Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Exhibit

{
  "properties": {
    "displayName": "GDPR Compliance Policy",
    "scope": "/subscriptions/12345678-1234-1234-1234-123456789abc/resourceGroups/RG-Prod",
    "policyDefinitionId": "/providers/Microsoft.Authorization/policyDefinitions/abc123",
    "parameters": {},
    "enforcementMode": "Default"
  }
}

Refer to the exhibit. You are a security administrator reviewing a custom Azure Policy assignment. The policy definition with ID 'abc123' is an initiative containing two policies: one that audits storage accounts with blob public access enabled and one that deploys a diagnostic setting for network security groups. The scope includes a production resource group. However, the compliance state shows 'Non-compliant' for several resources. What is the most likely reason for the non-compliance?

⚠ Common exam trap

Test-takers frequently assume all policy effects (like 'DeployIfNotExists') automatically remediate non-compliant resources, but in reality, they only mark non-compliance and require a separate remediation task to deploy the required configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The diagnostic setting deployment policy requires a remediation task to bring non-compliant resources into compliance.

The policy that deploys a diagnostic setting for network security groups is a 'DeployIfNotExists' (DINE) policy. DINE policies do not automatically remediate existing non-compliant resources; they require a remediation task to be created and run, which will deploy the diagnostic settings to bring the resources into compliance. The audit-only policy for storage accounts does not require remediation, but the DINE policy's non-compliance indicates that the diagnostic settings are missing and need to be deployed via a remediation task.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The scope is incorrectly targeting the resource group, missing the subscription.

    Why it's wrong here

    This option misidentifies the problem. Azure Policy assignments can target a resource group, a subscription, or a management group; a resource group scope is perfectly valid and restricts the policy to resources within that group. The subscription is not required to make the scope valid, so this is not the cause of the non-compliance. The actual issue is that the DeployIfNotExists policy needs an explicit remediation task to deploy the required diagnostic setting.

  • ✗

    The audit policy is preventing the creation of storage accounts with public access.

    Why it's wrong here

    This option misunderstands the effect of the audit policy. The audit effect only evaluates compliance and records the result in the activity log; it never blocks or prevents resource creation, because that would require a Deny effect. In this exhibit, the storage accounts are non-compliant due to missing diagnostic settings, not because the audit policy stopped them from being created. The block on public access, if any, would come from a separate Deny policy—which is not present here.

  • ✗

    The enforcement mode is set to 'Default' which disables policy evaluation.

    Why it's wrong here

    The enforcement mode 'Default' does not disable evaluation. 'Default' means the policy effect is enforced and compliance will be evaluated normally; to disable evaluation, you would set enforcement mode to 'DoNotEnforce'. Since this assignment uses 'Default', the policy is actively checking resources, and the non-compliant status is accurate. Therefore, the enforcement mode is not the reason the diagnostic setting is missing.

  • ✓

    The diagnostic setting deployment policy requires a remediation task to bring non-compliant resources into compliance.

    Why this is correct

    A DeployIfNotExists policy is designed to deploy a resource when the policy condition is met, but it does not automatically apply the deployment during evaluation. After the evaluation cycle, the policy enters a non-compliant state and a remediation task must be run to deploy the diagnostic setting to the storage account. Without that remediation task, even though the policy is correctly assigned and enforced, the configuration remains missing. Hence, the storage account lacks the diagnostic setting because the needed remediation task has not been executed.

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.