Microsoft Certified: DevOps Engineer ExpertDevelop a security and compliance planMedium

A financial services organization is implementing a new Azure environment. Regulatory compliance requires that all Azure Virtual Machines (VMs) must have a specific set of security extensions installed and configured upon creation, and non-compliant VMs must be automatically remediated or flagged for review. Which Azure service should the DevOps team leverage to enforce this policy across all subscriptions and resource groups?

  1. AAzure Security Center (Defender for Cloud)
  2. BAzure Policy
  3. CAzure Automation
  4. DAzure Advisor
Show answer & explanation

Correct answer: B. Azure Policy

Azure Policy allows you to define and enforce organizational standards to maintain compliance across your Azure environment. It can be used to ensure that specific VM extensions are installed and to audit for non-compliance, with options for automatic remediation.

Why the other options are wrong

  • A. Azure Security Center (now Defender for Cloud) provides a unified security posture management and threat protection, but Azure Policy is the direct tool for enforcing configuration standards.
  • C. Azure Automation can be used for scripting and executing tasks, but it's not the primary service for defining and enforcing compliance policies across an entire environment.
  • D. Azure Advisor provides recommendations for best practices, including security, but does not enforce or automatically remediate non-compliant resources.

Azure Policy

A service in Azure that enables you to create, assign, and manage policies that enforce rules and effects over your resources to stay compliant with corporate standards and service level agreements.

  • Can enforce resource configurations, such as required VM extensions.
  • Supports audit, deny, deploy if not exists, and modify effects.
  • Can be scoped to management groups, subscriptions, or resource groups.

Memory trick: Policy is the Rule Book for Azure, enforcing compliance.

More Develop a security and compliance plan questions