Start here! Get your feet wet with the Microsoft cloud and begin your journey to earning your Microsoft Certified: Azure Fundamentals certification!
Prepare and test your skills

Prepare and test your skills

Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An organization wants to establish cloud governance and security best practices across all of its Azure workloads. The IT security team needs to automatically prevent the deployment of non-compliant resources, audit existing resources against security baselines, and continuously assess compliance with organizational standards.
Which Azure service or feature should the organization use to enforce these configuration rules?
Azure Policy is a dedicated governance and compliance management service in Azure. It enables organizations to create, assign, and manage policies that define rules and effects for resource properties and configurations across subscriptions and management groups.
Azure Policy directly addresses all the stated governance and security needs:
Deny effect to automatically block resource creation or modification requests that violate established organizational standards (e.g., preventing public IP creation or unencrypted storage accounts).Audit effect to report resources that deviate from security baselines without disrupting active operations.DeployIfNotExists or Modify to remediate non-compliant configurations automatically.Azure Policy is the native, built-in governance engine designed specifically for configuration enforcement, compliance reporting, and automated policy guardrails across cloud assets.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.