AZ-305 exam dumps

AZ-305 practice question 49 of 243

Designing Microsoft Azure Infrastructure Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-305 Question 49

Single answer

Your organization needs to ensure compliance with internal policies that require specific tags and encryption at rest for all Azure resources. These policies must apply across multiple subscriptions, and you need a central solution that can automate the enforcement of these standards, track compliance state, and provide remediation guidance. Which approach should you recommend to achieve these goals?

  1. A

    Create resource locks at the subscription level to prevent any unauthorized changes or deletions

  2. B

    Assign Azure Policy definitions and initiatives to each subscription to enforce tagging, encryption, and compliance tracking

  3. C

    Use Azure Monitor alerts to notify administrators when noncompliant resources are created

  4. D

    Implement Azure Reservations to lock in pricing and ensure resources remain compliant

Show answer and explanation

Correct answer: B

Explanation

Azure Policy is designed to help organizations enforce and control organizational standards and assess compliance at scale. By creating policy definitions (or combining multiple definitions into initiatives), organizations can automatically audit new or existing resources for compliance and apply remediation tasks when discrepancies arise. This approach meets real-world compliance needs by offering ongoing policy checks, detailed reporting, and automated governance. For more information, see Microsoft Documentation on Azure Policy (https://docs.microsoft.com/azure/governance/policy/).

  • A. Incorrect.

    Incorrect. Resource locks protect resources from deletion or changes but do not enforce compliance requirements like specific tags or encryption. Locks alone cannot provide compliance tracking or automated remediation.

  • B. Correct.

    Correct. Azure Policy allows you to define and assign policy definitions (or group them into initiatives) across subscriptions. It can audit noncompliant resources, enforce requirements such as tags and encryption, and offer remediation steps. This is the recommended approach for centralized compliance management.

  • C. Incorrect.

    Incorrect. Azure Monitor can raise alerts when certain conditions are met, but it does not automatically enforce or remediate compliance requirements. It provides insights rather than policy enforcement.

  • D. Incorrect.

    Incorrect. Azure Reservations are used for cost savings on compute resources, not for enforcing compliance or automatically tagging and encrypting resources.

Timed practice exam

Take a AZ-305 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam