Courseiva
Describe Azure management and governancemediumMultiple ChoiceObjective-mapped

AZ-900 Describe Azure management and governance Practice Question

A company has an Azure subscription that contains hundreds of virtual machines (VMs) across multiple resource groups. The security team needs to enforce two governance rules: 1) All VMs must use managed disks. 2) All VMs must be deployed only in the East US region. The team wants to assign a single governance artifact that combines both rules so that the compliance state is evaluated as a group. The solution must not require assigning each rule individually. Which Azure feature should the team use to define and assign this combined set of rules?

⚠ Common exam trap

Watch out — candidates often confuse Azure Blueprints (which can include policy assignments) with the native grouping mechanism of Azure Policy initiatives, failing to recognize that Blueprints is an orchestration tool, not the dedicated artifact for combining policy rules into a single compliance evaluation unit.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Azure Policy initiative (policy set) definition

Azure Policy initiative (policy set) definitions allow you to group multiple individual policy definitions into a single, combined set of rules. By assigning the initiative, both the managed disks requirement and the East US region restriction are evaluated together as a single compliance artifact, meeting the requirement to avoid assigning each rule individually.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Azure Policy initiative (policy set) definition

    Why this is correct

    An Azure Policy initiative definition (also known as a policy set) groups multiple related policy definitions into a single assignable unit. When assigned to a management group, subscription, or resource group, the initiative evaluates compliance as an aggregated set, so a fleet of hundreds of VMs can be assessed against a combined compliance posture (e.g., all VM security and configuration policies) in one dashboard. Initiatives also support the same remediation tasks and exemptions as individual policies, making them the appropriate construct for large-scale governance.

  • Azure Policy group definition

    Why it's wrong here

    Azure Policy does not contain a resource type or definition called 'policy group definition.' The term 'policy set' is an informal synonym for an initiative definition, but the official API and portal name is 'initiative definition.' Therefore, 'policy group definition' is not a selectable artifact; to group policies, you must create an initiative definition and assign it to the desired scope.

    When this WOULD be correct

    If the question asked for a way to logically organize multiple policy assignments under a single management group for reporting purposes, a custom grouping concept might be considered, but Azure Policy itself does not offer a 'group definition' resource.

  • Azure Blueprints artifact

    Why it's wrong here

    Azure Blueprints can include policy assignments as artifacts, but its primary purpose is to orchestrate the deployment of resource templates, policies, and RBAC assignments. It is not specifically for grouping policy definitions to evaluate compliance as a combined set. Assignments of individual policies within Blueprints are still separate.

    When this WOULD be correct

    A company needs to deploy a standardized environment that includes a set of Azure resources (e.g., VMs, storage, networking) along with pre-configured policies and role assignments. The team wants to ensure that every new subscription or resource group follows the same template and governance settings. In this scenario, Azure Blueprints would be the correct answer because it packages multiple artifacts (including policies) into a single deployable blueprint.

  • Azure compliance bundle

    Why it's wrong here

    There is no Azure feature named 'compliance bundle.' While Azure Policy offers 'compliance states' and 'compliance scorecards' per initiative, the concept of bundling policy definitions for centralized compliance is implemented exclusively through initiative definitions (policy sets). Any reference to a 'compliance bundle' is a fabricated term, not a valid governance artifact.

    When this WOULD be correct

    In a scenario where the question asks for a feature that groups multiple Azure Policy definitions for compliance reporting but does not require assignment as a single unit, a hypothetical 'compliance bundle' might be considered, but in reality, Azure Policy initiatives are used. This option would never be correct in an Azure exam.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.

Azure Policy initiative (policy set) definitionCorrect answer

Why this is correct

An Azure Policy initiative definition (also known as a policy set) groups multiple related policy definitions into a single assignable unit. When assigned to a management group, subscription, or resource group, the initiative evaluates compliance as an aggregated set, so a fleet of hundreds of VMs can be assessed against a combined compliance posture (e.g., all VM security and configuration policies) in one dashboard. Initiatives also support the same remediation tasks and exemptions as individual policies, making them the appropriate construct for large-scale governance.

Azure Policy group definitionWrong answer — click to see why

Why this is wrong here

Azure Policy does not have a 'group definition' feature; the correct term for combining multiple policies is a 'policy initiative' (also called a policy set).

★ When this WOULD be the correct answer

If the question asked for a way to logically organize multiple policy assignments under a single management group for reporting purposes, a custom grouping concept might be considered, but Azure Policy itself does not offer a 'group definition' resource.

Why candidates choose this

Candidates may confuse the term 'group' with the concept of grouping policies together, not realizing that the official Azure term is 'initiative' or 'policy set'.

Azure Blueprints artifactWrong answer — click to see why

Why this is wrong here

Azure Blueprints artifacts are used to deploy and orchestrate resources (e.g., ARM templates, policies, role assignments) as part of a repeatable environment, not to define and assign a combined set of governance rules that evaluate compliance as a group. The question specifically requires a single artifact that combines rules for compliance evaluation, which is the purpose of a Policy Initiative, not Blueprints.

★ When this WOULD be the correct answer

A company needs to deploy a standardized environment that includes a set of Azure resources (e.g., VMs, storage, networking) along with pre-configured policies and role assignments. The team wants to ensure that every new subscription or resource group follows the same template and governance settings. In this scenario, Azure Blueprints would be the correct answer because it packages multiple artifacts (including policies) into a single deployable blueprint.

Why candidates choose this

Candidates may confuse Azure Blueprints with Policy Initiatives because both can group multiple policies. However, Blueprints are designed for environment orchestration and deployment, not for ongoing compliance evaluation of existing resources.

Azure compliance bundleWrong answer — click to see why

Why this is wrong here

Azure compliance bundle is not a real Azure feature; the correct feature for combining multiple policy rules into a single assignable artifact is an Azure Policy initiative (policy set) definition.

★ When this WOULD be the correct answer

In a scenario where the question asks for a feature that groups multiple Azure Policy definitions for compliance reporting but does not require assignment as a single unit, a hypothetical 'compliance bundle' might be considered, but in reality, Azure Policy initiatives are used. This option would never be correct in an Azure exam.

Why candidates choose this

The term 'compliance bundle' sounds like it could be a feature that bundles compliance rules, leading candidates to choose it without recognizing it is not an actual Azure service.

Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This AZ-900 question is part of Courseiva's 981-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.