Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceHard

A software development company is using Azure DevOps for their CI/CD pipelines. They want to ensure that all virtual machines deployed by these pipelines across different subscriptions automatically have specific security configurations applied, such as enforcing encryption on OS disks and requiring specific network security group rules. This needs to be enforced consistently and automatically upon deployment. Which Azure service can enforce these rules at scale?

  1. AAzure Logic Apps
  2. BAzure Policy
  3. CAzure Blueprints
  4. DAzure Resource Manager (ARM) templates
Show answer & explanation

Correct answer: B. Azure Policy

Azure Policy allows you to define rules that resources must adhere to, such as enforcing encryption on OS disks or specific NSG rules. When integrated with CI/CD pipelines, Policy can audit or even deny deployments that don't meet these standards, ensuring consistent security configurations at scale across multiple subscriptions, making it ideal for automatic enforcement upon deployment.

Why the other options are wrong

  • A. Azure Logic Apps are used for workflow automation and integration, not for enforcing resource configuration standards across an entire Azure estate.
  • C. Azure Blueprints define and orchestrate consistent environments, which *include* policies, but Azure Policy itself is the service that enforces the individual rules at scale after or during deployment.
  • D. Azure Resource Manager (ARM) templates define the desired state of resources, but they don't *enforce* ongoing compliance or automatically remediate non-compliant resources after deployment; Policy does that.

Azure Policy for Enforcement

A service that enforces organizational standards and assesses compliance at scale. It can audit, deny, or modify resource deployments to ensure they meet predefined security configurations and other rules.

  • Enforces rules on resource properties and configuration.
  • Can prevent non-compliant deployments (Deny effect).
  • Integrates with CI/CD for automated governance.
  • Works across subscriptions and management groups.

Memory trick: Build it, check the rules, ensure security.

More Describe Azure management and governance questions