AZ-900 Describe Azure management and governance Practice Question
Which feature of Azure subscriptions allows an organization to separate billing and access management for different departments?
⚠ Common exam trap
Many exam-takers confuse Azure tags or resource groups as mechanisms for separating billing and access, when in fact only multiple subscriptions provide independent billing and administrative boundaries.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Multiple subscriptions
Multiple subscriptions allow an organization to create separate billing invoices and independent access management boundaries for different departments. Each subscription has its own billing relationship and can be assigned distinct Azure AD tenants or RBAC configurations, enabling cost tracking and administrative isolation per department.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Resource groups
Why it's wrong here
A resource group is a logical container used to group related resources for an application, enabling organization by lifecycle, security scope, and management policies. However, resource groups exist within exactly one subscription and have no billing relationship of their own; all resources in the same subscription appear on the same invoice and share the same cost center. Moving a resource between resource groups does not change which subscription or billing profile pays for it, so resource groups cannot create departmental billing separation.
- ✓
Multiple subscriptions
Why this is correct
Multiple subscriptions provide the only correct billing boundary among these options because each Azure subscription is a distinct billing entity linked to an enrollment or billing profile. Each subscription generates its own invoice or cost statement and can have its own payment method, budget, and Azure RBAC scope. This allows a department to own its subscription, see its specific usage charges, and control access independently, making multiple subscriptions the right mechanism for separating costs and permissions.
- ✗
Azure tags
Why it's wrong here
Azure tags are key-value metadata pairs that can be attached to resources or resource groups to enable fine-grained filtering and grouping in cost reports and monitoring views. While tags help categorize spending for internal show-back or charge-back reporting, they do not alter the underlying billing relationship. All resources in a subscription share the same invoice and billing account regardless of their tags, so tags cannot create separate billing boundaries or departmental invoice separation.
- ✗
Azure RBAC
Why it's wrong here
Azure RBAC (Role-Based Access Control) governs identity permissions by assigning roles (e.g., Reader, Contributor, Owner) to users or service principals at a specific scope such as a subscription, resource group, or resource. RBAC determines who can perform actions, but it is completely independent of billing and financial management; it does not define which department pays for what. Because billing separation is an accounting function tied to subscription boundaries, RBAC alone cannot create cost isolation or separate invoices for departments.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Azure Cost Management and Billing
Key term
RBAC
RBAC is a method of restricting network access based on the roles of individual users within an organization, where permissions are assigned to roles rather than to individuals directly.
Key term
Feature
A feature is a distinct unit of functionality that delivers value to the user, often managed and tracked throughout the software development lifecycle.
About these practice questions
Courseiva writes every AZ-900 question from scratch — 981 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.