Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

You are designing a governance strategy for a new Azure subscription. The security team requires that all resources must have a 'CostCenter' tag and an 'Environment' tag. Which Azure policy effect should you use to automatically apply the tags to new resources?

⚠ Common exam trap

It's easy for candidates to confuse 'deployIfNotExists' with 'modify', thinking both can automatically apply tags, but 'deployIfNotExists' requires a separate remediation task and does not apply tags inline during resource creation, making 'modify' the correct choice for automatic tag application on new resources.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

modify

The 'modify' effect is correct because it can automatically append or replace missing tags on new or existing non-compliant resources during resource creation or update. Unlike 'deployIfNotExists', which only runs remediation tasks after creation, 'modify' applies the tags inline as part of the resource creation request, ensuring compliance without requiring a separate remediation task.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    audit

    Why it's wrong here

    The audit effect only evaluates resources against the policy definition and writes compliance details to the activity log; it never changes the resource. If a resource is missing required tags, audit flags it as non-compliant but does not add or fix anything. Therefore it cannot enforce a tagging standard by itself, only report on it.

  • ✓

    modify

    Why this is correct

    The modify effect is designed to add, replace, or remove tags on a resource during creation or update, and with a remediation task it can also apply tags to existing non-compliant resources. This makes it the appropriate effect for an automated tagging governance strategy, since it actively brings resources into compliance without blocking them. It supports both addOrReplace and add operations, giving flexible tag enforcement.

  • ✗

    deny

    Why it's wrong here

    The deny effect prevents a request from being created or updated when the resource does not meet the policy condition, such as lacking a required tag. It does not apply tags to the resource; it simply blocks the operation. While deny can enforce a required tag by forcing callers to specify it, it cannot remediate existing untagged resources or automatically assign a default value.

  • ✗

    deployIfNotExists

    Why it's wrong here

    The deployIfNotExists effect is intended to deploy a separate auxiliary resource (like a network watcher or diagnostic storage account) when a policy condition isn't met, not to alter the tags of the evaluated resource. It cannot add or replace tags directly on the triggering resource, and it does not run during creation. For tag governance, it would be an incorrect choice because it fails to modify the resource that is out of compliance.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.