Microsoft Azure Solutions Architect Expert AZ-305 Practice Question
You are designing governance for a financial-services tenant that contains 20 Azure subscriptions. Auditors require continuous proof that every workload meets PCI-DSS controls. When a resource drifts from the standard, it must be brought back into compliance automatically. The solution must be applied centrally across all subscriptions and its definitions must be stored and version-controlled for future updates. Which approach should you recommend?
Enable the Microsoft Defender for Cloud regulatory compliance dashboard in each subscription.
Assign the built-in PCI-DSS initiative in Azure Policy at the management-group level and enable remediation tasks.
Tag every resource with compliance=PCI and use Azure Resource Graph queries to detect non-compliance.
Configure Azure Advisor score alerts and trigger Logic Apps to correct configuration drift.
Azure Policy includes built-in initiative definitions that map to common regulatory standards such as PCI-DSS. Assigning the initiative at the management-group scope evaluates every resource in all child subscriptions, reports compliance status, and can run remediation tasks (for example, using DeployIfNotExists) to bring non-compliant resources back into the desired state. Policy definitions and assignments can be stored as code in source control, satisfying the versioning requirement.
The Defender for Cloud regulatory compliance dashboard only reports on drift; it does not enforce or remediate configuration. Azure Advisor focuses on optimisation recommendations, and adding Logic Apps would still lack the governance and audit features required. Tagging resources and querying Azure Resource Graph provides visibility but no enforcement or automatic remediation.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Azure Policy and what is its purpose?
Open an interactive chat with Bash
What are management groups, and why are they important for governance?
Open an interactive chat with Bash
What is DeployIfNotExists in Azure Policy?
Open an interactive chat with Bash
Microsoft Azure Solutions Architect Expert AZ-305
Design identity, governance, and monitoring solutions
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .