hardmultiple choiceObjective-mapped

A large enterprise has a management group hierarchy with 50 subscriptions. They need to enforce that every resource group must have a 'CostCenter' tag and that any new resource group without that tag is automatically denied creation. Additionally, they need to ensure that only the Finance team can modify tags on any resource. They also want to generate monthly compliance reports showing which resources are non-compliant. Which combination of Azure services should they use?

Question 1hardmultiple choice
Full question →

A large enterprise has a management group hierarchy with 50 subscriptions. They need to enforce that every resource group must have a 'CostCenter' tag and that any new resource group without that tag is automatically denied creation. Additionally, they need to ensure that only the Finance team can modify tags on any resource. They also want to generate monthly compliance reports showing which resources are non-compliant. Which combination of Azure services should they use?

Answer choices

Why each option matters

Good practice is not just finding the correct option. The wrong answers often show the exact trap the exam wants you to fall into.

A

Best answer

Azure Policy for tag enforcement, Azure RBAC for scoping tag modification to Finance, and Azure Policy for compliance reporting

Correct. Azure Policy enforces the tag requirement and provides compliance reports; RBAC restricts tag modification to the Finance team.

B

Distractor review

Azure Blueprints with tag policy and Azure RBAC, and Azure Security Center for compliance

Blueprints are not necessary for this requirement, and Azure Security Center does not generate tag compliance reports.

C

Distractor review

Azure Policy for tag enforcement, Azure Management Groups for governance, and Azure Monitor for compliance reports

Management Groups help organize subscriptions but do not enforce policies or generate compliance reports; Azure Monitor does not produce policy compliance reports.

D

Distractor review

Azure Policy for tag enforcement, Azure RBAC for tag modification, and Azure Security Center for compliance

Azure Security Center is focused on security recommendations, not tag compliance reporting.

Common exam trap

Common exam trap: NAT rules depend on direction and matching traffic

NAT is not only about the public address. The inside/outside interface roles and the ACL or rule that matches traffic are just as important.

Technical deep dive

How to think about this question

NAT questions usually test address translation, overload/PAT behaviour, static mappings and whether the right traffic is being translated. Read the interface direction and address terms carefully.

KKey Concepts to Remember

  • Static NAT maps one inside address to one outside address.
  • PAT allows many inside hosts to share one public address using ports.
  • Inside local and inside global describe the private and translated addresses.
  • NAT ACLs identify traffic for translation, not always security filtering.

TExam Day Tips

  • Identify inside and outside interfaces first.
  • Check whether the scenario needs static NAT, dynamic NAT or PAT.
  • Do not confuse NAT matching ACLs with normal packet-filtering intent.

Related practice questions

Related AZ-305 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

More questions from this exam

Keep practising from the same exam bank, or move into a focused topic page if this question exposed a weak area.

FAQ

Questions learners often ask

What does this AZ-305 question test?

Static NAT maps one inside address to one outside address.

What is the correct answer to this question?

The correct answer is: Azure Policy for tag enforcement, Azure RBAC for scoping tag modification to Finance, and Azure Policy for compliance reporting — Azure Policy is the primary tool for enforcing tag compliance; an 'audit' or 'deny' policy can prevent resource group creation without the required tag. Azure RBAC allows scoping the ability to modify tags to the Finance team via a custom role. Azure Policy itself provides built-in compliance reporting (via Compliance dashboard) to generate monthly reports. Azure Blueprints can bundle policies but are not required. Azure Security Center focuses on security, not governance tags. Azure Monitor does not natively produce policy compliance reports.

What should I do if I get this AZ-305 question wrong?

Then try more questions from the same exam bank and focus on understanding why the wrong options are tempting.

Discussion

Loading comments…

Sign in to join the discussion.