hardMultiple Choice
SC-100 Planning their cloud governance strategy Practice Question
A company is planning their cloud governance strategy. They have multiple business units with varying compliance requirements. They need to enforce policies consistently across subscriptions while allowing some flexibility. Which Azure governance structure should they recommend?
⚠ Common exam trap
A common mix-up: candidates confuse RBAC (access control) with Azure Policy (compliance enforcement), or assume that separate tenants or Blueprints are needed for isolation, when in fact management groups with policy exemptions provide the exact balance of consistency and flexibility required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a management group hierarchy with Azure Policy assignments and exemptions.
B is correct because a management group hierarchy allows the company to organize subscriptions by business unit or compliance requirement, then apply Azure Policy assignments at the management group level to enforce consistent policies across all subscriptions. Exemptions can be granted at lower scopes (e.g., specific subscriptions or resource groups) to provide the required flexibility while maintaining overall governance. This structure centralizes policy enforcement without requiring separate tenants or manual RBAC assignments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assign RBAC roles to each subscription owner.
Why it's wrong here
Assigning RBAC roles to each subscription owner governs who can access and manage resources, but it does not enforce the actual configuration or compliance of deployed workloads. Subscription owners could provision resources that violate corporate standards without any automatic guardrails or policy enforcement. RBAC is identity-based access control, not a mechanism for evaluating resource configuration, lacking the centralized inheritance and exemption capabilities of policy assignments. Thus, it fails to implement a proactive cloud governance strategy.
- ✓
Use a management group hierarchy with Azure Policy assignments and exemptions.
Why this is correct
A management group hierarchy provides a scalable governance structure by organizing subscriptions under corporate-level domains, allowing Azure Policy assignments to inherit across all descendant subscriptions and resource groups. Policies, such as enforcing approved VM sizes or location restrictions, can be centrally assigned at the root management group, ensuring consistent compliance. Exemptions offer a controlled mechanism to exclude specific resources from policy evaluation when legitimate exceptions are required, with the ability to set an expiry date. This combination delivers both enforcement and flexibility, making it the correct governance approach.
- ✗
Create separate Microsoft Entra ID tenants for each business unit.
Why it's wrong here
Creating separate Microsoft Entra ID tenants for each business unit introduces administrative silos that fragment identity management, conditional access policies, and resource governance across the organization. Collaboration and resource sharing between business units would require complex cross-tenant trust, Microsoft Entra B2B configurations, or manual federation, increasing operational overhead and security risk. Additionally, organizations lose the ability to enforce unified compliance through a single management group hierarchy, since each tenant is its own independent governance boundary. This approach is unnecessarily complex and does not align with centralized governance best practices.
- ✗
Use Azure Blueprints with locked permissions.
Why it's wrong here
Azure Blueprints package reusable resource groups, role assignments, policies, and ARM templates to create consistent environments, but they are scoped to a single subscription and primarily support initial deployment, not ongoing governance changes. While Blueprints can include deny assignments to lock permissions, they lack the dynamic, centralized exemption capability that management group-level policy assignments provide. Exceptions to a blueprint's resources require editing or reassigning the blueprint, which is rigid and not scalable for continuous compliance across many subscriptions. Moreover, Blueprints are deprecated in favor of deployment stacks, but neither replaces the need for a management group hierarchy with Azure Policy.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.