AZ-305 Practice Question: Design identity, governance, and monitoring solutions
You are designing a governance strategy for a new Azure subscription. The security team requires that all resources must have a 'CostCenter' tag and an 'Environment' tag. Which Azure policy effect should you use to automatically apply the tags to new resources?
⚠ Common exam trap
It's easy for candidates to confuse 'deployIfNotExists' with 'modify', thinking both can automatically apply tags, but 'deployIfNotExists' requires a separate remediation task and does not apply tags inline during resource creation, making 'modify' the correct choice for automatic tag application on new resources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
modify
The 'modify' effect is correct because it can automatically append or replace missing tags on new or existing non-compliant resources during resource creation or update. Unlike 'deployIfNotExists', which only runs remediation tasks after creation, 'modify' applies the tags inline as part of the resource creation request, ensuring compliance without requiring a separate remediation task.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
audit
Why it's wrong here
The audit effect only evaluates resources against the policy definition and writes compliance details to the activity log; it never changes the resource. If a resource is missing required tags, audit flags it as non-compliant but does not add or fix anything. Therefore it cannot enforce a tagging standard by itself, only report on it.
- ✓
modify
Why this is correct
The modify effect is designed to add, replace, or remove tags on a resource during creation or update, and with a remediation task it can also apply tags to existing non-compliant resources. This makes it the appropriate effect for an automated tagging governance strategy, since it actively brings resources into compliance without blocking them. It supports both addOrReplace and add operations, giving flexible tag enforcement.
- ✗
deny
Why it's wrong here
The deny effect prevents a request from being created or updated when the resource does not meet the policy condition, such as lacking a required tag. It does not apply tags to the resource; it simply blocks the operation. While deny can enforce a required tag by forcing callers to specify it, it cannot remediate existing untagged resources or automatically assign a default value.
- ✗
deployIfNotExists
Why it's wrong here
The deployIfNotExists effect is intended to deploy a separate auxiliary resource (like a network watcher or diagnostic storage account) when a policy condition isn't met, not to alter the tags of the evaluated resource. It cannot add or replace tags directly on the triggering resource, and it does not run during creation. For tag governance, it would be an incorrect choice because it fails to modify the resource that is out of compliance.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.