Courseiva

AZ-305 Design infrastructure solutions Practice Question

You are designing a governance strategy for multiple Azure subscriptions. You need to ensure that all resources in a specific subscription are deployed only in the West US region. Additionally, any new resource group must contain a tag named 'Environment' with a value of 'Production'. What combination of Azure Policy initiatives should you assign?

⚠ Common exam trap

It's easy for candidates to confuse the 'Require a tag on resource groups' policy with the 'Inherit a tag from the resource group' policy, mistakenly thinking inheritance will enforce the tag on the resource group itself, when in fact inheritance applies tags to resources within the group, not to the group itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign the 'Allowed Locations' policy and the 'Require a tag on resource groups' policy to the subscription

It assigns both the 'Allowed Locations' policy and the 'Require a tag on resource groups' policy directly to the subscription. The 'Allowed Locations' policy restricts resource deployment to the West US region, while the 'Require a tag on resource groups' policy ensures that every new resource group includes the 'Environment' tag with a value of 'Production'. Assigning both policies at the subscription scope meets both requirements without unnecessary inheritance or scope issues.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Assign the 'Allowed Locations' policy to the management group and the 'Require a tag on resource groups' policy to the subscription

    Why it's wrong here

    Assigning 'Allowed Locations' to the management group applies the policy to every subscription under that group, which could unintentionally restrict regions for other workloads outside the intended subscription. While the 'Require a tag on resource groups' policy on the subscription is correct in itself, the overly broad scope of the location policy makes this combination invalid for a governance strategy focused on a single subscription.

  • ✓

    Assign the 'Allowed Locations' policy and the 'Require a tag on resource groups' policy to the subscription

    Why this is correct

    This is correct because both policies are assigned at the subscription scope, directly targeting the specific subscription that needs governance. 'Allowed Locations' restricts where resources can be deployed, and 'Require a tag on resource groups' mandates that each resource group carry a required tag, satisfying the dual constraints of location and tagging without affecting other subscriptions.

  • ✗

    Assign the 'Allowed Locations' policy to the subscription and the 'Inherit a tag from the resource group' policy to the management group

    Why it's wrong here

    The 'Inherit a tag from the resource group' policy applies an existing resource group tag to its child resources, but it does not require or enforce that a resource group itself has a tag; for that, you need the 'Require a tag on resource groups' policy. Additionally, assigning this policy to the management group would cascade inheritance behavior across all subscriptions, and since it doesn't enforce the tag requirement, this combination fails to meet the governance goal.

  • ✗

    Assign a single Azure Policy definition that includes both the allowed location and require tag effects

    Why it's wrong here

    A single Azure Policy definition can only have one effect per policy rule; you cannot combine a Deny effect for allowed locations with a Deny effect for missing tags in the same definition. Even though a policy rule can contain multiple logical conditions, they all contribute to a single effect, so you would need separate policy definitions (or a single initiative/policy set) to enforce both requirements. Therefore, this option is syntactically and semantically invalid.

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.