Microsoft Azure Security Engineer Associate AZ-500 Practice Question

You assigned the built-in Azure Policy "Allowed locations" at the production subscription scope. After a merger, three resource groups must remain in an unsupported region for the next six months. You need to prevent those resource groups from being reported as non-compliant without removing or modifying the existing policy assignment. What should you configure?

  • Wrap the existing policy in an initiative definition and assign the initiative instead.

  • Add a role assignment granting the Policy Contributor role to each resource group.

  • Create a policy exemption for each of the three resource groups.

  • Create a new policy assignment with the Allowed locations policy but set the effect to Disabled at the resource-group scope.

Microsoft Azure Security Engineer Associate AZ-500
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot