AZ-305 Practice Question: Design identity, governance, and monitoring solutions
Your organization has multiple Azure subscriptions and uses Azure Blueprints to enforce governance. You need to design a blueprint that includes role assignments, policy assignments, and resource groups. Which THREE components can be included in an Azure Blueprint? (Choose three.)
⚠ Common exam trap
It's easy for candidates to confuse the target scope (management group or subscription) with the artifacts that can be included in the blueprint definition, leading them to incorrectly select management group or subscription as valid blueprint components.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Role assignments
Azure Blueprints allow you to define a repeatable set of Azure resources that adhere to your organization's standards, patterns, and requirements. Role assignments (B) are a core artifact that can be included to grant specific Azure RBAC roles at the blueprint scope, ensuring consistent access control. Policy assignments (C) are also a native blueprint artifact, enabling you to enforce compliance rules across the environment. ARM templates (E) can be included as an artifact to deploy infrastructure as code, making them a valid component of a blueprint definition.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Management group
Why it's wrong here
Management groups are hierarchical containers in Azure that organize subscriptions for governance and policy, but they serve as the assignment scope for blueprints, not as an artifact within the blueprint definition itself. A blueprint definition can be assigned to a management group, which then propagates the blueprint's artifacts (role assignments, policies, ARM templates) to child subscriptions, but you cannot include a management group as a deployable item in the blueprint. This distinction is critical: blueprints are composed of artifacts that deploy or control resources, whereas management groups are structural scopes.
- ✓
Role assignments
Why this is correct
Role assignments in Azure Blueprints are artifacts that specify which Azure RBAC role (e.g., Contributor, Reader, Owner) is granted to a named user, group, or service principal at the blueprint's assigned scope. When the blueprint is assigned, these assignments are created automatically, enabling consistent identity-based access control across multiple subscriptions. For example, a blueprint can assign the 'Security Reader' role to a central security team in every subscription, ensuring uniform visibility without manual configuration.
- ✓
Policy assignment
Why this is correct
Policy assignments are blueprint artifacts that attach an Azure Policy definition to the scope, enforcing compliance requirements such as allowed resource locations, tagging rules, or resource SKU restrictions. They enable an organization to guarantee that all resources created under an assigned subscription adhere to the same governance standards. Unlike role assignments, which control who can act, policy assignments control what actions and resources are permitted, providing a non-identity-based layer of guardrails.
- ✗
Subscription
Why it's wrong here
Subscriptions are billing and management boundaries in Azure that contain resource groups and resources, and they act as the target scope for blueprint assignments, not as artifacts within a blueprint. When you assign a blueprint to a subscription, the blueprint's artifacts (templates, policies, roles) are deployed into that subscription's context, but the subscription itself cannot be defined or created by the blueprint. Therefore, a subscription is not a component of the blueprint definition; it is the environment where the blueprint is applied.
- ✓
ARM template
Why this is correct
ARM templates are declarative JSON or Bicep files that define Azure resources and their configurations, and they can be embedded into a blueprint definition as artifacts to provision infrastructure like storage accounts, VMs, or virtual networks. Blueprints orchestrate the deployment of these templates in a defined order, often alongside RBAC and policy artifacts, to deliver a complete, repeatable environment. This makes ARM template artifacts a powerful way to ensure that the same infrastructure is rolled out identically across all subscriptions without relying on manual deployment scripts.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.