Microsoft Certified: DevOps Engineer ExpertDevelop a security and compliance planHard
A global software company maintains several Azure subscriptions for different development, test, and production environments. They need to ensure that all virtual networks (VNets) created across these subscriptions are peered with a central hub VNet in the production subscription for secure, internal network routing. Furthermore, this peering must be established automatically whenever a new VNet is created. Which Azure service combination provides the most efficient and compliant solution?
- AAzure Automation runbooks triggered by Azure Event Grid.
- BAzure Policy with a 'DeployIfNotExists' effect and Azure Resource Manager (ARM) templates.
- CAzure DevOps Pipelines with ARM templates and a scheduled Azure Function.
- DAzure Network Watcher and custom PowerShell scripts.
Show answer & explanationAnswer & explanation
Correct answer: B. Azure Policy with a 'DeployIfNotExists' effect and Azure Resource Manager (ARM) templates.
Azure Policy with a 'DeployIfNotExists' effect is specifically designed to audit for non-compliant resources (like a VNet missing a peering) and automatically deploy the missing resource (the VNet peering) if it doesn't exist. This ensures consistent, automatic compliance across all subscriptions.
Why the other options are wrong
- A. Azure Automation runbooks triggered by Event Grid could work, but it involves more custom scripting and orchestration compared to the declarative and built-in capabilities of Azure Policy for this scenario.
- C. While possible, an Azure Function would require custom logic to continuously poll or react to VNet creations, which is less native and scalable than Azure Policy for this specific governance need.
- D. Azure Network Watcher is for monitoring and diagnostics, not for automatic resource deployment or policy enforcement. Custom scripts would be less scalable and harder to manage for enterprise-wide compliance.
Azure Policy DeployIfNotExists
An Azure Policy effect that audits for compliant resources and automatically deploys a specified resource if the condition is met and the resource does not exist.
- Ideal for enforcing baseline configurations like VNet peerings or diagnostic settings.
- Runs after a resource is created or updated.
- Can be used to add missing components or settings to resources.
Memory trick: Policy is the Auto-Pilot for Network Compliance, Deploying what's Missing!