AZ-900 Describe Azure management and governance Practice Question
A global company creates a new Azure subscription for each major project. To ensure compliance and consistency, the governance team needs a single, versioned, auditable package that, when assigned to a subscription, automatically deploys a standard set of Azure Policy assignments, role assignments, a resource group structure, and a pre-configured virtual network. The solution must allow these packages to be updated centrally and have changes tracked for auditing. Which Azure service should the governance team use?
⚠ Common exam trap
Many candidates confuse Azure Blueprints with Azure Policy or ARM templates, failing to recognize that Blueprints uniquely combine multiple artifact types into a single, versioned, auditable package that can be centrally managed and updated across subscriptions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Blueprints
Azure Blueprints is the correct service because it provides a single, versioned, auditable package that can be assigned to a subscription to orchestrate the deployment of Azure Policy assignments, role assignments, resource groups, and resource templates (like a virtual network). Blueprints support versioning and central update management, with changes tracked in the blueprint definition history for auditing. This aligns exactly with the requirement for a governance team to enforce compliance and consistency across subscriptions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Policy
Why it's wrong here
Azure Policy enforces and audits compliance rules, but it cannot deploy resources like virtual networks or create resource groups. It only handles policy definitions and assignments, not the full package of resources, roles, and policies.
When this WOULD be correct
In a scenario where the governance team needs to enforce specific compliance rules (e.g., requiring a specific tag on all resources) across multiple subscriptions without deploying infrastructure or role assignments, Azure Policy would be the correct service.
- ✓
Azure Blueprints
Why this is correct
Azure Blueprints allows you to define a repeatable set of Azure resources and governance artifacts (policies, role assignments, resource groups, ARM templates) that can be assigned to subscriptions. Blueprints are versioned and auditable, ideal for a single package that enforces a standard environment.
- ✗
Azure Resource Manager templates
Why it's wrong here
ARM templates deploy Azure resources declaratively, but they do not natively assign Azure Policy or role assignments. While you can use ARM templates for resource deployment, they lack the centralized versioning and auditing of governance artifacts that Blueprints provide.
When this WOULD be correct
A company needs to deploy a consistent set of resources (e.g., VMs, storage, networking) across multiple environments using infrastructure as code, with the ability to parameterize deployments for different environments. ARM templates are the correct choice for repeatable, declarative resource deployment.
- ✗
Management groups
Why it's wrong here
Management groups are hierarchy containers that organize subscriptions for centralized governance, enabling inherited policy and RBAC assignments across multiple subscriptions. However, they do not themselves deploy any Azure resources or define a package of artifacts such as ARM templates, policies, and role assignments. Their purpose is to apply and aggregate compliance controls, not to provision environments, which is why they cannot serve as a repeatable definition of a standard environment.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Azure BlueprintsCorrect answer▾
Why this is correct
Azure Blueprints allows you to define a repeatable set of Azure resources and governance artifacts (policies, role assignments, resource groups, ARM templates) that can be assigned to subscriptions. Blueprints are versioned and auditable, ideal for a single package that enforces a standard environment.
✗Azure PolicyWrong answer — click to see why▾
Why this is wrong here
Azure Policy only enforces individual compliance rules (policies) and does not provide a versioned, auditable package that deploys multiple resource types like role assignments, resource groups, and virtual networks in a coordinated manner.
★ When this WOULD be the correct answer
In a scenario where the governance team needs to enforce specific compliance rules (e.g., requiring a specific tag on all resources) across multiple subscriptions without deploying infrastructure or role assignments, Azure Policy would be the correct service.
Why candidates choose this
Candidates may confuse Azure Policy with Azure Blueprints because both are used for governance, but they overlook that Blueprints is designed for deploying a complete environment package, while Policy only handles rule enforcement.
✗Azure Resource Manager templatesWrong answer — click to see why▾
Why this is wrong here
Azure Resource Manager templates can deploy infrastructure but lack built-in versioning, centralized update tracking, and audit capabilities for the entire package. They do not provide a single, versioned, auditable package that can be assigned to a subscription and updated centrally.
★ When this WOULD be the correct answer
A company needs to deploy a consistent set of resources (e.g., VMs, storage, networking) across multiple environments using infrastructure as code, with the ability to parameterize deployments for different environments. ARM templates are the correct choice for repeatable, declarative resource deployment.
Why candidates choose this
Candidates may confuse ARM templates with Azure Blueprints because both can deploy resources, but they overlook Blueprints' additional governance features like versioning, assignment tracking, and integration with Azure Policy and RBAC.
Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Azure Cost Management and Billing
Key term
Governance
Governance is the framework of policies, processes, and controls that ensures IT activities align with business goals and comply with regulations.
Key term
Group
A group is a collection of users, devices, or other objects that are assigned permissions and policies together for simplified management in identity and governance systems like Microsoft Entra ID.
About these practice questions
One of 981 original AZ-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.