AZ-305 Practice Question: Design identity, governance, and monitoring solutions
Exhibit
Refer to the exhibit.
$resources = Get-AzResource | Where-Object {$_.Tags -eq $null}
foreach ($resource in $resources) {
$tags = @{"Environment"="Unknown"}
Update-AzTag -ResourceId $resource.ResourceId -Tag $tags -Operation Merge
}Refer to the exhibit. You run this PowerShell script in an Azure subscription. The script executes successfully. What is the outcome?
⚠ Common exam trap
Watch out — candidates often assume `Update-AzTag` with Merge behaves like a full replacement (Option A) or applies to all resources (Option C), when in fact Merge only adds or updates the specified tags and only targets resources that match the resource ID pipeline input — in this case, resources without tags due to the `Where-Object` filter.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
All resources without tags get the tag 'Environment' with value 'Unknown'.
The `Update-AzTag` cmdlet with the `-Operation Merge` parameter merges the specified tags into existing resource tags without removing any existing tags. When a resource already has tags, only the specified tag is added or updated; when a resource has no tags, the specified tag is applied. This matches option B: all resources without tags get the tag 'Environment' with value 'Unknown'.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
All existing tags are replaced with 'Environment'='Unknown'.
Why it's wrong here
This option misinterprets the tag operation as a destructive replacement. When the script merges tags, Update-AzTag with -Operation Merge modifies only the keys supplied in the hashtable, so the 'Environment' key is added or updated while all other existing tag keys and values are preserved. The behavior described here would only occur if the script used -Operation Replace, and even then the affected set would not be all resources because the script filters for untagged resources only.
- ✓
All resources without tags get the tag 'Environment' with value 'Unknown'.
Why this is correct
The PowerShell script successfully identifies all Azure resources that currently possess no tags. It then systematically iterates through these untagged resources, utilising cmdlets such as `Update-AzResource` to apply the 'Environment' tag with the value 'Unknown' to each. This precise mechanism ensures that all previously untagged resources within the subscription are now categorised, satisfying the successful execution implied by the stem.
- ✗
All resources in the subscription get the tag 'Environment' with value 'Unknown'.
Why it's wrong here
This option overstates the scope of the script's effect. The script first selects only Azure resources whose Tags property is empty, typically via Get-AzResource and a Where-Object filter, and then applies 'Environment'='Unknown' to that filtered subset. Resources in the subscription that already have any tags are excluded from the loop, so the tag is not applied to every resource. Therefore, the statement incorrectly assumes all resources receive the tag, whereas only previously untagged resources are modified.
- ✗
The script fails because Update-AzTag does not support merge.
Why it's wrong here
This option is factually incorrect because Update-AzTag does support the Merge operation. The cmdlet's -Operation parameter accepts Merge, Replace, and Delete values, and Merge is actually the default operation, meaning it is designed exactly for adding or updating tags without replacing the existing tag set. A script that calls Update-AzTag with a tag hashtable and relies on merging will not fail due to an unsupported operation. Failures would instead come from invalid parameter syntax, a missing ResourceId, or a resource that no longer exists.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.