AZ-500 exam dumps

AZ-500 practice question 191 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 191

Select 2

You need to enforce mandatory tags on all Azure resources to meet your organization's governance standards. You create a custom policy definition with a 'Deny' effect for any resource missing the 'Department' tag. You then bundle this policy along with other tag-related policies into an initiative and assign that initiative at the subscription scope. After a week, you review the Azure Policy compliance dashboard to see if the initiative is properly applied. Which two statements accurately describe creating, assigning, and interpreting the policies within this initiative?

  1. A
    1. Initiatives let you group multiple policy definitions under one assignment, making it simpler to manage and track overall compliance.
  2. B
    1. The 'Deny' effect in the policy definition automatically adds missing tags to existing resources, ensuring immediate compliance without further action.
  3. C
    1. You can review the initiative's compliance results in the Azure Policy blade, which reports compliant and non-compliant resources for each policy definition included in the initiative.
  4. D
    1. Existing resources will remain non-compliant if they do not meet the policy conditions, unless you use an effect that updates or remediates those resources (such as 'Modify' or 'DeployIfNotExists').
Show answer and explanation

Correct answers: A, C

Explanation

When creating and assigning policies in Azure, an initiative lets you bundle multiple policy definitions under one scope. This makes it easier to manage compliance across a range of resources. A 'Deny' effect prevents non-compliant resources from being created or updated, but does not fix existing non-compliant resources. The compliance dashboard in the Azure Portal shows an overview of how many resources comply with each policy definition in the initiative. More details on these concepts can be found in Microsoft documentation under 'Azure Policy documentation' and 'Create and manage policies to enforce compliance' (https://docs.microsoft.com/azure/governance/policy).

  • A. Correct.

    Option 1: Correct. An initiative (also known as an initiative definition) allows you to group multiple policy definitions into a single unit, making it easier to manage, assign, and track compliance for a set of related policies.

  • B. Incorrect.

    Option 2: Incorrect. A 'Deny' effect prevents resources from being created or modified if they don't meet certain conditions, it does not automatically add or fix missing tags. To remediate tags on existing resources, you would typically use a 'Modify' or 'DeployIfNotExists' effect, if supported.

  • C. Correct.

    Option 3: Correct. The Azure Policy compliance dashboard shows the overall compliance state for each assigned initiative or policy. You can drill down at the policy definition level to see which resources are in or out of compliance.

  • D. Incorrect.

    Option 4: Incorrect. A 'Deny' effect alone won't change existing resources; it only blocks non-compliant changes going forward. If existing resources are missing the required tag, they will remain non-compliant unless you use a remediation effect (e.g., 'Modify' or 'DeployIfNotExists') or manually update the tags.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam