Courseiva
hardMultiple Choice

SC-100 Planning their cloud governance strategy Practice Question

A company is planning their cloud governance strategy. They have multiple business units with varying compliance requirements. They need to enforce policies consistently across subscriptions while allowing some flexibility. Which Azure governance structure should they recommend?

⚠ Common exam trap

A common mix-up: candidates confuse RBAC (access control) with Azure Policy (compliance enforcement), or assume that separate tenants or Blueprints are needed for isolation, when in fact management groups with policy exemptions provide the exact balance of consistency and flexibility required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a management group hierarchy with Azure Policy assignments and exemptions.

B is correct because a management group hierarchy allows the company to organize subscriptions by business unit or compliance requirement, then apply Azure Policy assignments at the management group level to enforce consistent policies across all subscriptions. Exemptions can be granted at lower scopes (e.g., specific subscriptions or resource groups) to provide the required flexibility while maintaining overall governance. This structure centralizes policy enforcement without requiring separate tenants or manual RBAC assignments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Assign RBAC roles to each subscription owner.

    Why it's wrong here

    Assigning RBAC roles to each subscription owner governs who can access and manage resources, but it does not enforce the actual configuration or compliance of deployed workloads. Subscription owners could provision resources that violate corporate standards without any automatic guardrails or policy enforcement. RBAC is identity-based access control, not a mechanism for evaluating resource configuration, lacking the centralized inheritance and exemption capabilities of policy assignments. Thus, it fails to implement a proactive cloud governance strategy.

  • ✓

    Use a management group hierarchy with Azure Policy assignments and exemptions.

    Why this is correct

    A management group hierarchy provides a scalable governance structure by organizing subscriptions under corporate-level domains, allowing Azure Policy assignments to inherit across all descendant subscriptions and resource groups. Policies, such as enforcing approved VM sizes or location restrictions, can be centrally assigned at the root management group, ensuring consistent compliance. Exemptions offer a controlled mechanism to exclude specific resources from policy evaluation when legitimate exceptions are required, with the ability to set an expiry date. This combination delivers both enforcement and flexibility, making it the correct governance approach.

  • ✗

    Create separate Microsoft Entra ID tenants for each business unit.

    Why it's wrong here

    Creating separate Microsoft Entra ID tenants for each business unit introduces administrative silos that fragment identity management, conditional access policies, and resource governance across the organization. Collaboration and resource sharing between business units would require complex cross-tenant trust, Microsoft Entra B2B configurations, or manual federation, increasing operational overhead and security risk. Additionally, organizations lose the ability to enforce unified compliance through a single management group hierarchy, since each tenant is its own independent governance boundary. This approach is unnecessarily complex and does not align with centralized governance best practices.

  • ✗

    Use Azure Blueprints with locked permissions.

    Why it's wrong here

    Azure Blueprints package reusable resource groups, role assignments, policies, and ARM templates to create consistent environments, but they are scoped to a single subscription and primarily support initial deployment, not ongoing governance changes. While Blueprints can include deny assignments to lock permissions, they lack the dynamic, centralized exemption capability that management group-level policy assignments provide. Exceptions to a blueprint's resources require editing or reassigning the blueprint, which is rigid and not scalable for continuous compliance across many subscriptions. Moreover, Blueprints are deprecated in favor of deployment stacks, but neither replaces the need for a management group hierarchy with Azure Policy.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.