AZ-305 Practice Question: Design identity, governance, and monitoring solutions
Exhibit
{
"policyRule": {
"if": {
"allOf": [
{
"field": "type",
"equals": "Microsoft.Compute/virtualMachines"
},
{
"field": "Microsoft.Compute/virtualMachines/sku.name",
"notEquals": "Standard_DS2_v2"
}
]
},
"then": {
"effect": "deny"
}
}
}Refer to the exhibit. You are reviewing an Azure Policy definition. Which virtual machines will be denied?
⚠ Common exam trap
The trap here is that candidates may misinterpret 'notEquals' as denying the specified SKU, when in fact it denies everything except that SKU, leading them to incorrectly choose option C.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
All virtual machines except those with SKU Standard_DS2_v2
The Azure Policy definition uses a 'deny' effect with a condition that checks if the virtual machine's SKU field is not equal to 'Standard_DS2_v2'. This means any VM whose SKU does not match 'Standard_DS2_v2' will be denied. Only VMs with the exact SKU 'Standard_DS2_v2' will be allowed, making option D correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
No virtual machines because the condition is invalid
Why it's wrong here
The condition is valid. Azure Policy's field operator supports 'notEquals' against the alias 'Microsoft.Compute/virtualMachines/sku.name', so the policy definition will parse and evaluate normally. The deny effect is not triggered for every VM; it is triggered only when the condition evaluates true, i.e., for SKUs other than Standard_DS2_v2. A syntactically invalid condition would cause a deployment or evaluation error, not a blanket denial of all virtual machines.
- ✗
All virtual machines regardless of SKU
Why it's wrong here
This option overstates the policy effect. Because the condition uses 'notEquals' with Standard_DS2_v2, any VM whose SKU matches that exact value fails the condition (condition false), so the deny effect is skipped. Therefore a Standard_DS2_v2 VM would be allowed, meaning not all VMs are denied regardless of SKU. Only VMs using any other SKU name satisfy the condition and are denied.
- ✗
Only virtual machines with SKU Standard_DS2_v2
Why it's wrong here
This option inverts the logic. The deny effect is applied when the condition is true, and the condition is true only when the SKU is not Standard_DS2_v2. Consequently, a VM with SKU Standard_DS2_v2 does not match the condition and is explicitly allowed by this policy. The only virtual machines that are denied are those that do not have that SKU, so saying 'only' Standard_DS2_v2 VMs are denied is backwards.
- ✓
All virtual machines except those with SKU Standard_DS2_v2
Why this is correct
This is the correct behavior. The policy definition evaluates the field 'Microsoft.Compute/virtualMachines/sku.name' and applies the deny effect when that value is 'notEquals' to Standard_DS2_v2. As a result, any virtual machine using another SKU will be denied, while a Standard_DS2_v2 VM will be allowed. This is a common pattern for restricting compute SKUs to an approved allowlist using Azure Policy.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.