Objective governance.complianceAZ-900

Describe features and tools in Azure for governance and compliance

Objective governance.compliance sits in Describe Azure management and governance, which carries 35% of the Azure Fundamentals exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Describe Azure management and governanceEasy

A cloud governance lead wants a single Azure service that evaluates resource properties against organizational rules and shows an aggregated compliance dashboard. Which service meets this need?

Correct.

The concept

Rules about how resources may be configured have to be both enforced at creation and reported on for what already exists. One service does both, which is why it answers questions about standards and questions about drift.

Why this answer

The source states Azure Policy helps enforce organizational standards and assess compliance at-scale, with a dashboard that gives an aggregated compliance view.

  • Correct: Azure Policy is built specifically for standards enforcement and compliance assessment.
  • BResource locks only prevent accidental deletion or modification; they don't evaluate compliance.
  • CCost Management tracks spend, not policy compliance against organizational rules.
  • DMicrosoft Entra ID handles identity and access, not resource property compliance evaluation.
  • EAzure Monitor focuses on telemetry and alerting, not rule-based compliance assessment.
Read the sourceAzure Policy overview
Verified against learn.microsoft.com · 2026-07-27
azure-policycompliancegovernance

Now you: objective governance.compliance questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Describe Azure management and governanceModerate

An organization cancels an Azure subscription that contains several resources protected by Delete locks. What happens to those resources immediately after cancellation?

Sample question 2 of 3

Describe Azure management and governanceHard

A storage account has a ReadOnly lock applied. A client application uses a data plane request to delete a file share, while an administrator separately uses a control plane request to delete the same type of resource. What is the outcome of each attempt?

Sample question 3 of 3

Describe Azure management and governanceHard

A diagnostic setting extension resource is attached to a blob within a storage account. The storage account itself has a Delete lock applied, but the blob container and diagnostic setting have no locks of their own. Can an administrator delete the diagnostic setting?

That’s 3 of the full Azure Fundamentals bank.

Keep going free: 10 questions per certification in bank practice, with no account.

Continue practicing

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Describe Azure management and governance