AZ-305 exam dumps

AZ-305 practice question 51 of 243

Designing Microsoft Azure Infrastructure Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-305 Question 51

Single answer

Your organization processes sensitive financial data and must comply with the PCI DSS standard. You need to ensure that all new and existing resources in your Azure subscription meet encryption, network security, and other compliance requirements automatically. Which approach should you recommend to manage and monitor compliance across all Azure resources?

  1. A

    Create custom Resource Manager templates with embedded compliance checks and manually deploy them for each new resource.

  2. B

    Use Azure Policy initiatives to automatically audit and enforce compliance rules across all subscriptions.

  3. C

    Rely on Azure Monitor alerts to send notifications whenever a resource might be out of compliance.

  4. D

    Enable Azure Advisor recommendations and manually remediate any non-compliant resources.

Show answer and explanation

Correct answer: B

Explanation

Azure Policy is a native Azure service that allows you to define, assign, and manage policies in order to enforce different rules and effects over your resources. By grouping multiple policies into initiatives (such as PCI DSS), you can audit, remediate, and continuously enforce compliance standards at scale. Refer to Microsoft’s documentation on Azure Policy (https://docs.microsoft.com/azure/governance/policy/overview) for details on how to create and assign policy definitions that meet regulatory requirements.

  • A. Incorrect.

    Option 1: Creating custom Resource Manager templates can help deploy standardized configurations, but they won’t continuously enforce or audit existing resources. This approach is manual and prone to drift once resources are deployed, making it insufficient to fully manage compliance.

  • B. Correct.

    Option 2: Azure Policy initiatives provide a centralized way to define, audit, and enforce compliance requirements. They can automatically assess existing resources and block or remediate new resources that violate policy rules, making this the correct approach.

  • C. Incorrect.

    Option 3: Azure Monitor alerts can notify administrators about potential issues, but they do not actively enforce compliance configurations or remediate non-compliant resources. This alone is not enough to manage PCI DSS requirements effectively.

  • D. Incorrect.

    Option 4: Azure Advisor provides best practice recommendations for high availability, security, performance, and cost, but it does not replace a robust compliance enforcement solution. Manually remediating resources based on Advisor alerts is too reactive and does not guarantee continuous compliance.

Timed practice exam

Take a AZ-305 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam