AZ-305 Practice Question: Design identity, governance, and monitoring solutions
Your company has a Azure subscription with multiple resource groups. You need to ensure that all resources are tagged with a 'CostCenter' tag. What should you use?
⚠ Common exam trap
It's easy for candidates to confuse Azure Policy with Azure Blueprints, thinking Blueprints can enforce tags directly, but Blueprints only define the initial state and do not enforce ongoing compliance like Policy does.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Policy
Azure Policy is the correct choice because it enforces organizational standards and compliance by evaluating resources for non-compliance with defined rules, such as requiring a specific tag. You can create a policy that audits or denies resources missing the 'CostCenter' tag, ensuring all resources are tagged automatically or during deployment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure Policy
Why this is correct
Azure Policy is the correct answer because it is a native governance service that can evaluate and enforce resource properties such as tags at scale. You can define a policy with an effect like 'deny' or 'modify' to either reject non-compliant tags or automatically append missing ones via a remediation task. Unlike RBAC, the policy engine runs independently of access control, directly inspecting each resource for compliance.
- ✗
Azure Blueprints
Why it's wrong here
Azure Blueprints is a deprecated orchestration service that bundled Azure Resource Manager templates, policies, role assignments, and other artifacts into a single package. While a blueprint could include a policy definition that enforces tagging rules, the enforcement mechanism itself is still Azure Policy; Blueprints only declared the intended state and assigned the policy. Since Blueprints is now retired, using Azure Policy directly is the correct, current method.
- ✗
Management Groups
Why it's wrong here
Management Groups provide a hierarchical structure above subscriptions for organizing governance, where you can assign Azure Policies and RBAC roles at scale. However, Management Groups do not themselves enforce tagging rules; they are simply containers. Even if you assign a tag-enforcing policy to a Management Group, it is that policy, not the Management Group, that performs the actual denial or remediation—so this option is incorrect.
- ✗
Azure RBAC
Why it's wrong here
Azure RBAC (Role-Based Access Control) governs who can perform actions on resources, such as create, modify, or delete them, via role assignments and the control plane. It does not evaluate or enforce resource-level attributes like tags; tags are purely metadata managed by the resource provider. Attempting to enforce tag rules through RBAC is fundamentally a misuse because RBAC lacks the ability to inspect or alter resource properties automatically—it only gates access.
Go deeper
Related to this question
About these practice questions
One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.