AZ-305 Design infrastructure solutions Practice Question
You are designing a governance strategy for multiple Azure subscriptions. You need to ensure that all resources in a specific subscription are deployed only in the West US region. Additionally, any new resource group must contain a tag named 'Environment' with a value of 'Production'. What combination of Azure Policy initiatives should you assign?
⚠ Common exam trap
It's easy for candidates to confuse the 'Require a tag on resource groups' policy with the 'Inherit a tag from the resource group' policy, mistakenly thinking inheritance will enforce the tag on the resource group itself, when in fact inheritance applies tags to resources within the group, not to the group itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign the 'Allowed Locations' policy and the 'Require a tag on resource groups' policy to the subscription
It assigns both the 'Allowed Locations' policy and the 'Require a tag on resource groups' policy directly to the subscription. The 'Allowed Locations' policy restricts resource deployment to the West US region, while the 'Require a tag on resource groups' policy ensures that every new resource group includes the 'Environment' tag with a value of 'Production'. Assigning both policies at the subscription scope meets both requirements without unnecessary inheritance or scope issues.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assign the 'Allowed Locations' policy to the management group and the 'Require a tag on resource groups' policy to the subscription
Why it's wrong here
Assigning 'Allowed Locations' to the management group applies the policy to every subscription under that group, which could unintentionally restrict regions for other workloads outside the intended subscription. While the 'Require a tag on resource groups' policy on the subscription is correct in itself, the overly broad scope of the location policy makes this combination invalid for a governance strategy focused on a single subscription.
- ✓
Assign the 'Allowed Locations' policy and the 'Require a tag on resource groups' policy to the subscription
Why this is correct
This is correct because both policies are assigned at the subscription scope, directly targeting the specific subscription that needs governance. 'Allowed Locations' restricts where resources can be deployed, and 'Require a tag on resource groups' mandates that each resource group carry a required tag, satisfying the dual constraints of location and tagging without affecting other subscriptions.
- ✗
Assign the 'Allowed Locations' policy to the subscription and the 'Inherit a tag from the resource group' policy to the management group
Why it's wrong here
The 'Inherit a tag from the resource group' policy applies an existing resource group tag to its child resources, but it does not require or enforce that a resource group itself has a tag; for that, you need the 'Require a tag on resource groups' policy. Additionally, assigning this policy to the management group would cascade inheritance behavior across all subscriptions, and since it doesn't enforce the tag requirement, this combination fails to meet the governance goal.
- ✗
Assign a single Azure Policy definition that includes both the allowed location and require tag effects
Why it's wrong here
A single Azure Policy definition can only have one effect per policy rule; you cannot combine a Deny effect for allowed locations with a Deny effect for missing tags in the same definition. Even though a policy rule can contain multiple logical conditions, they all contribute to a single effect, so you would need separate policy definitions (or a single initiative/policy set) to enforce both requirements. Therefore, this option is syntactically and semantically invalid.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.