Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

You are designing a governance solution for a Microsoft Azure environment that contains multiple subscriptions. You need to ensure that all resources are compliant with corporate security policies. The solution must automatically remediate non-compliant resources. What should you include in the design?

⚠ Common exam trap

It's easy for candidates to confuse Azure Policy's audit-only effects (like AuditIfNotExists) with the automatic remediation capability, or they mistakenly think Azure Blueprints can handle ongoing compliance enforcement, when in fact Blueprints are a one-time deployment orchestration tool and do not provide continuous remediation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Policy with DeployIfNotExists effect

Azure Policy with the DeployIfNotExists effect is the correct choice because it automatically remediates non-compliant resources by triggering a deployment (e.g., via a template) when a resource is created or updated and does not meet the policy condition. This ensures continuous compliance with corporate security policies without manual intervention, as the effect can also be assigned a remediation task to fix existing resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure RBAC custom roles

    Why it's wrong here

    Azure RBAC custom roles define granular identity permissions (e.g., which principals can perform read/write actions on specific resource types), but they do not evaluate resource configuration or enforce compliance. Governance remediation requires inspecting properties such as tags, diagnostics, or security settings and acting on drift, which is outside RBAC's authorization scope. Thus RBAC addresses 'who can do what,' not 'is the resource compliant,' so it cannot remediate non-compliant resources.

  • ✓

    Azure Policy with DeployIfNotExists effect

    Why this is correct

    Azure Policy with the DeployIfNotExists effect evaluates resources against policy definitions and, when a non-compliant resource lacks a required configuration, triggers a deployment to remediate it automatically. This deployment is performed by a managed identity defined in the policy assignment, and remediation tasks can be run on demand or continuously to fix existing and newly created resources. Because it couples compliance assessment with actual resource modification, it directly satisfies the requirement for automated governance remediation.

  • ✗

    Azure Resource Graph queries

    Why it's wrong here

    Azure Resource Graph is a high-performance query service that allows you to explore and inventory resources across subscriptions using the Kusto Query Language, making it ideal for building complex reports or dashboards. While you can filter for resources that are missing tags or have non-compliant settings, Resource Graph is read-only and cannot modify resources or trigger remediation actions. Therefore it helps discover the problem but offers no enforcement or automatic correction capability within the governance solution.

  • ✗

    Azure Blueprints

    Why it's wrong here

    Azure Blueprints package reusable Azure resources such as policies, RBAC role assignments, resource groups, and ARM templates into a single assignable definition for consistent environment initialization. However, Blueprints apply these artifacts only at assignment time; they do not continuously evaluate existing resources against compliance rules or remediate drift after deployment. This makes Blueprints suitable for establishing a baseline, but not for ongoing automated remediation of non-compliant resources.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.