Courseiva

AZ-305 Design infrastructure solutions Practice Question

You are designing a governance and compliance solution for a large Azure environment with multiple subscriptions. The solution must enforce tagging policies, restrict resource types, and ensure compliance with regulatory standards. Which THREE Azure services or features should you use? (Choose three.)

⚠ Common exam trap

Watch out — candidates often confuse Azure Resource Graph's discovery and query capabilities with actual enforcement, but it only provides read-only resource inventory and cannot apply or enforce governance policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Management Groups

Azure Management Groups (B) are essential for organizing subscriptions hierarchically, enabling the application of governance policies and compliance controls at scale. They allow you to enforce tagging policies, restrict resource types, and ensure regulatory compliance across multiple subscriptions by inheriting Azure Policy and RBAC assignments from the root management group down to individual subscriptions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Resource Graph

    Why it's wrong here

    Azure Resource Graph is a query engine that enables efficient exploration of resource properties across subscriptions, but it performs no enforcement or mutation. While it can be used to audit current state (e.g., find un-tagged VMs), it cannot assign policies, deny deployments, or apply compliance remediations. Its role is discovery and inventory, not governance enforcement.

  • ✓

    Azure Management Groups

    Why this is correct

    Azure Management Groups provide a hierarchical structure above subscriptions, allowing you to organize and govern enterprise subscription fleets at scale. Policies and role-based access control assignments placed on a management group are inherited by all descendant subscriptions and resource groups, enabling consistent compliance baselining. They are fundamental for applying governance in a multi-subscription enterprise.

  • ✗

    Azure Cost Management

    Why it's wrong here

    Azure Cost Management is a financial operations service centered on monitoring, analyzing, and optimizing cloud spending, with capabilities such as budgets, anomaly detection, and cost allocation. Although it can trigger alerts or budgets, it operates entirely in the cost domain and cannot define or enforce resource configuration rules, tagging standards, or allowed resource types. Thus it does not address governance/compliance enforcement.

  • ✓

    Azure Blueprints (or Policy Initiatives)

    Why this is correct

    Azure Blueprints (or Policy Initiatives) support the packaging of Azure Policy definitions, RBAC role assignments, and Azure Resource Manager templates into a single deployable artifact for compliance. By orchestrating these components together, they enable repeatable, audited provisioning of governed environments. Blueprints are deprecated in favor of deployment stacks and initiative definitions, but the concept remains a valid compliance packaging tool. If referring to Policy Initiatives, they group policies to achieve a specific compliance goal.

  • ✓

    Azure Policy

    Why this is correct

    Azure Policy is the enforcement engine that evaluates resources for compliance with rules, applying effects such as deny, audit, append, and modify. It can enforce tagging conventions, restrict allowed resource types/locations, and automatically remediate non-compliant resources at scale. Unlike query-based or cost-based tools, Azure Policy actively governs resource state and enforces organizational standards.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.