tag 'CostCenter'. They also need to be able to delegate management of policies to individual business units while maintaining central control. Which two features should be included in the design? (Choose two.)
⚠ Common exam trap
The trap here is assuming that RBAC or ARM templates can enforce resource properties like location and tags, when they only control permissions or deployment-time settings, not ongoing compliance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Management groups to organize subscriptions and apply policies hierarchically.
Azure Policy with deny effects enforces that resources can only be created in approved regions and must have the required tag. Management groups provide a hierarchical structure to apply these policies across subscriptions and allow delegation to business units while maintaining central oversight. Together, they deliver scalable governance with central control and delegated administration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Management groups to organize subscriptions and apply policies hierarchically.
Why this is correct
Management groups allow hierarchical organization of subscriptions and inheritance of policies and role assignments. By assigning policies at a management group, all subscriptions inherit them. This provides central control while allowing delegation to business units through separate management groups with their own policies.
- ✗
Role-based access control (RBAC) assignments to restrict who can create resources in certain regions.
Why it's wrong here
RBAC controls who can perform actions, but it cannot enforce resource properties like location or tags. A user with contributor rights could still create resources in any region or without tags. RBAC is about permissions, not policy compliance. It does not meet the requirement for enforcing region and tag rules.
- ✗
Azure Blueprints to define and assign policies across subscriptions.
Why it's wrong here
Azure Blueprints can assign policies, but they are being deprecated and are not the recommended approach for new governance designs. They also do not provide the same hierarchical inheritance as management groups. While they can bundle policies, they are not the primary feature for central control and delegation.
- ✗
Azure Resource Manager templates to enforce tagging and region constraints at deployment time.
Why it's wrong here
ARM templates can include parameters and constraints, but they do not enforce compliance for resources created outside the template. They are deployment-time only and cannot prevent non-compliant resources from being created through other means. They do not provide ongoing governance or central control across subscriptions.
- ✓
Azure Policy with a deny effect for allowed locations and a deny effect for required tags.
Why this is correct
Azure Policy can enforce allowed locations and required tags using the deny effect. This prevents non-compliant resources from being created. It can be assigned at management group scope to apply across subscriptions. This meets the requirement for enforcing region and tag compliance centrally.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.