AZ-305 Practice Question: Design identity, governance, and monitoring solutions
Your company uses Azure Resource Manager templates for infrastructure deployment. You need to ensure that all deployments are validated against organizational policies before resources are provisioned. Which Azure service should you use?
⚠ Common exam trap
AZ-305 often tests the confusion between Azure Policy and Azure Blueprints, where candidates mistakenly think Blueprints enforces policies, but Blueprints only packages them; the actual validation and enforcement is done by Azure Policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Policy
Azure Policy is the correct service because it enforces organizational standards and assesses compliance at scale. It evaluates resources during deployment (via the ARM template deployment process) and can deny non-compliant resources before they are provisioned. Specifically, policies with a 'deny' effect block the deployment if the resource violates the policy, ensuring validation against organizational policies. This directly meets the requirement to validate deployments before resources are provisioned.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure RBAC
Why it's wrong here
Azure RBAC governs who can perform actions on resources, not whether template configurations comply with organisational rules. It is tempting because RBAC is the default access-control mechanism for Azure deployments, and it would be correct when the requirement is restricting which principals may create or modify resources.
- ✗
Management Groups
Why it's wrong here
Management Groups organise subscriptions into a hierarchy for inherited policy and access assignment, but they do not evaluate ARM template deployments before resources are provisioned. They are tempting because they are the standard way to apply governance across many subscriptions, which is correct for scoping policy rather than validating a deployment.
- ✓
Azure Policy
Why this is correct
Azure Policy evaluates resource properties against organisational rules and blocks non-compliant provisioning, satisfying the requirement that deployments be validated before resources are created. Assigned at management group, subscription or resource group scope, its deny effect prevents policy-violating resources from being deployed at all.
- ✗
Azure Blueprints
Why it's wrong here
Azure Blueprints packages role assignments, policies and templates into an assignable definition but does not validate ARM template deployments against policy before provisioning. It is tempting because Blueprints governs environments at scale, which is correct when you need repeatable compliant environment definitions rather than deployment-time validation.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.