AZ-900 Describe Azure management and governance Practice Question
A global company wants to organize its Azure resources by department and project. They need to enforce cost allocation and apply governance policies consistently across all subscriptions. Which two Azure features should they use together? (Select two.)
⚠ Common exam trap
Many candidates confuse Azure Policy (a governance enforcement tool) with a structural organization feature, or they think resource groups can span subscriptions, when in fact management groups are the correct hierarchical container for organizing subscriptions and enforcing policies at scale.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Management groups
Management groups (B) are correct because they provide a hierarchical structure above subscriptions, enabling consistent governance and policy assignment across multiple subscriptions. Tags (C) are correct because they allow you to attach metadata (e.g., department and project) to resources for cost allocation and organization. Together, management groups enforce policies at scale, while tags enable granular cost tracking and reporting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Resource groups
Why it's wrong here
Resource groups act as logical containers that group resources for a single application or workload, sharing the same lifecycle and management boundaries. However, a resource group exists within a single subscription and cannot span subscriptions, so it cannot provide enterprise-wide organization. For a global company needing to organize resources across many subscriptions, resource groups lack the necessary scope and governance capabilities.
When this WOULD be correct
When a question asks for organizing resources within a single subscription by lifecycle or environment (e.g., dev, test, prod), and the goal is to manage access and permissions at that level, Resource groups would be the correct answer.
- ✓
Management groups
Why this is correct
Management groups support hierarchical organization of Azure subscriptions, enabling centralized governance, policy assignment, and access control across a global enterprise. They can nest subscriptions under a common structure, allowing consistent RBAC and compliance at scale. This makes them the appropriate mechanism for organizing resources by business unit, region, or other top-level groupings.
- ✓
Tags
Why this is correct
Tags are key-value pairs that can be assigned to resources, resource groups, or subscriptions to categorize them according to business units, environments, cost centers, or owners. They provide a straightforward way to organize metadata for cost allocation, reporting, and operational filtering, but they do not affect governance or access. Tags are a complementary organizational tool, often used alongside management groups for finer-grained labeling.
- ✗
Azure Policies
Why it's wrong here
Azure Policy is a governance service used to define and enforce rules on resources, such as allowed locations or required SKUs. It is not an organizational structure itself, but rather a mechanism to audit, enforce, and ensure compliance across resources. Policies can be assigned at management groups or subscriptions, but they do not offer a scheme for arranging resources; they operate within an organizational hierarchy you create with management groups.
When this WOULD be correct
A question asks: 'A company needs to enforce that all resources in a subscription are deployed only in specific regions and must have a specific tag. Which Azure feature should they use?' In that scenario, Azure Policies would be correct.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Management groupsCorrect answer▾
Why this is correct
Management groups support hierarchical organization of Azure subscriptions, enabling centralized governance, policy assignment, and access control across a global enterprise. They can nest subscriptions under a common structure, allowing consistent RBAC and compliance at scale. This makes them the appropriate mechanism for organizing resources by business unit, region, or other top-level groupings.
✗Resource groupsWrong answer — click to see why▾
Why this is wrong here
Resource groups are logical containers for resources but do not provide hierarchical management across subscriptions for cost allocation and governance; they are scoped to a single subscription.
★ When this WOULD be the correct answer
When a question asks for organizing resources within a single subscription by lifecycle or environment (e.g., dev, test, prod), and the goal is to manage access and permissions at that level, Resource groups would be the correct answer.
Why candidates choose this
Candidates often confuse resource groups as a cross-subscription organizational tool because they are used to group related resources, but they lack the hierarchical and policy inheritance capabilities needed for enterprise-wide management.
✗Azure PoliciesWrong answer — click to see why▾
Why this is wrong here
Azure Policies enforce compliance rules but do not organize resources by department/project or enforce cost allocation; they are used to apply governance rules, not to structure resources for cost tracking.
★ When this WOULD be the correct answer
A question asks: 'A company needs to enforce that all resources in a subscription are deployed only in specific regions and must have a specific tag. Which Azure feature should they use?' In that scenario, Azure Policies would be correct.
Why candidates choose this
Candidates may confuse governance enforcement with organizational structure, thinking that policies can also categorize resources, but policies lack the hierarchical grouping and cost allocation capabilities of management groups and tags.
Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Azure Cost Management and Billing
Key term
Policy assignment
Policy assignment is the process of attaching a set of rules or permissions to a specific resource, user, or group so that those rules are enforced in a cloud or IT environment.
Key term
Governance
Governance is the framework of policies, processes, and controls that ensures IT activities align with business goals and comply with regulations.
About these practice questions
Courseiva writes every AZ-900 question from scratch — 981 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.