AZ-305 Practice Question: Design identity, governance, and monitoring solutions
Exhibit
{
"policyRule": {
"if": {
"allOf": [
{
"field": "type",
"equals": "Microsoft.Compute/virtualMachines"
},
{
"field": "Microsoft.Compute/virtualMachines/sku.name",
"notEquals": "Standard_D2s_v3"
}
]
},
"then": {
"effect": "deny"
}
}
}Refer to the exhibit. You are implementing an Azure Policy to control VM SKU deployment. You assign this policy to a subscription. A developer attempts to deploy a virtual machine with SKU Standard_DS2_v2. What is the outcome?
⚠ Common exam trap
Many candidates confuse the 'deny' effect with 'audit' or 'disabled', assuming the policy only logs non-compliance or allows deployment with a flag, when in fact 'deny' actively blocks the resource creation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The deployment is denied.
The Azure Policy in the exhibit uses a 'deny' effect, which explicitly blocks any deployment that does not match the allowed VM SKUs. Since Standard_DS2_v2 is not in the allowed list, the policy engine evaluates the request during deployment and rejects it before any resource is created. This results in the deployment being denied entirely, not just audited or flagged.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The deployment is audited and logged.
Why it's wrong here
This describes the behavior of the Audit effect, not Deny. With a Deny effect, Azure Policy actively interrupts the resource creation request and returns a conflict response, preventing the VM from being provisioned. While Azure Activity Log records the failed put request for troubleshooting, that logging is incidental to the effect and not the same as an audit compliance state.
- ✗
The deployment is allowed.
Why it's wrong here
The policy rule evaluates the VM SKU against the notEquals condition; any SKU other than Standard_D2s_v3 matches, triggering the Deny effect. Azure Policy is enforced synchronously during deployment, so the request fails before any resource is created. Allowed deployments occur only when the SKU equals Standard_D2s_v3, which is outside the denied condition.
- ✗
The VM is deployed but flagged as non-compliant.
Why it's wrong here
This reflects the Audit effect's outcome—the resource is created and its compliance state is reported as NonCompliant in Azure Policy compliance. A Deny effect, by contrast, rejects the PUT request during policy evaluation, so no VM exists to be flagged. You cannot have a non-compliant resource when provisioning itself is blocked.
- ✓
The deployment is denied.
Why this is correct
The policy's condition (if the VM SKU is not equal to Standard_D2s_v3) evaluates to true for the attempted SKU, and the then block applies the Deny effect. Azure Policy returns a 403 Forbidden or similar conflict, and the deployment fails. This is the intended hard enforcement for restricting VM SKUs in the assigned scope.
Go deeper
Related to this question
About these practice questions
One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.