Microsoft Certified: DevOps Engineer ExpertDevelop a security and compliance planMedium

A multinational corporation needs to ensure that all Azure resources deployed within specific subscriptions adhere to data residency requirements for different geographical regions. For example, resources in the 'Europe' subscription must only be deployed to 'West Europe' or 'North Europe' regions, while resources in the 'US' subscription must only be deployed to 'East US' or 'West US 2'. How can a DevOps engineer enforce these region-specific compliance rules across their Azure environment?

  1. AUtilize Azure Policies to restrict resource deployments to specific allowed locations.
  2. BUse Azure Advisor to identify and recommend moving resources to compliant regions.
  3. CImplement Azure Resource Locks on resource groups to prevent deployments outside allowed regions.
  4. DConfigure Network Security Groups (NSGs) to block outbound traffic to non-compliant regions.
Show answer & explanation

Correct answer: A. Utilize Azure Policies to restrict resource deployments to specific allowed locations.

Azure Policy is the service designed for enforcing organizational standards and assessing compliance. You can create a policy definition that restricts the allowed locations for resource deployments and assign it to the relevant subscriptions or management groups to enforce data residency requirements.

Why the other options are wrong

  • B. Azure Advisor provides recommendations but does not enforce or block non-compliant deployments.
  • C. Resource Locks prevent deletion or modification of existing resources, but they do not prevent the creation of new resources in non-compliant regions.
  • D. NSGs control network traffic, not where resources can be deployed geographically.

Azure Policy Allowed Locations

An Azure Policy capability that restricts resource deployments to a predefined set of Azure regions to enforce data residency and compliance requirements.

  • Uses the 'Microsoft.Resources/subscriptions/locations' alias in policy definitions.
  • Can be set at management group, subscription, or resource group scope.
  • Helps prevent accidental or intentional resource deployment in unapproved regions.

Memory trick: Policy is the Border Patrol for your Azure Regions!

More Develop a security and compliance plan questions