A company uses Azure Policy to enforce tagging on resources. The security team reports that some resources are missing the required 'CostCenter' tag. You need to ensure that any resource created without the required tag is automatically remediated by adding the tag with a default value. What should you configure in Azure Policy?
DeployIfNotExists effect evaluates resources after they are created and, if they are missing the required tag, triggers a remediation task through Azure Policy. This remediation task uses a managed identity to run a nested deployment that adds the missing tag, effectively modifying the existing resource. It is the only effect among the options that both identifies and automatically fixes non-compliant existing resources, making it the correct choice for enforcing tags across the entire environment.
Why this answer
The DeployIfNotExists effect is correct because it automatically remediates non-compliant resources by deploying a tag with a default value when the required 'CostCenter' tag is missing. This effect triggers a deployment task that adds the tag, ensuring continuous compliance without manual intervention.
Exam trap
The trap here is that candidates often confuse Append (which only works during creation/update) with DeployIfNotExists (which can remediate existing resources), leading them to choose Append for automatic remediation of all resources.
How to eliminate wrong answers
Option B (AuditIfNotExists) is wrong because it only audits and reports non-compliance without performing any automatic remediation. Option C (Append) is wrong because it adds the tag during resource creation or update but does not remediate existing resources that are already missing the tag. Option D (Deny) is wrong because it blocks resource creation if the tag is missing, but the requirement is to automatically add the tag with a default value, not to deny creation.