AZ-305 Practice Question: Design identity, governance, and monitoring solutions
You are designing a governance strategy for Azure resources. The company has multiple departments, each requiring separate cost tracking and policy enforcement. You need to organize resources to align with the departments while minimizing management overhead. What should you use?
⚠ Common exam trap
It's easy for candidates to confuse resource tags with a governance mechanism for policy enforcement and cost tracking, but tags are only metadata and cannot enforce policies or aggregate costs across subscriptions like management groups can.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Management groups
Management groups are the correct choice because they allow you to organize Azure subscriptions into a hierarchy that aligns with your organizational structure, enabling you to apply Azure Policy and cost management controls at scale across multiple departments. By placing each department's subscriptions into separate management groups, you can enforce department-specific policies and track costs without managing each subscription individually, minimizing administrative overhead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Management groups
Why this is correct
Management groups provide a hierarchical governance structure above subscriptions, allowing you to apply Azure Policy and RBAC assignments at scale, and aggregate cost data across multiple subscriptions for consolidated billing and compliance. They enable enterprise-level organization of your Azure estate, with policies and governance inherited down through child management groups and subscriptions.
- ✗
Azure Blueprints
Why it's wrong here
Azure Blueprints were a packaging service that bundled templates, policies, and RBAC assignments into a single deployable artifact, but they are deprecated and no longer recommended. Blueprints do not provide a persistent governance hierarchy; they simply orchestrate deployment, whereas management groups offer ongoing, inherited governance. Azure now recommends using management groups combined with policy assignments and deployment stacks as a modern replacement.
- ✗
Resource tags
Why it's wrong here
Resource tags are key-value pairs attached to resources for metadata, cost allocation, and filtering, but they are not a governance mechanism. Tags do not enforce compliance, provide hierarchical inheritance, or manage access across subscriptions. While policies can require or generate tags, tags themselves cannot organize resources for cross-subscription policy or cost management.
- ✗
Resource groups
Why it's wrong here
Resource groups are logical containers that group related resources within a single subscription, offering management and lifecycle operations like templates and access control. However, they cannot span multiple subscriptions, do not inherit policies across subscriptions, and lack the organizational hierarchy needed for enterprise-wide governance. Resource groups are operational scopes, not governance structures for the entire Azure environment.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 212-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.