AZ-305 exam dumps

AZ-305 practice question 45 of 243

Designing Microsoft Azure Infrastructure Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-305 Question 45

Select 2

Contoso has recently acquired multiple smaller companies, each with its own Azure resources. You have been asked to design a new Azure hierarchy that separates concerns at the organizational level, centralizes governance, and enforces consistent tagging. Which two recommendations should you make to best structure management groups, subscriptions, and resource groups, and to implement an effective tagging strategy?

  1. A

    A. Create a top-level Management Group named “Security” and place all subscriptions under it to ensure a single point for access policies.

  2. B

    B. Use departmental or functional Management Groups (for example, “Finance,” “IT,” “HR”) under the Root Management Group, and separate production and non-production subscriptions accordingly.

  3. C

    C. Place all resources across multiple departments in a single Resource Group and differentiate them only with tags for cost tracking and governance.

  4. D

    D. Define a standard set of tags (such as cost center, environment, and owner) at the subscription level and apply them consistently to all Resource Groups and resources.

Show answer and explanation

Correct answers: B, D

Explanation

When designing a management hierarchy, Azure recommends creating a root management group and then nested management groups based on organizational structure or functional areas (e.g., departments, production vs. non-production). Subscriptions sit under these management groups, allowing you to apply specific governance and policy controls. Within each subscription, resource groups should be organized logically based on workload or lifecycle. A well-defined tagging strategy (covering cost-center, environment, and ownership) helps with consistent resource governance, cost allocation, and lifecycle management. For more details, refer to Microsoft Docs: https://learn.microsoft.com/azure/governance/management-groups/ and https://learn.microsoft.com/azure/azure-resource-manager/management/tag-resources.

  • A. Incorrect.

    A. Incorrect. While security policies can be applied via Management Groups, having only one top-level Management Group for security does not align well with recommended hierarchical structures that separate departments or environments. Organizations typically place security or compliance policies at the root or higher-level MGs, then create sub-groups aligned to departments or workload environments.

  • B. Correct.

    B. Correct. Azure best practices recommend creating management groups aligned by business function or department and separating production and non-production subscriptions. This hierarchical approach facilitates applying governance and policy controls at different organizational levels.

  • C. Incorrect.

    C. Incorrect. Placing all resources in a single Resource Group is not recommended. Resource groups should logically group resources by lifecycle or workload. Relying only on tags for cost tracking or management is insufficient for effective resource organization and access control.

  • D. Correct.

    D. Correct. Defining a consistent tagging strategy for key attributes such as cost center, environment, and owner at the subscription level ensures that policies can enforce consistent tagging across Resource Groups and individual resources. This helps with cost management, accountability, and governance.

Timed practice exam

Take a AZ-305 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam