AZ-305 Practice Question: Design identity, governance, and monitoring solutions
A company uses Azure Policy to enforce tagging on resources. The security team reports that some resources are missing the required 'CostCenter' tag. You need to ensure that any resource created without the required tag is automatically remediated by adding the tag with a default value. What should you configure in Azure Policy?
⚠ Common exam trap
Candidates often confuse Append (which only works during creation/update) with DeployIfNotExists (which can remediate existing resources), leading them to choose Append for automatic remediation of all resources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DeployIfNotExists effect
The DeployIfNotExists effect is correct because it automatically remediates non-compliant resources by deploying a tag with a default value when the required 'CostCenter' tag is missing. This effect triggers a deployment task that adds the tag, ensuring continuous compliance without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DeployIfNotExists effect
Why this is correct
DeployIfNotExists effect evaluates resources after they are created and, if they are missing the required tag, triggers a remediation task through Azure Policy. This remediation task uses a managed identity to run a nested deployment that adds the missing tag, effectively modifying the existing resource. It is the only effect among the options that both identifies and automatically fixes non-compliant existing resources, making it the correct choice for enforcing tags across the entire environment.
- ✗
AuditIfNotExists effect
Why it's wrong here
AuditIfNotExists effect checks whether a dependent resource or condition exists, but it only reports the compliance state in the compliance logs and policy evaluation results. It does not deploy anything or invoke a remediation task, so a resource missing the required tag would remain non-compliant and unchanged. While useful for visibility, it cannot enforce or correct tagging, and thus it fails to meet the company's requirement to enforce tags on existing resources.
- ✗
Append effect
Why it's wrong here
Append effect is evaluated during a resource creation or update request and adds the missing tag to the resource before the request is committed, so it can prevent non-compliant resources from being created in the future. However, Append does not act on resources that already exist without the tag, because there is no update request to intercept. As a result, it leaves the current inventory unchanged unless the resource is explicitly updated, making it insufficient for remediating existing resources.
- ✗
Deny effect
Why it's wrong here
Deny effect blocks a resource create or update operation if the resource does not meet the policy condition, such as missing a required tag. It is enforced at the moment of the API call, so it can only prevent new non-compliant resources or updates that would result in a missing tag. It does not alter or repair resources that were already provisioned before the policy was assigned, meaning existing untagged resources will remain untagged unless manually corrected.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.