AZ-305 Azure Policy Practice Question
Your organization needs to ensure that all Azure resources are compliant with corporate security policies. You need to design a solution that can enforce policies at scale, audit compliance, and automatically remediate non-compliant resources. Which THREE Azure services should you include?
⚠ Common exam trap
AZ-305 often tests the confusion between Azure Policy (enforcement/audit) and Azure Blueprints (packaging and deployment). Note that Azure Blueprints is deprecated/retired, so it should not be selected as the answer; the enforcement, audit, and remediation capabilities are provided by Azure Policy and Azure Automation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Policy
Azure Policy (A) is the core governance service that defines, assigns, and evaluates policy definitions and initiatives at management-group, subscription, and resource-group scopes, providing the enforce and audit-at-scale capabilities required. Azure Automation (C) supplies runbooks and, via its integration with Azure Policy's deployIfNotExists and modify effects (or remediation tasks), performs the automatic remediation of non-compliant resources. Azure Blueprints is deprecated/retired and should not be used for new designs, so it is not a valid AZ-305 answer. Azure Monitor (B) is for telemetry, metrics, and alerts rather than policy enforcement or remediation, and Azure RBAC (D) governs who can perform actions on resources through role assignments, not whether resource configurations comply with security policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure Policy
Why this is correct
Azure Policy enforces corporate security standards at scale by evaluating resource properties against built-in or custom definitions, denying non-compliant deployments and auditing existing estate state. Its remediation tasks deploy correction via managed identities, satisfying the automatic remediation requirement. Policy assignments scoped to management groups apply governance consistently across all subscriptions.
- ✗
Azure Monitor
Why it's wrong here
Monitors health, not policy enforcement.
- ✓
Azure Automation
Why this is correct
Azure Automation provides the runbook engine that executes remediation logic against non-compliant resources, satisfying the automatic remediation requirement. Policy assignments alone detect drift but cannot act; Automation runbooks, triggered by Azure Policy remediation tasks or alerts, apply the corrective configuration at scale across subscriptions.
- ✗
Azure RBAC
Why it's wrong here
Manages access, not compliance policies.
- ✗
Azure Blueprints
Why it's wrong here
Azure Blueprints packages policy assignments, role assignments and resource templates into a repeatable definition applied to subscriptions, enforcing governance consistently at scale. It complements Policy's auditing and remediation by standardising deployments across many subscriptions from a single governed artefact.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Azure Database Migration Service
Key term
Role Based Access Control Design
Role Based Access Control Design is the process of planning and defining who can access specific resources in a system based on their job role, not their identity.
Key term
Azure Site Recovery
Azure Site Recovery is a Microsoft Azure service that keeps your business applications and data running by automatically replicating them to a secondary location and failing over if the primary site goes down.
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.