Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Your organization is designing a governance solution for multiple Azure subscriptions. You need to enforce that all resources are created in specific Azure regions (East US and West Europe only). Additionally, any resource group must have a cost center tag. Which THREE Azure components should you use? (Choose three.)

⚠ Common exam trap

Test-takers frequently confuse Azure Blueprints (which packages and deploys resources) with Azure Policy (which enforces rules), or they overlook that Management Groups are needed to apply policies across multiple subscriptions efficiently.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Policy

Azure Policy is correct because it allows you to define and enforce rules for resource creation, such as restricting allowed locations to East US and West Europe. By assigning a built-in or custom policy definition to a management group or subscription, you can prevent any resource from being created outside the specified regions. This directly addresses the requirement to enforce regional compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Azure Policy

    Why this is correct

    Azure Policy is the correct service for implementing resource governance rules such as allowed region constraints and mandatory tags. It evaluates resources against business rules and can automatically deny non-compliant resource creation, audit existing resources, or remediate drift. Policies are assigned at management group, subscription, or resource group scopes, making it the primary tool in a multi-subscription governance architecture.

  • ✗

    Azure Blueprints

    Why it's wrong here

    Azure Blueprints is an obsolete orchestration service that used to combine ARM templates, policies, and RBAC assignments into a single 'blueprint' for environment deployment. Microsoft deprecated Blueprints in June 2020 and is retiring the service, directing customers to use template specs, Bicep modules, and Azure Policy initiatives instead. Because it is no longer supported and only provided packaging rather than ongoing enforcement, it cannot be the governance solution for your design.

  • ✓

    Policy Initiative

    Why this is correct

    A Policy Initiative (or policy set definition) is a curated bundle of one or more Azure Policy definitions. Assigning an initiative lets you enforce multiple related rules together, such as a compliance framework, while maintaining centralized versioning and exception management. In this scenario, an initiative would be the ideal way to group 'allowed location' and 'required tag' policies, but it is functionally a capability of Azure Policy rather than a separate governance solution.

  • ✓

    Management Groups

    Why this is correct

    Management Groups create a hierarchy above subscriptions, letting you apply Azure Policy, Azure RBAC, and inherited resource configuration to every subscription under a node. They are indispensable for organizing a large enterprise environment and cascading governance to many subscriptions, but they only provide the traversal scope; the actual rule evaluation and enforcement still happens through Azure Policy definitions and assignments. Thus, Management Groups are a prerequisite for, not a substitute for, Azure Policy.

  • ✗

    Role-Based Access Control (RBAC)

    Why it's wrong here

    Azure RBAC is an authorization system that controls what identities can do to Azure resources, such as who can read, write, or delete a resource. It cannot enforce where resources are created or whether tags are present, so it does not address regional compliance or metadata governance. RBAC is orthogonal to Azure Policy; it limits access but never inspects or enforces resource properties.

About these practice questions

One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.