Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Exhibit

{
  "policy": {
    "if": {
      "anyOf": [
        {
          "field": "type",
          "equals": "Microsoft.Network/virtualNetworks"
        },
        {
          "field": "type",
          "equals": "Microsoft.Network/networkSecurityGroups"
        }
      ]
    },
    "then": {
      "effect": "deny"
    }
  },
  "parameters": {}
}

Refer to the exhibit. You are an Azure administrator for a company that enforces a policy that no virtual networks or network security groups can be created. However, a developer reports that they successfully created a virtual network. What is the most likely reason the policy did not block the creation?

⚠ Common exam trap

Candidates often assume a policy definition automatically applies to all resources in the tenant, but Azure Policy requires explicit assignment to a scope, and without proper scope coverage, the policy has no effect.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The policy was assigned to a scope that does not include the subscription or resource group where the virtual network was created.

Azure Policy assignments are scoped to a specific management group, subscription, or resource group. If the policy was assigned to a scope that does not include the subscription or resource group where the developer created the virtual network, the policy would not apply, and the creation would succeed. The policy definition itself may be valid, but without proper assignment scope, it cannot enforce the deny effect.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The policy definition contains a syntax error.

    Why it's wrong here

    The policy definition is valid JSON; Azure Policy's schema validation would flag any syntax errors before assignment. A syntax error typically surfaces as a validation failure in the portal or via an error when creating the definition, not as a silently unevaluated resource. Since the virtual network was permitted, the issue lies not in malformed JSON but in whether the policy was correctly assigned and within scope.

  • ✗

    The policy only applies to network security groups, not virtual networks.

    Why it's wrong here

    Azure Policy definitions can target multiple resource types by using a `type` condition with an array or appending a suffix like `Microsoft.Network/virtualNetworks` or `Microsoft.Network/networkSecurityGroups`. The policy in question explicitly includes both resource types in its `if` block, so it is not limited to network security groups. If it were NSG-only, virtual networks would never be evaluated, but the definition's condition clearly applies to virtual networks as well.

  • ✓

    The policy was assigned to a scope that does not include the subscription or resource group where the virtual network was created.

    Why this is correct

    Azure Policy assignments are scoped to management groups, subscriptions, or resource groups, and resources are only evaluated if they fall within that chosen scope. If the virtual network was created in a subscription or resource group that is not covered by the policy assignment (or outside the management group hierarchy), the deny effect never triggers. Even a correctly defined policy with a valid scope only affects resources inside that scope; a virtual network outside it will be created without restriction.

  • ✗

    The policy effect should be 'append' instead of 'deny'.

    Why it's wrong here

    The `deny` effect is the correct choice when a policy is meant to proactively block a non-compliant resource from being created. `append` is used to automatically add fields or tags during resource creation or update, but it does not prevent the operation; it merely augments the request. Since the goal is to prohibit virtual networks that don't meet the requirement, `deny` is appropriate, and changing to `append` would allow the virtual network to be created.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.