AZ-900 Describe Azure management and governance Practice Question
A large enterprise manages hundreds of Azure subscriptions. The central governance team wants to ensure that every resource deployed across all subscriptions always has two required tags: 'Department' and 'CostCenter'. If a resource is created without these tags, the governance policy must automatically add the missing tags with placeholder values (e.g., 'Department: Unknown') and generate a compliance report. The team does not want to rely on user training or manual audits. Which Azure service should the team use to meet these requirements?
⚠ Common exam trap
Many exam-takers confuse Azure Policy with Azure Blueprints, thinking Blueprints can enforce tags automatically, but Blueprints only deploys policies at creation time and does not provide ongoing remediation or compliance reporting for existing resources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Policy
Azure Policy is the correct service because it can enforce tagging rules across all subscriptions in a management group. By using a policy definition with the 'modify' effect, Azure Policy can automatically add missing tags with placeholder values (e.g., 'Department: Unknown') during resource creation or at scale via remediation tasks. It also integrates with Azure Policy compliance reports to provide continuous governance without relying on user training or manual audits.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure Policy
Why this is correct
Azure Policy can evaluate resources for compliance with defined tagging rules. Using the 'Append' effect, it can automatically add missing tags with specified values when a resource is created or updated. It also provides compliance reports.
- ✗
Azure Cost Management
Why it's wrong here
Azure Cost Management is a monitoring, analysis, and optimization service that tracks spend, provides budgets, and sends alerts. It relies on tags already applied to resources to group and filter cost data, but it has no capability to modify resources or enforce tagging rules, so it cannot automatically add or correct tags across subscriptions. Thus, while useful for cost governance, it is not the correct tool for enforcing tag compliance.
When this WOULD be correct
A question asking which service provides cost analysis, budgeting, and cost anomaly alerts for Azure subscriptions, without requiring policy enforcement or tag remediation.
- ✗
Azure Blueprints
Why it's wrong here
Azure Blueprints packages Azure Policy definitions, role assignments, and resource templates into a deployable artifact. While a blueprint can include a policy that enforces tags, the enforcement itself is performed by Azure Policy. Blueprints are used for orchestration, not real-time enforcement.
When this WOULD be correct
A question asks: 'A company needs to deploy a standardized environment that includes a specific set of Azure resources, role assignments, and policies across multiple subscriptions. Which service should they use?' In that scenario, Azure Blueprints would be correct because it packages resource templates, policies, and RBAC assignments into a single deployable artifact.
- ✗
Azure Resource Groups
Why it's wrong here
Azure Resource Groups are logical containers that group related Azure resources for lifecycle management, access control, and organization. They do not contain any built-in logic to enforce tag creation or update resources within them, as resource groups themselves are not policy enforcement points. Tagging must be applied by Azure Policy or other management tools, making Resource Groups an incorrect answer for automatic tag enforcement.
When this WOULD be correct
A question asks: 'Which Azure object is used to organize and manage related resources, such as grouping all resources for a specific application, and provides a scope for applying role-based access control and policies?' In that context, Azure Resource Groups would be the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Azure PolicyCorrect answer▾
Why this is correct
Azure Policy can evaluate resources for compliance with defined tagging rules. Using the 'Append' effect, it can automatically add missing tags with specified values when a resource is created or updated. It also provides compliance reports.
✗Azure Cost ManagementWrong answer — click to see why▾
Why this is wrong here
Azure Cost Management provides cost analysis and budgeting, but it cannot automatically enforce or remediate missing tags on resources. It lacks policy enforcement capabilities.
★ When this WOULD be the correct answer
A question asking which service provides cost analysis, budgeting, and cost anomaly alerts for Azure subscriptions, without requiring policy enforcement or tag remediation.
Why candidates choose this
Candidates may associate tags with cost tracking and assume Cost Management handles tag enforcement, but it only reports on existing tags, not enforces them.
✗Azure BlueprintsWrong answer — click to see why▾
Why this is wrong here
Azure Blueprints is used to orchestrate the deployment of resource templates and policy assignments, but it does not automatically add missing tags to existing resources or generate compliance reports. The requirement for automatic remediation and compliance reporting is a core feature of Azure Policy, not Blueprints.
★ When this WOULD be the correct answer
A question asks: 'A company needs to deploy a standardized environment that includes a specific set of Azure resources, role assignments, and policies across multiple subscriptions. Which service should they use?' In that scenario, Azure Blueprints would be correct because it packages resource templates, policies, and RBAC assignments into a single deployable artifact.
Why candidates choose this
Candidates may confuse Blueprints with Policy because both are used for governance and can include policy definitions. They might think Blueprints can enforce tags automatically, not realizing that Blueprints only assigns policies but does not provide the automatic remediation or compliance reporting described.
✗Azure Resource GroupsWrong answer — click to see why▾
Why this is wrong here
Azure Resource Groups are logical containers for resources, not a governance service. They cannot automatically enforce or add tags across subscriptions; they lack policy enforcement and remediation capabilities.
★ When this WOULD be the correct answer
A question asks: 'Which Azure object is used to organize and manage related resources, such as grouping all resources for a specific application, and provides a scope for applying role-based access control and policies?' In that context, Azure Resource Groups would be the correct answer.
Why candidates choose this
Candidates may confuse resource groups with governance tools because resource groups can be used to organize resources and apply some management controls, but they do not provide automated policy enforcement or tag remediation.
Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Azure Cost Management and Billing
Key term
Azure Policy
Azure Policy is a service in Microsoft Azure that lets you create, assign, and manage rules to ensure your resources stay compliant with your company standards and service-level agreements.
Key term
Management group
A Management group is a container in Microsoft Azure that helps you organize and manage access, policies, and compliance across multiple Azure subscriptions.
About these practice questions
One of 981 original AZ-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.