Courseiva

AZ-305 Design infrastructure solutions Practice Question

Exhibit

{
  "policy": {
    "policyType": "Custom",
    "mode": "All",
    "displayName": "Allowed locations for resource groups",
    "description": "This policy enables you to restrict the locations your organization can specify when creating resource groups. Use to enforce your geo-compliance requirements.",
    "policyRule": {
      "if": {
        "allOf": [
          {
            "field": "type",
            "equals": "Microsoft.Resources/subscriptions/resourceGroups"
          },
          {
            "field": "location",
            "notIn": ["eastus", "westus", "centralus"]
          }
        ]
      },
      "then": {
        "effect": "deny"
      }
    },
    "parameters": {
      "listOfAllowedLocations": {
        "type": "Array",
        "metadata": {
          "description": "The list of allowed locations for resource groups.",
          "displayName": "Allowed locations",
          "strongType": "location"
        },
        "defaultValue": ["eastus", "westus", "centralus"]
      }
    }
  }
}

Refer to the exhibit. You are assigned an Azure policy that restricts resource group locations to eastus, westus, and centralus. A user attempts to create a resource group in 'eastus2' and receives a denial. The user argues that there are existing resources in 'eastus2' and that the policy should allow it. What is the best course of action to allow the resource group creation while maintaining compliance?

⚠ Common exam trap

The trap here is that candidates mistakenly believe a resource group's location restricts where its resources can be deployed, when in fact Azure resource groups can contain resources from any region regardless of the resource group's own location.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Instruct the user to create the resource group in an allowed location and then deploy resources to 'eastus2'

Azure Policy evaluates resource group location at creation time, not the location of individual resources within it. A resource group is a logical container that can hold resources in any region, regardless of the resource group's own location. By creating the resource group in an allowed location (eastus, westus, or centralus), the user satisfies the policy constraint while still being able to deploy resources to 'eastus2' within that resource group.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Instruct the user to create the resource group in an allowed location and then deploy resources to 'eastus2'

    Why this is correct

    The Azure Policy assignment targets the resource group resource type (Microsoft.Resources/subscriptions/resourceGroups), denying creation only when the group's location is not in the allowed list. Resource groups are logical containers, not regional boundaries; individual resources can be deployed to any region supported by the subscription, including eastus2. Instructing the user to create the resource group in an allowed location and then deploy to eastus2 satisfies the policy while preserving the intended geo-compliance controls.

  • ✗

    Add 'eastus2' to the list of allowed locations in the policy parameters

    Why it's wrong here

    Modifying the policy parameters to append 'eastus2' to the allowed list would permit resource group creation there, but that is unnecessary to meet the user's actual need—deploying resources to eastus2. Changing the policy assignment affects every scope where it is applied, potentially weakening a compliance mandate that resource groups remain in designated regions and requiring formal change approval. The user can achieve their goal without any policy change by simply placing the resource group in an already-allowed location.

  • ✗

    Create an Azure Policy exemption for the user's subscription

    Why it's wrong here

    An Azure Policy exemption applies to an existing resource, resource group, or subscription and only excludes it from compliance reporting; it does not override the Deny effect during resource creation. Because the policy denies the creation of a resource group in a disallowed location, there is no existing resource to exempt, and an exemption on the subscription would still not allow the PUT command to succeed. This makes the exemption both unnecessary and ineffective when creating the resource group in an allowed location already resolves the issue.

  • ✗

    Disable the policy assignment for that subscription

    Why it's wrong here

    Disabling the policy assignment removes all enforcement for that policy across the entire subscription, leaving every resource group location unregulated and violating the organization's geo-compliance requirements. This is an administrative overreaction that exposes all workloads to a compliance gap, whereas the user's request only requires deploying resources to eastus2. The proper action is to follow the policy—create the resource group in an allowed location—rather than globally disabling a governance control.

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.