Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceMedium

A global enterprise needs to ensure that all virtual machines deployed in Azure have disk encryption enabled by default to comply with internal security policies. They want to prevent the creation of any new VM that does not meet this encryption requirement. Which Azure feature should they use?

  1. AAzure Advisor
  2. BAzure Cost Management + Billing
  3. CAzure Policy
  4. DAzure Monitor
Show answer & explanation

Correct answer: C. Azure Policy

Azure Policy can be used to enforce specific configurations, such as requiring disk encryption for all virtual machines. By setting a 'Deny' effect, it can prevent the creation of non-compliant resources, ensuring adherence to security policies.

Why the other options are wrong

  • A. Azure Advisor provides recommendations for best practices but does not enforce configurations or prevent resource creation.
  • B. Azure Cost Management + Billing focuses on financial aspects and cost optimization, not security configuration enforcement.
  • D. Azure Monitor collects and analyzes operational data but does not enforce security configurations like disk encryption.

Azure Policy for Enforcement

Azure Policy enables organizations to enforce rules and standards for Azure resources, helping to achieve compliance, cost savings, security, and consistent resource configurations.

  • Defines rules for resource properties.
  • Can audit existing resources for compliance.
  • Can deny the creation or update of non-compliant resources.
  • Can automatically remediate non-compliant settings.

Memory trick: Policies enforce rules to secure and standardize resources.

More Describe Azure management and governance questions