AZ-305 Practice Question: Design identity, governance, and monitoring solutions
Exhibit
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"resources": [
{
"type": "Microsoft.Authorization/policyAssignments",
"apiVersion": "2021-06-01",
"name": "audit-vm-managed-disks",
"properties": {
"policyDefinitionId": "/providers/Microsoft.Authorization/policyDefinitions/06a5a3b5-7a6b-4c5d-8e6f-7a8b9c0d1e2f",
"scope": "/subscriptions/12345678-1234-1234-1234-123456789abc",
"parameters": {}
}
}
]
}Refer to the exhibit. You are deploying an ARM template that assigns a policy to audit virtual machines not using managed disks. After deployment, you need to verify that the policy assignment is working. Which Azure CLI command should you run?
⚠ Common exam trap
Many exam-takers confuse the command for listing policy assignments with the command for viewing compliance states, leading them to choose `az policy state list` (Option B) instead of `az policy assignment list` (Option A) when the question asks to verify that the assignment itself is working.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
az policy assignment list --subscription 12345678-1234-1234-1234-123456789abc
The `az policy assignment list` command retrieves all policy assignments in the specified subscription, including the one deployed via the ARM template. This allows you to confirm that the policy assignment exists and is properly configured. To verify that the policy is actually evaluating resources and producing compliance states, you would then use `az policy state list` to see the compliance results, but the question specifically asks to verify that the assignment itself is working, which is done by listing assignments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
az policy assignment list --subscription 12345678-1234-1234-1234-123456789abc
Why this is correct
The az policy assignment list command enumerates policy assignments at the specified subscription scope, and because the ARM template was deployed at that scope, the newly created assignment object appears as an entry in the output. It returns each assignment’s name, ID, scope, associated definition, and parameters, allowing you to verify that the deployment actually registered the assignment. This is the only option that directly queries the assignment resource rather than definitions or derived evaluation records.
- ✗
az policy state list --resource-group myResourceGroup
Why it's wrong here
az policy state list --resource-group myResourceGroup returns the current compliance states (Compliant/NonCompliant) of resources within that resource group, not the policy assignments themselves. A state record is an aggregate of evaluation results across existing assignments, so it cannot indicate whether a specific assignment was just deployed; it only reflects the effects already applied to resources. To validate the assignment entity, you need to inspect assignment metadata directly.
- ✗
az policy definition list --subscription 12345678-1234-1234-1234-123456789abc
Why it's wrong here
az policy definition list --subscription ... lists the library of available policy definitions, both built-in and custom, that exist in the subscription, but it does not show assignments created from those definitions. An assignment links a definition to a scope with parameters and enforcement mode; seeing a definition in this list gives no evidence that any scope is bound to it. The output omits assignment-specific properties such as scope, excluded scopes, parameter values, and enforcement mode.
- ✗
az policy event list --subscription 12345678-1234-1234-1234-123456789abc
Why it's wrong here
az policy event list --subscription ... exposes policy evaluation events, such as compliance state changes for resources, along with timestamps and the policy definition/assignment IDs involved. Events are time-bounded records used for auditing and troubleshooting; they may indirectly reflect an assignment creation but are not a reliable, queryable representation of the assignment object itself. They also require explicit time filters and have retention limits, making them unsuitable for verifying deployment success.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.