Courseiva
Question 398 of 981
Describe Azure architecture and servicesmediumMatchingObjective-mapped

AZ-900 Describe Azure architecture and services Practice Question

Match each Azure governance tool to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Enforce rules and compliance for resources

Define repeatable set of Azure resources

Organize subscriptions hierarchically

Query and explore resources across subscriptions

Monitor and optimize cloud spending

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Azure Policy: Enforces rules and compliance across resources.

Correct matches: Azure Policy enforces rules; Azure Blueprints sets up governed environments; Management Groups organize subscriptions for policy management. Common confusions involve swapping these definitions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Azure Policy: Enforces rules and compliance across resources.

    Why this is correct

    Azure Policy is the governance service that creates, assigns, and enforces rule definitions that evaluate the properties of Azure resources against corporate standards. It can identify non-compliant resources, deny disallowed deployment actions, and trigger automatic remediation tasks, such as App Service enforcing TLS 1.2. In this way, it directly enforces compliance across the fleet of resources.

  • Azure Blueprints: Enables repeatable setup of governed environments.

    Why this is correct

    Azure Blueprints orchestrates the deployment of a fully governed environment by bundling Azure Resource Manager templates, policy assignments, role-based access control (RBAC) assignments, and resource groups into a single, versioned, repeatable definition. Each blueprint can be updated and managed as a unit, enabling organizations to stand up a new subscription that already conforms to regulatory and compliance requirements. Its purpose is repeatable environment setup, not per-resource rule evaluation.

  • Management Groups: Organize subscriptions for policy and compliance management.

    Why this is correct

    Management Groups are Azure containers that sit above subscriptions in the governance hierarchy, allowing you to organize subscriptions into logical groupings like cost centers, business units, or environments. Any policy assignment or RBAC role granted at a management group scope is automatically inherited by all descendant subscriptions, enabling centralized policy and compliance management across many subscriptions without needing to configure each one individually. This structural organization is what differentiates management groups from services that act directly on resources.

  • Azure Policy: Enables repeatable setup of governed environments.

    Why it's wrong here

    Azure Policy does not perform repeatable environment setup because it focuses on evaluating and enforcing rules against each individual resource after it is deployed. Its model is rule definition, assignment, and compliance evaluation, not deployment orchestration. The service that packages templates, policies, and role assignments for repeatable governed environments is Azure Blueprints, making this match incorrect.

  • Azure Blueprints: Organize subscriptions for policy and compliance management.

    Why it's wrong here

    Azure Blueprints does not organize or manage subscriptions hierarchically; it deploys resources and policies within an assigned scope, which could be a subscription or management group. Its job is to compose a reusable collection of resources and governance artifacts, not to create the parent-child relationship between subscriptions. Management Groups are the Azure service responsible for organizing subscriptions for policy and compliance inheritance, so this statement misattributes that function to Blueprints.

  • Management Groups: Enforces rules and compliance across resources.

    Why it's wrong here

    Management Groups provide a structural container for organizing subscriptions and applying inherited governance scope, but they do not directly enforce rules against resource properties. For example, granting a policy at a management group scope delegates the actual rule evaluation and enforcement to Azure Policy, which runs at the resource level. Since Management Groups do not themselves evaluate resource compliance, this purpose belongs to Azure Policy, not to Management Groups.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.