Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Your company uses Azure Resource Manager templates for infrastructure deployment. You need to ensure that all deployments are validated against organizational policies before resources are provisioned. Which Azure service should you use?

⚠ Common exam trap

AZ-305 often tests the confusion between Azure Policy and Azure Blueprints, where candidates mistakenly think Blueprints enforces policies, but Blueprints only packages them; the actual validation and enforcement is done by Azure Policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Policy

Azure Policy is the correct service because it enforces organizational standards and assesses compliance at scale. It evaluates resources during deployment (via the ARM template deployment process) and can deny non-compliant resources before they are provisioned. Specifically, policies with a 'deny' effect block the deployment if the resource violates the policy, ensuring validation against organizational policies. This directly meets the requirement to validate deployments before resources are provisioned.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure RBAC

    Why it's wrong here

    Azure RBAC governs who can perform actions on resources, not whether template configurations comply with organisational rules. It is tempting because RBAC is the default access-control mechanism for Azure deployments, and it would be correct when the requirement is restricting which principals may create or modify resources.

  • ✗

    Management Groups

    Why it's wrong here

    Management Groups organise subscriptions into a hierarchy for inherited policy and access assignment, but they do not evaluate ARM template deployments before resources are provisioned. They are tempting because they are the standard way to apply governance across many subscriptions, which is correct for scoping policy rather than validating a deployment.

  • ✓

    Azure Policy

    Why this is correct

    Azure Policy evaluates resource properties against organisational rules and blocks non-compliant provisioning, satisfying the requirement that deployments be validated before resources are created. Assigned at management group, subscription or resource group scope, its deny effect prevents policy-violating resources from being deployed at all.

  • ✗

    Azure Blueprints

    Why it's wrong here

    Azure Blueprints packages role assignments, policies and templates into an assignable definition but does not validate ARM template deployments against policy before provisioning. It is tempting because Blueprints governs environments at scale, which is correct when you need repeatable compliant environment definitions rather than deployment-time validation.

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.