AZ-500 exam dumps

AZ-500 practice question 212 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 212

Single answer

You are a security engineer for an organization that manages hundreds of Azure resources across multiple subscriptions. You need to ensure that each new resource is assigned security-relevant tags (such as department, environment, and data classification) and that all resources remain compliant with these tagging requirements. Additionally, you want to continuously track asset security posture and identify any untagged or misconfigured assets across your subscriptions. What is the best way to achieve this objective?

  1. A

    Create a custom policy in Azure Policy that audits missing tags and deploys default tags when they’re absent, then use Microsoft Defender for Cloud to monitor compliance.

  2. B

    Periodically export your resource list from the Azure portal into an Excel spreadsheet and use an on-premises script to compare tag requirements.

  3. C

    Use Azure Resource Locks to enforce read-only access on untagged resources so that future modifications are restricted until tags are applied.

  4. D

    Configure an Azure Resource Manager template for each department and manually deploy all resources through that template to ensure tags are included.

Show answer and explanation

Correct answer: A

Explanation

The recommended approach is to use Azure Policy to enforce and remediate required resource tags automatically, then leverage Microsoft Defender for Cloud for continuous compliance tracking and security posture management. This combination allows you to maintain an up-to-date view of your assets and their security configurations in a scalable, automated manner. For additional guidance, refer to Microsoft’s documentation on Azure Policy (https://learn.microsoft.com/azure/governance/policy/overview) and Microsoft Defender for Cloud (https://learn.microsoft.com/azure/defender-for-cloud/).

  • A. Correct.

    Option 1 is correct. Azure Policy can both audit and remediate missing tags by applying default tags. Microsoft Defender for Cloud (formerly Azure Security Center) then provides a unified view of resource compliance, allowing you to track which resources are missing tags or have misconfigurations. This setup enables a consistent and automated approach across multiple subscriptions.

  • B. Incorrect.

    Option 2 is incorrect. While manually exporting to Excel and using a script can help you identify missing tags, it is neither scalable nor automated. This approach introduces administrative overhead and risk of human error.

  • C. Incorrect.

    Option 3 is incorrect. Azure Resource Locks are used primarily to prevent deletion or modification of critical resources, not for enforcing tagging or other compliance policies. Locking untagged resources would also block important configuration updates.

  • D. Incorrect.

    Option 4 is incorrect. Although using department-specific templates can standardize tags for new deployments, it doesn't address existing resources or updates made outside of the template process. You would also lack a central enforcement point and ongoing compliance checks across all subscriptions.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam