Microsoft Azure Solutions Architect Expert AZ-305 Practice Question
Your company has a tenant with a production and a development subscription. Security requirements mandate that all production storage accounts use only General Purpose v2 with customer-managed keys, while development is exempt. You need a solution that enforces the requirement automatically across any current or future production subscriptions and provides a single compliance report. What should you recommend?
Assign individual policy definitions to each storage resource group in every subscription.
Create a custom RBAC role that denies creation of non-compliant storage accounts and assign it at the subscription level.
Create an Azure Blueprint that includes the policy and apply the blueprint to each subscription.
Assign an Azure Policy initiative to the production management group and a separate initiative to the development management group.
Assigning an Azure Policy initiative at the management group level lets you bundle multiple policy definitions-such as allowed SKUs and required encryption-and apply them to every subscription contained in that management group. All existing and newly created subscriptions that move under the production management group will automatically inherit the policy assignments, and compliance data is aggregated at the management group scope. Assigning at resource-group scope would require ongoing manual work and yield fragmented reporting. Blueprints would still need to be applied to each subscription and do not automatically affect future subscriptions. RBAC custom roles control permissions but cannot enforce configuration settings such as storage account SKU or encryption.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an Azure Policy initiative?
Open an interactive chat with Bash
What is the difference between a management group and a subscription in Azure?
Open an interactive chat with Bash
Why is using Azure Policy initiatives more effective than custom RBAC roles for this scenario?
Open an interactive chat with Bash
Microsoft Azure Solutions Architect Expert AZ-305
Design identity, governance, and monitoring solutions
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .