Microsoft AZ-305 Azure Governance and Compliance Practice Test

 

Topic 06 focuses on Azure Governance Hierarchy, Tagging, Policy, and Compliance for the Microsoft Certified: Azure Solutions Architect Expert certification and the AZ-305 exam, using Microsoft Azure solution-architecture scenarios. For broader exam preparation, review the Microsoft Azure Solutions Architect Expert AZ-305 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.

Question 1

For Azure Policy definition, which statement is accurate?

  1. Maps security posture and configuration assessments to supported regulatory standards.
  2. Applies supported modify or deployIfNotExists policy effects to existing non-compliant resources.
  3. Groups multiple policy definitions into a single assignable compliance objective.
  4. Evaluates Azure resources against rules and can audit, deny, modify, deploy related configuration, or otherwise enforce supported effects.

Correct Answer: D

 

Correct Answer

Answer D is correct because Azure Policy definition evaluates Azure resources against rules and can audit, deny, modify, deploy related configuration, or otherwise enforce supported effects.

Incorrect Answers

Answer A is incorrect because that description belongs to Microsoft Defender for Cloud regulatory compliance dashboard, whose purpose is to review compliance posture against recognized security frameworks and standards.

Answer B is incorrect because that description belongs to Azure Policy remediation task, whose purpose is to bring existing resources toward compliance after policy assignment.

Answer C is incorrect because that description belongs to Azure Policy initiative, whose purpose is to manage a set of related governance controls as one package.

 

Question 2

When considering Azure subscription, which requirement supports that choice?

  1. To group resources for deployment, access, policy, and lifecycle operations.
  2. To enforce technical governance and compliance requirements at scale.
  3. To separate environments or business units with independent billing and governance boundaries.
  4. To activate governance rules at the appropriate management scope.

Correct Answer: C

 

Correct Answer

Answer C is correct because Azure subscription is a billing, quota, and Azure Resource Manager governance boundary that contains resource groups and resources.

Incorrect Answers

Answer A is incorrect because that outcome is more directly associated with Resource group, not Azure subscription.

Answer B is incorrect because that outcome is more directly associated with Azure Policy definition, not Azure subscription.

Answer D is incorrect because that outcome is more directly associated with Azure Policy assignment, not Azure subscription.

 

Question 3

To activate governance rules at the appropriate management scope, which Azure design option should be selected?

  1. Azure Policy assignment
  2. Microsoft Defender for Cloud regulatory compliance dashboard
  3. Management group
  4. Azure Policy remediation task

Correct Answer: A

 

Correct Answer

Answer A is correct because Azure Policy assignment is designed to activate governance rules at the appropriate management scope. Azure Policy assignment applies a policy definition or initiative to a selected scope and can include parameters and exclusions.

Incorrect Answers

Answer B is incorrect because Microsoft Defender for Cloud regulatory compliance dashboard can be useful in Azure architectures, but its primary role is to review compliance posture against recognized security frameworks and standards; it is not the best match for the stated priority.

Answer C is incorrect because Management group can be useful in Azure architectures, but its primary role is to apply organization-wide governance consistently across subscription estates; it is not the best match for the stated priority.

Answer D is incorrect because Azure Policy remediation task can be useful in Azure architectures, but its primary role is to bring existing resources toward compliance after policy assignment; it is not the best match for the stated priority.

 

Question 4

Which Azure capability is a billing, quota, and Azure Resource Manager governance boundary that contains resource groups and resources?

  1. Azure Policy assignment
  2. Azure subscription
  3. Resource group
  4. Azure Policy definition

Correct Answer: B

 

Correct Answer

Answer B is correct because Azure subscription matches the described capability and is intended to separate environments or business units with independent billing and governance boundaries.

Incorrect Answers

Answer A is incorrect because Azure Policy assignment is intended to activate governance rules at the appropriate management scope, which is a different architectural function.

Answer C is incorrect because Resource group is intended to group resources for deployment, access, policy, and lifecycle operations, which is a different architectural function.

Answer D is incorrect because Azure Policy definition is intended to enforce technical governance and compliance requirements at scale, which is a different architectural function.

 

Question 5

Which Azure capability evaluates Azure resources against rules and can audit, deny, modify, deploy related configuration, or otherwise enforce supported effects?

  1. Azure Policy definition
  2. Azure Policy initiative
  3. Microsoft Defender for Cloud regulatory compliance dashboard
  4. Azure Policy remediation task

Correct Answer: A

 

Correct Answer

Answer A is correct because Azure Policy definition matches the described capability and is intended to enforce technical governance and compliance requirements at scale.

Incorrect Answers

Answer B is incorrect because Azure Policy initiative is intended to manage a set of related governance controls as one package, which is a different architectural function.

Answer C is incorrect because Microsoft Defender for Cloud regulatory compliance dashboard is intended to review compliance posture against recognized security frameworks and standards, which is a different architectural function.

Answer D is incorrect because Azure Policy remediation task is intended to bring existing resources toward compliance after policy assignment, which is a different architectural function.

 

Question 6

A governance rule has been defined but must now apply to a particular subscription or management scope. Which Azure Policy object activates that rule at the scope?

  1. Azure Policy remediation task
  2. Azure Policy assignment
  3. Microsoft Defender for Cloud regulatory compliance dashboard
  4. Management group

Correct Answer: B

 

Correct Answer

Answer B is correct because Azure Policy assignment applies a policy definition or initiative to a selected scope and can include parameters and exclusions. It directly meets the requirement to activate governance rules at the appropriate management scope.

Incorrect Answers

Answer A is incorrect because Azure Policy remediation task is used to bring existing resources toward compliance after policy assignment; that does not directly satisfy the requirement in this scenario.

Answer C is incorrect because Microsoft Defender for Cloud regulatory compliance dashboard is used to review compliance posture against recognized security frameworks and standards; that does not directly satisfy the requirement in this scenario.

Answer D is incorrect because Management group is used to apply organization-wide governance consistently across subscription estates; that does not directly satisfy the requirement in this scenario.

 

Question 7

To apply organization-wide governance consistently across subscription estates, which Azure design option should be selected?

  1. Azure subscription
  2. Azure resource tag
  3. Management group
  4. Azure Policy initiative

Correct Answer: C

 

Correct Answer

Answer C is correct because Management group provides a governance scope above subscriptions so policy and access assignments can inherit across multiple subscriptions. It directly meets the requirement to apply organization-wide governance consistently across subscription estates.

Incorrect Answers

Answer A is incorrect because Azure subscription is used to separate environments or business units with independent billing and governance boundaries; that does not directly satisfy the requirement in this scenario.

Answer B is incorrect because Azure resource tag is used to classify resources without changing their resource hierarchy; that does not directly satisfy the requirement in this scenario.

Answer D is incorrect because Azure Policy initiative is used to manage a set of related governance controls as one package; that does not directly satisfy the requirement in this scenario.

 

Question 8

Which Azure capability provides a prescriptive architecture for identity, management groups, subscriptions, networking, governance, security, and platform operations?

  1. Azure landing zone
  2. Azure Policy definition
  3. Resource group
  4. Management group

Correct Answer: A

 

Correct Answer

Answer A is correct because Azure landing zone matches the described capability and is intended to establish scalable enterprise Azure governance before large-scale workload deployment.

Incorrect Answers

Answer B is incorrect because Azure Policy definition is intended to enforce technical governance and compliance requirements at scale, which is a different architectural function.

Answer C is incorrect because Resource group is intended to group resources for deployment, access, policy, and lifecycle operations, which is a different architectural function.

Answer D is incorrect because Management group is intended to apply organization-wide governance consistently across subscription estates, which is a different architectural function.

 

Question 9

Which Azure capability applies a policy definition or initiative to a selected scope and can include parameters and exclusions?

  1. Azure Policy remediation task
  2. Management group
  3. Microsoft Defender for Cloud regulatory compliance dashboard
  4. Azure Policy assignment

Correct Answer: D

 

Correct Answer

Answer D is correct because Azure Policy assignment matches the described capability and is intended to activate governance rules at the appropriate management scope.

Incorrect Answers

Answer A is incorrect because Azure Policy remediation task is intended to bring existing resources toward compliance after policy assignment, which is a different architectural function.

Answer B is incorrect because Management group is intended to apply organization-wide governance consistently across subscription estates, which is a different architectural function.

Answer C is incorrect because Microsoft Defender for Cloud regulatory compliance dashboard is intended to review compliance posture against recognized security frameworks and standards, which is a different architectural function.

 

Question 10

To document and manage justified policy exceptions without deleting the policy, which Azure design option should be selected?

  1. Microsoft Defender for Cloud regulatory compliance dashboard
  2. Management group
  3. Resource group
  4. Azure Policy exemption

Correct Answer: D

 

Correct Answer

Answer D is correct because Azure Policy exemption is designed to document and manage justified policy exceptions without deleting the policy. Azure Policy exemption records an approved exception so a scoped resource is not counted as non-compliant for a specified assignment.

Incorrect Answers

Answer A is incorrect because Microsoft Defender for Cloud regulatory compliance dashboard can be useful in Azure architectures, but its primary role is to review compliance posture against recognized security frameworks and standards; it is not the best match for the stated priority.

Answer B is incorrect because Management group can be useful in Azure architectures, but its primary role is to apply organization-wide governance consistently across subscription estates; it is not the best match for the stated priority.

Answer C is incorrect because Resource group can be useful in Azure architectures, but its primary role is to group resources for deployment, access, policy, and lifecycle operations; it is not the best match for the stated priority.

 

Question 11

Several subscriptions must inherit the same governance controls from a common parent. Which Azure hierarchy element should group them?

  1. Management group
  2. Azure Policy initiative
  3. Azure resource tag
  4. Azure subscription

Correct Answer: A

 

Correct Answer

Answer A is correct because Management group is designed to apply organization-wide governance consistently across subscription estates. Management group provides a governance scope above subscriptions so policy and access assignments can inherit across multiple subscriptions.

Incorrect Answers

Answer B is incorrect because Azure Policy initiative can be useful in Azure architectures, but its primary role is to manage a set of related governance controls as one package; it is not the best match for the stated priority.

Answer C is incorrect because Azure resource tag can be useful in Azure architectures, but its primary role is to classify resources without changing their resource hierarchy; it is not the best match for the stated priority.

Answer D is incorrect because Azure subscription can be useful in Azure architectures, but its primary role is to separate environments or business units with independent billing and governance boundaries; it is not the best match for the stated priority.

 

Question 12

When considering Azure Policy exemption, which requirement supports that choice?

  1. To group resources for deployment, access, policy, and lifecycle operations.
  2. To document and manage justified policy exceptions without deleting the policy.
  3. To apply organization-wide governance consistently across subscription estates.
  4. To review compliance posture against recognized security frameworks and standards.

Correct Answer: B

 

Correct Answer

Answer B is correct because Azure Policy exemption records an approved exception so a scoped resource is not counted as non-compliant for a specified assignment.

Incorrect Answers

Answer A is incorrect because that outcome is more directly associated with Resource group, not Azure Policy exemption.

Answer C is incorrect because that outcome is more directly associated with Management group, not Azure Policy exemption.

Answer D is incorrect because that outcome is more directly associated with Microsoft Defender for Cloud regulatory compliance dashboard, not Azure Policy exemption.

 

Question 13

Which Azure capability groups multiple policy definitions into a single assignable compliance objective?

  1. Azure Policy exemption
  2. Azure landing zone
  3. Azure Policy initiative
  4. Azure Policy assignment

Correct Answer: C

 

Correct Answer

Answer C is correct because Azure Policy initiative matches the described capability and is intended to manage a set of related governance controls as one package.

Incorrect Answers

Answer A is incorrect because Azure Policy exemption is intended to document and manage justified policy exceptions without deleting the policy, which is a different architectural function.

Answer B is incorrect because Azure landing zone is intended to establish scalable enterprise Azure governance before large-scale workload deployment, which is a different architectural function.

Answer D is incorrect because Azure Policy assignment is intended to activate governance rules at the appropriate management scope, which is a different architectural function.

 

Question 14

For Azure subscription, which statement is accurate?

  1. Evaluates Azure resources against rules and can audit, deny, modify, deploy related configuration, or otherwise enforce supported effects.
  2. Is a lifecycle and management container for Azure resources that are commonly managed together.
  3. Applies a policy definition or initiative to a selected scope and can include parameters and exclusions.
  4. Is a billing, quota, and Azure Resource Manager governance boundary that contains resource groups and resources.

Correct Answer: D

 

Correct Answer

Answer D is correct because Azure subscription is a billing, quota, and Azure Resource Manager governance boundary that contains resource groups and resources.

Incorrect Answers

Answer A is incorrect because that description belongs to Azure Policy definition, whose purpose is to enforce technical governance and compliance requirements at scale.

Answer B is incorrect because that description belongs to Resource group, whose purpose is to group resources for deployment, access, policy, and lifecycle operations.

Answer C is incorrect because that description belongs to Azure Policy assignment, whose purpose is to activate governance rules at the appropriate management scope.

 

Question 15

For Azure landing zone, which statement is accurate?

  1. Evaluates Azure resources against rules and can audit, deny, modify, deploy related configuration, or otherwise enforce supported effects.
  2. Provides a governance scope above subscriptions so policy and access assignments can inherit across multiple subscriptions.
  3. Provides a prescriptive architecture for identity, management groups, subscriptions, networking, governance, security, and platform operations.
  4. Is a lifecycle and management container for Azure resources that are commonly managed together.

Correct Answer: C

 

Correct Answer

Answer C is correct because Azure landing zone provides a prescriptive architecture for identity, management groups, subscriptions, networking, governance, security, and platform operations.

Incorrect Answers

Answer A is incorrect because that description belongs to Azure Policy definition, whose purpose is to enforce technical governance and compliance requirements at scale.

Answer B is incorrect because that description belongs to Management group, whose purpose is to apply organization-wide governance consistently across subscription estates.

Answer D is incorrect because that description belongs to Resource group, whose purpose is to group resources for deployment, access, policy, and lifecycle operations.

 

Question 16

A workload has an approved, documented exception to an assigned policy. The broader assignment must remain in force. Which governance mechanism records the exception?

  1. Microsoft Defender for Cloud regulatory compliance dashboard
  2. Management group
  3. Resource group
  4. Azure Policy exemption

Correct Answer: D

 

Correct Answer

Answer D is correct because Azure Policy exemption records an approved exception so a scoped resource is not counted as non-compliant for a specified assignment. It directly meets the requirement to document and manage justified policy exceptions without deleting the policy.

Incorrect Answers

Answer A is incorrect because Microsoft Defender for Cloud regulatory compliance dashboard is used to review compliance posture against recognized security frameworks and standards; that does not directly satisfy the requirement in this scenario.

Answer B is incorrect because Management group is used to apply organization-wide governance consistently across subscription estates; that does not directly satisfy the requirement in this scenario.

Answer C is incorrect because Resource group is used to group resources for deployment, access, policy, and lifecycle operations; that does not directly satisfy the requirement in this scenario.

 

Question 17

When considering Azure Policy remediation task, which requirement supports that choice?

  1. To bring existing resources toward compliance after policy assignment.
  2. To establish scalable enterprise Azure governance before large-scale workload deployment.
  3. To document and manage justified policy exceptions without deleting the policy.
  4. To separate environments or business units with independent billing and governance boundaries.

Correct Answer: A

 

Correct Answer

Answer A is correct because Azure Policy remediation task applies supported modify or deployIfNotExists policy effects to existing non-compliant resources.

Incorrect Answers

Answer B is incorrect because that outcome is more directly associated with Azure landing zone, not Azure Policy remediation task.

Answer C is incorrect because that outcome is more directly associated with Azure Policy exemption, not Azure Policy remediation task.

Answer D is incorrect because that outcome is more directly associated with Azure subscription, not Azure Policy remediation task.

 

Question 18

For Resource group, which statement is accurate?

  1. Stores name-value metadata on supported resources and can support organization, reporting, automation, or cost allocation.
  2. Groups multiple policy definitions into a single assignable compliance objective.
  3. Applies supported modify or deployIfNotExists policy effects to existing non-compliant resources.
  4. Is a lifecycle and management container for Azure resources that are commonly managed together.

Correct Answer: D

 

Correct Answer

Answer D is correct because Resource group is a lifecycle and management container for Azure resources that are commonly managed together.

Incorrect Answers

Answer A is incorrect because that description belongs to Azure resource tag, whose purpose is to classify resources without changing their resource hierarchy.

Answer B is incorrect because that description belongs to Azure Policy initiative, whose purpose is to manage a set of related governance controls as one package.

Answer C is incorrect because that description belongs to Azure Policy remediation task, whose purpose is to bring existing resources toward compliance after policy assignment.

 

Question 19

For Azure Policy exemption, which statement is accurate?

  1. Provides a governance scope above subscriptions so policy and access assignments can inherit across multiple subscriptions.
  2. Records an approved exception so a scoped resource is not counted as non-compliant for a specified assignment.
  3. Is a lifecycle and management container for Azure resources that are commonly managed together.
  4. Maps security posture and configuration assessments to supported regulatory standards.

Correct Answer: B

 

Correct Answer

Answer B is correct because Azure Policy exemption records an approved exception so a scoped resource is not counted as non-compliant for a specified assignment.

Incorrect Answers

Answer A is incorrect because that description belongs to Management group, whose purpose is to apply organization-wide governance consistently across subscription estates.

Answer C is incorrect because that description belongs to Resource group, whose purpose is to group resources for deployment, access, policy, and lifecycle operations.

Answer D is incorrect because that description belongs to Microsoft Defender for Cloud regulatory compliance dashboard, whose purpose is to review compliance posture against recognized security frameworks and standards.

 

Question 20

When considering Azure resource tag, which requirement supports that choice?

  1. To enforce technical governance and compliance requirements at scale.
  2. To document and manage justified policy exceptions without deleting the policy.
  3. To classify resources without changing their resource hierarchy.
  4. To activate governance rules at the appropriate management scope.

Correct Answer: C

 

Correct Answer

Answer C is correct because Azure resource tag stores name-value metadata on supported resources and can support organization, reporting, automation, or cost allocation.

Incorrect Answers

Answer A is incorrect because that outcome is more directly associated with Azure Policy definition, not Azure resource tag.

Answer B is incorrect because that outcome is more directly associated with Azure Policy exemption, not Azure resource tag.

Answer D is incorrect because that outcome is more directly associated with Azure Policy assignment, not Azure resource tag.

 

Question 21

A platform architect needs to review compliance posture against recognized security frameworks and standards. Which Azure service or capability is the best fit?

  1. Azure subscription
  2. Microsoft Defender for Cloud regulatory compliance dashboard
  3. Azure resource tag
  4. Azure landing zone

Correct Answer: B

 

Correct Answer

Answer B is correct because Microsoft Defender for Cloud regulatory compliance dashboard maps security posture and configuration assessments to supported regulatory standards. It directly meets the requirement to review compliance posture against recognized security frameworks and standards.

Incorrect Answers

Answer A is incorrect because Azure subscription is used to separate environments or business units with independent billing and governance boundaries; that does not directly satisfy the requirement in this scenario.

Answer C is incorrect because Azure resource tag is used to classify resources without changing their resource hierarchy; that does not directly satisfy the requirement in this scenario.

Answer D is incorrect because Azure landing zone is used to establish scalable enterprise Azure governance before large-scale workload deployment; that does not directly satisfy the requirement in this scenario.

 

Question 22

Which Azure capability is a lifecycle and management container for Azure resources that are commonly managed together?

  1. Azure resource tag
  2. Resource group
  3. Azure Policy initiative
  4. Azure Policy remediation task

Correct Answer: B

 

Correct Answer

Answer B is correct because Resource group matches the described capability and is intended to group resources for deployment, access, policy, and lifecycle operations.

Incorrect Answers

Answer A is incorrect because Azure resource tag is intended to classify resources without changing their resource hierarchy, which is a different architectural function.

Answer C is incorrect because Azure Policy initiative is intended to manage a set of related governance controls as one package, which is a different architectural function.

Answer D is incorrect because Azure Policy remediation task is intended to bring existing resources toward compliance after policy assignment, which is a different architectural function.

 

Question 23

To classify resources without changing their resource hierarchy, which Azure design option should be selected?

  1. Azure Policy exemption
  2. Azure resource tag
  3. Azure Policy definition
  4. Azure Policy assignment

Correct Answer: B

 

Correct Answer

Answer B is correct because Azure resource tag stores name-value metadata on supported resources and can support organization, reporting, automation, or cost allocation. It directly meets the requirement to classify resources without changing their resource hierarchy.

Incorrect Answers

Answer A is incorrect because Azure Policy exemption is used to document and manage justified policy exceptions without deleting the policy; that does not directly satisfy the requirement in this scenario.

Answer C is incorrect because Azure Policy definition is used to enforce technical governance and compliance requirements at scale; that does not directly satisfy the requirement in this scenario.

Answer D is incorrect because Azure Policy assignment is used to activate governance rules at the appropriate management scope; that does not directly satisfy the requirement in this scenario.

 

Question 24

For Azure Policy remediation task, which statement is accurate?

  1. Applies supported modify or deployIfNotExists policy effects to existing non-compliant resources.
  2. Provides a prescriptive architecture for identity, management groups, subscriptions, networking, governance, security, and platform operations.
  3. Is a billing, quota, and Azure Resource Manager governance boundary that contains resource groups and resources.
  4. Records an approved exception so a scoped resource is not counted as non-compliant for a specified assignment.

Correct Answer: A

 

Correct Answer

Answer A is correct because Azure Policy remediation task applies supported modify or deployIfNotExists policy effects to existing non-compliant resources.

Incorrect Answers

Answer B is incorrect because that description belongs to Azure landing zone, whose purpose is to establish scalable enterprise Azure governance before large-scale workload deployment.

Answer C is incorrect because that description belongs to Azure subscription, whose purpose is to separate environments or business units with independent billing and governance boundaries.

Answer D is incorrect because that description belongs to Azure Policy exemption, whose purpose is to document and manage justified policy exceptions without deleting the policy.

 

Question 25

For Microsoft Defender for Cloud regulatory compliance dashboard, which statement is accurate?

  1. Stores name-value metadata on supported resources and can support organization, reporting, automation, or cost allocation.
  2. Is a billing, quota, and Azure Resource Manager governance boundary that contains resource groups and resources.
  3. Maps security posture and configuration assessments to supported regulatory standards.
  4. Provides a prescriptive architecture for identity, management groups, subscriptions, networking, governance, security, and platform operations.

Correct Answer: C

 

Correct Answer

Answer C is correct because Microsoft Defender for Cloud regulatory compliance dashboard maps security posture and configuration assessments to supported regulatory standards.

Incorrect Answers

Answer A is incorrect because that description belongs to Azure resource tag, whose purpose is to classify resources without changing their resource hierarchy.

Answer B is incorrect because that description belongs to Azure subscription, whose purpose is to separate environments or business units with independent billing and governance boundaries.

Answer D is incorrect because that description belongs to Azure landing zone, whose purpose is to establish scalable enterprise Azure governance before large-scale workload deployment.

 

Question 26

To manage a set of related governance controls as one package, which Azure design option should be selected?

  1. Azure Policy assignment
  2. Azure Policy initiative
  3. Azure landing zone
  4. Azure Policy exemption

Correct Answer: B

 

Correct Answer

Answer B is correct because Azure Policy initiative is designed to manage a set of related governance controls as one package. Azure Policy initiative groups multiple policy definitions into a single assignable compliance objective.

Incorrect Answers

Answer A is incorrect because Azure Policy assignment can be useful in Azure architectures, but its primary role is to activate governance rules at the appropriate management scope; it is not the best match for the stated priority.

Answer C is incorrect because Azure landing zone can be useful in Azure architectures, but its primary role is to establish scalable enterprise Azure governance before large-scale workload deployment; it is not the best match for the stated priority.

Answer D is incorrect because Azure Policy exemption can be useful in Azure architectures, but its primary role is to document and manage justified policy exceptions without deleting the policy; it is not the best match for the stated priority.

 

Question 27

When considering Azure landing zone, which requirement supports that choice?

  1. To establish scalable enterprise Azure governance before large-scale workload deployment.
  2. To apply organization-wide governance consistently across subscription estates.
  3. To group resources for deployment, access, policy, and lifecycle operations.
  4. To enforce technical governance and compliance requirements at scale.

Correct Answer: A

 

Correct Answer

Answer A is correct because Azure landing zone provides a prescriptive architecture for identity, management groups, subscriptions, networking, governance, security, and platform operations.

Incorrect Answers

Answer B is incorrect because that outcome is more directly associated with Management group, not Azure landing zone.

Answer C is incorrect because that outcome is more directly associated with Resource group, not Azure landing zone.

Answer D is incorrect because that outcome is more directly associated with Azure Policy definition, not Azure landing zone.

 

Question 28

To review compliance posture against recognized security frameworks and standards, which Azure design option should be selected?

  1. Azure landing zone
  2. Azure resource tag
  3. Microsoft Defender for Cloud regulatory compliance dashboard
  4. Azure subscription

Correct Answer: C

 

Correct Answer

Answer C is correct because Microsoft Defender for Cloud regulatory compliance dashboard is designed to review compliance posture against recognized security frameworks and standards. Microsoft Defender for Cloud regulatory compliance dashboard maps security posture and configuration assessments to supported regulatory standards.

Incorrect Answers

Answer A is incorrect because Azure landing zone can be useful in Azure architectures, but its primary role is to establish scalable enterprise Azure governance before large-scale workload deployment; it is not the best match for the stated priority.

Answer B is incorrect because Azure resource tag can be useful in Azure architectures, but its primary role is to classify resources without changing their resource hierarchy; it is not the best match for the stated priority.

Answer D is incorrect because Azure subscription can be useful in Azure architectures, but its primary role is to separate environments or business units with independent billing and governance boundaries; it is not the best match for the stated priority.

 

Question 29

When considering Resource group, which requirement supports that choice?

  1. To bring existing resources toward compliance after policy assignment.
  2. To manage a set of related governance controls as one package.
  3. To classify resources without changing their resource hierarchy.
  4. To group resources for deployment, access, policy, and lifecycle operations.

Correct Answer: D

 

Correct Answer

Answer D is correct because Resource group is a lifecycle and management container for Azure resources that are commonly managed together.

Incorrect Answers

Answer A is incorrect because that outcome is more directly associated with Azure Policy remediation task, not Resource group.

Answer B is incorrect because that outcome is more directly associated with Azure Policy initiative, not Resource group.

Answer C is incorrect because that outcome is more directly associated with Azure resource tag, not Resource group.

 

Question 30

An organization wants to group resources for deployment, access, policy, and lifecycle operations. Which design choice most directly meets the requirement?

  1. Resource group
  2. Azure resource tag
  3. Azure Policy remediation task
  4. Azure Policy initiative

Correct Answer: A

 

Correct Answer

Answer A is correct because Resource group is a lifecycle and management container for Azure resources that are commonly managed together. It directly meets the requirement to group resources for deployment, access, policy, and lifecycle operations.

Incorrect Answers

Answer B is incorrect because Azure resource tag is used to classify resources without changing their resource hierarchy; that does not directly satisfy the requirement in this scenario.

Answer C is incorrect because Azure Policy remediation task is used to bring existing resources toward compliance after policy assignment; that does not directly satisfy the requirement in this scenario.

Answer D is incorrect because Azure Policy initiative is used to manage a set of related governance controls as one package; that does not directly satisfy the requirement in this scenario.

img