Start here! Get your feet wet with the Microsoft cloud and begin your journey to earning your Microsoft Certified: Azure Fundamentals certification!
Prepare and test your skills

Prepare and test your skills

Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A financial enterprise is deploying infrastructure across multiple Azure subscriptions. The security and governance team must ensure that all deployed cloud resources consistently comply with industry standards (such as CIS benchmarks and ISO certifications).
The team requires a built-in governance solution that can evaluate resource properties against specific compliance controls, flag non-compliant resources, and automatically enforce or remediate configurations.
Which Azure service should the enterprise implement to meet these regulatory compliance requirements?
Azure Policy is a core cloud governance service designed to create, assign, and manage resource configuration rules across Azure environments. It continuously evaluates cloud resources against predefined organizational standards and regulatory frameworks to maintain operational integrity.
Azure Policy directly solves compliance challenges by offering built-in regulatory compliance initiatives mapped to international and industry standards such as CIS Microsoft Azure Foundations Benchmark, ISO 27001, PCI DSS, and NIST. Key operational capabilities include:
Deny effects to block non-compliant deployments or using DeployIfNotExists / Modify effects to remediate configurations automatically.Azure Policy operates natively within Azure Resource Manager (ARM), providing proactive governance before resources are created without requiring third-party management tools or custom agent installations.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.