nerdexam
Microsoft

AZ-305 · Question #357

Your company has IT, security, and finance departments. You need to implement a new Azure deployment that will include multiple Azure subscriptions and management groups. The solution must meet the…

The correct answer is B. 2. One for the finance department, and one for the IT department. Note: If your organization has many Azure subscriptions, you might need a way to efficiently manage access, policies, and compliance for those subscriptions. Management groups provide a governance scope above…

Submitted by kim_seoul· Mar 6, 2026Design identity, governance, and monitoring solutions

Question

Your company has IT, security, and finance departments. You need to implement a new Azure deployment that will include multiple Azure subscriptions and management groups. The solution must meet the following requirements: - Ensure that all policies are assigned at the management group level. - Ensure that all the finance department resources have specific encryption policies applied. - Ensure that only users in the IT department can create virtual machines in any Azure region. - Ensure that users in the finance department can create virtual machines in only the East US Azure region. What is the minimum number of management groups you can create for the planned deployment?

Options

  • A1
  • B2
  • C3
  • D4

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    65% (13)
  • C
    20% (4)
  • D
    10% (2)

Explanation

One for the finance department, and one for the IT department. Note: If your organization has many Azure subscriptions, you might need a way to efficiently manage access, policies, and compliance for those subscriptions. Management groups provide a governance scope above subscriptions. When you organize subscriptions into management groups, the governance conditions that you apply cascade by inheritance to all associated Management groups give you enterprise-grade management at scale, no matter what type of subscriptions you might have. However, all subscriptions within a single management group must trust the same Microsoft Entra tenant. For example, you can apply a policy to a management group that limits the regions available for virtual machine (VM) creation. This policy would be applied to all nested management groups, subscriptions, and resources to allow VM creation only in authorized regions. https://learn.microsoft.com/en-us/azure/governance/management-groups/overview

Community Discussion

No community discussion yet for this question.

Full AZ-305 Practice