Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Your company has a Azure subscription with multiple resource groups. You need to ensure that all resources are tagged with a 'CostCenter' tag. What should you use?

⚠ Common exam trap

It's easy for candidates to confuse Azure Policy with Azure Blueprints, thinking Blueprints can enforce tags directly, but Blueprints only define the initial state and do not enforce ongoing compliance like Policy does.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Policy

Azure Policy is the correct choice because it enforces organizational standards and compliance by evaluating resources for non-compliance with defined rules, such as requiring a specific tag. You can create a policy that audits or denies resources missing the 'CostCenter' tag, ensuring all resources are tagged automatically or during deployment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Azure Policy

    Why this is correct

    Azure Policy is the correct answer because it is a native governance service that can evaluate and enforce resource properties such as tags at scale. You can define a policy with an effect like 'deny' or 'modify' to either reject non-compliant tags or automatically append missing ones via a remediation task. Unlike RBAC, the policy engine runs independently of access control, directly inspecting each resource for compliance.

  • ✗

    Azure Blueprints

    Why it's wrong here

    Azure Blueprints is a deprecated orchestration service that bundled Azure Resource Manager templates, policies, role assignments, and other artifacts into a single package. While a blueprint could include a policy definition that enforces tagging rules, the enforcement mechanism itself is still Azure Policy; Blueprints only declared the intended state and assigned the policy. Since Blueprints is now retired, using Azure Policy directly is the correct, current method.

  • ✗

    Management Groups

    Why it's wrong here

    Management Groups provide a hierarchical structure above subscriptions for organizing governance, where you can assign Azure Policies and RBAC roles at scale. However, Management Groups do not themselves enforce tagging rules; they are simply containers. Even if you assign a tag-enforcing policy to a Management Group, it is that policy, not the Management Group, that performs the actual denial or remediation—so this option is incorrect.

  • ✗

    Azure RBAC

    Why it's wrong here

    Azure RBAC (Role-Based Access Control) governs who can perform actions on resources, such as create, modify, or delete them, via role assignments and the control plane. It does not evaluate or enforce resource-level attributes like tags; tags are purely metadata managed by the resource provider. Attempting to enforce tag rules through RBAC is fundamentally a misuse because RBAC lacks the ability to inspect or alter resource properties automatically—it only gates access.

About these practice questions

One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.