Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

A large enterprise has a management group hierarchy with 50 subscriptions. They need to enforce that every resource group must have a 'CostCenter' tag and that any new resource group without that tag is automatically denied creation. Additionally, they need to ensure that only the Finance team can modify tags on any resource. They also want to generate monthly compliance reports showing which resources are non-compliant. Which combination of Azure services should they use?

⚠ Common exam trap

Test-takers frequently confuse Azure Security Center (for security compliance) with Azure Policy (for governance compliance), or assume Azure Monitor can generate compliance reports when it is designed for metrics and logs, not policy evaluation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Policy for tag enforcement, Azure RBAC for scoping tag modification to Finance, and Azure Policy for compliance reporting

Azure Policy can enforce the 'CostCenter' tag on resource groups via a 'deny' effect policy, Azure RBAC can restrict tag modification to the Finance team by assigning the 'Tag Contributor' role at the appropriate scope, and Azure Policy's compliance reporting (via the Azure Policy Compliance dashboard or export to Log Analytics) provides monthly reports on non-compliant resources without needing additional services.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Azure Policy for tag enforcement, Azure RBAC for scoping tag modification to Finance, and Azure Policy for compliance reporting

    Why this is correct

    The correct combination uses Azure Policy to assign a tag requirement at the root or intermediate management group, so the Deny or Modify effects apply consistently across every subscription and the Policy compliance dashboard gives finance stakeholders a continuously updated report of noncompliant resources. Azure RBAC then grants the Finance team the Tag Contributor built-in role at the necessary scope, letting them edit tag keys and values without broader write access. Because compliance reporting is generated from the same Azure Policy assignments, no separate monitoring or security tool is needed. This is the only option that both enforces the policy and correctly identifies the reporting service.

  • ✗

    Azure Blueprints with tag policy and Azure RBAC, and Azure Security Center for compliance

    Why it's wrong here

    Azure Blueprints is not needed here because the tag requirement is a single policy or initiative assignment, not a full environment archetype with multiple artifacts such as ARM templates and role assignments; Blueprints is also deprecated in favor of Policy/Initiatives and Template Specs, so depending on it is poor architectural judgment. RBAC alone can permit the Finance team to add tags, but it cannot force anyone to add them or stop a developer from creating a resource missing the tag—actual enforcement requires an Azure Policy effect. Azure Security Center, now Microsoft Defender for Cloud, reports on security posture and workload security, not tag governance, so this stack would leave the enterprise without a tag compliance report.

  • ✗

    Azure Policy for tag enforcement, Azure Management Groups for governance, and Azure Monitor for compliance reports

    Why it's wrong here

    Management Groups provide an efficient policy assignment boundary and help organize a large subscription hierarchy, but they are only containers—they do not evaluate resources or produce compliance results; the actual evaluation and reporting must come from Azure Policy. Azure Monitor collects platform metrics, activity logs, and resource diagnostics and can alert on operational conditions, but it has no native view of policy compliance or tag presence. This pairing also omits Azure RBAC, so there is no defined mechanism restricting tag edits to the Finance team, meaning any contributor could change tags. A complete solution must combine policy assignment for enforcement, role-based access control for delegation, and the Azure Policy compliance dashboard for reporting.

  • ✗

    Azure Policy for tag enforcement, Azure RBAC for tag modification, and Azure Security Center for compliance

    Why it's wrong here

    The first two components are correct—Azure Policy should enforce the tag rule, and Azure RBAC should constrain tag modifications to Finance—so the flaw is the compliance-reporting service. Microsoft Defender for Cloud (formerly Azure Security Center) evaluates security configurations such as endpoint protection, encryption, firewall rules, and secure-score recommendations; it does not audit whether resources carry a required cost-center tag. Tag compliance is measured by Azure Policy's built-in compliance view, which shows percentage compliance and the per-resource evaluation state for the assignment. Because this option puts a security tool in place of Azure Policy's reporting function, it is incomplete and incorrect.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.