Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingHard

An administrator needs to implement a policy in Azure that requires all newly created virtual machines to have a specific tag (e.g., 'CostCenter: IT'). This policy should automatically audit compliance and prevent non-compliant resources from being created. Which Azure security feature can enforce this requirement?

  1. AAzure Resource Locks
  2. BAzure Blueprints
  3. CAzure Security Center
  4. DAzure Policy
Show answer & explanation

Correct answer: D. Azure Policy

Azure Policy helps enforce organizational standards and assess compliance at scale. It can define rules for resource creation, configuration, and naming conventions, including requiring specific tags, and can have 'Deny' effects to prevent non-compliant resources.

Why the other options are wrong

  • A. Azure Resource Locks prevent accidental deletion or modification of resources, not for enforcing creation rules like tagging.
  • B. Azure Blueprints orchestrate the deployment of environmental setups, packaging policies, resource groups, and other resources, but Azure Policy is the underlying mechanism for enforcing the rules themselves.
  • C. Azure Security Center (now Defender for Cloud) provides security posture management and threat protection, not for enforcing resource creation policies.

Azure Policy

A service that helps enforce organizational standards and assess compliance at scale by defining rules for Azure resources.

  • Defines policies for resource creation, configuration, and naming.
  • Can audit compliance and prevent non-compliant resources.
  • Supports various effects like Audit, Deny, DeployIfNotExists.

Memory trick: Azure Policy is the 'rulebook' that 'ensures' your 'Azure resources play fair'.

More Describe Azure identity, security, and networking questions