Courseiva

AZ-900 Azure Policy effects Practice Question

A company wants to ensure that all resources in their Azure environment are created with mandatory tags for cost tracking. They have already assigned a policy to append tags, but existing resources are still missing tags. They want to automatically add the tags to existing resources without manual intervention. What should they do?

⚠ Common exam trap

The trap is assuming that an 'append' policy can be remediated retroactively. Remediation tasks are only supported for 'deployIfNotExists' and 'modify' effects. The correct approach is to change the policy effect to 'modify' first, then create a remediation task; this combination is not listed among the options.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a remediation task for the policy.

None of the provided options correctly solve the problem. The 'append' effect does not support remediation tasks; remediation tasks are only available for 'deployIfNotExists' and 'modify' effects. To automatically add tags to existing resources, the policy effect must be changed to 'modify', and then a remediation task can be created. This option is not listed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Modify the policy effect to 'deny' instead of 'append'.

    Why it's wrong here

    Changing the effect to 'deny' would prevent creation of untagged resources but would not add tags to existing ones.

    When this WOULD be correct

    If the question asked how to prevent users from creating resources without mandatory tags, then setting the policy effect to 'deny' would be correct, as it blocks non-compliant resource creation.

  • ✓

    Create a remediation task for the policy.

    Why this is correct

    Incorrect. Remediation tasks are not supported for policies with 'append' effect. They require 'deployIfNotExists' or 'modify' effects.

  • ✗

    Use Azure Resource Graph to identify and manually tag.

    Why it's wrong here

    Using Azure Resource Graph to manually identify and tag resources is not automatic and requires manual intervention.

    When this WOULD be correct

    A company needs to audit all Azure resources for compliance with tagging policies and generate a report of non-compliant resources for manual review. Using Azure Resource Graph to query resources missing tags would be the correct approach to gather the data efficiently.

  • ✗

    Reassign the policy with a new scope.

    Why it's wrong here

    Reassigning the policy with a new scope does not apply the tags to existing resources; it only applies to resources within the new scope on future updates.

    When this WOULD be correct

    If a company wants to apply a policy to a different set of resources (e.g., a different subscription or resource group) without affecting the original scope, reassigning the policy with a new scope would be correct.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-900 exam frequently reuses these exact scenarios with slightly different constraints.

✓Create a remediation task for the policy.Correct answer▾

Why this is correct

Incorrect. Remediation tasks are not supported for policies with 'append' effect. They require 'deployIfNotExists' or 'modify' effects.

✗Modify the policy effect to 'deny' instead of 'append'.Wrong answer — click to see why▾

Why this is wrong here

Changing the policy effect to 'deny' would prevent creation of non-compliant resources but does not remediate existing resources that are already missing tags.

★ When this WOULD be the correct answer

If the question asked how to prevent users from creating resources without mandatory tags, then setting the policy effect to 'deny' would be correct, as it blocks non-compliant resource creation.

Why candidates choose this

Candidates may think that denying non-compliant resources will force existing resources to be updated, but 'deny' only affects new resource creation, not existing ones.

✗Use Azure Resource Graph to identify and manually tag.Wrong answer — click to see why▾

Why this is wrong here

Azure Resource Graph can identify resources missing tags, but it does not automatically apply tags; it only helps query resources. The question requires automatic remediation without manual intervention, which Resource Graph cannot provide.

★ When this WOULD be the correct answer

A company needs to audit all Azure resources for compliance with tagging policies and generate a report of non-compliant resources for manual review. Using Azure Resource Graph to query resources missing tags would be the correct approach to gather the data efficiently.

Why candidates choose this

Candidates may think that identifying resources with Azure Resource Graph is a necessary first step to fix the issue, and they might overlook that the question explicitly requires automatic remediation, not manual tagging.

✗Reassign the policy with a new scope.Wrong answer — click to see why▾

Why this is wrong here

Reassigning the policy with a new scope does not automatically remediate existing non-compliant resources; it only applies the policy to new resources within the new scope.

★ When this WOULD be the correct answer

If a company wants to apply a policy to a different set of resources (e.g., a different subscription or resource group) without affecting the original scope, reassigning the policy with a new scope would be correct.

Why candidates choose this

Candidates may think that changing the scope will force the policy to re-evaluate and fix existing resources, not realizing that scope changes only affect future resource creation.

Analysis generated from the official AZ-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This AZ-900 question is part of Courseiva's 983-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.