nerdexam
Microsoft

AZ-500 · Question #87

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…

The correct answer is B. No. Option B (No) is correct because scoping the policy initiative assignments to resource groups is too narrow - the requirement is to deploy the policy definitions as a group to all three subscriptions, meaning the assignments must be scoped at the subscription level (or…

Submitted by stefanr· Mar 6, 2026Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Question

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You use Azure Security Center for the centralized policy management of three Azure subscriptions. You use several policy definitions to manage the security of the subscriptions. You need to deploy the policy definitions as a group to all three subscriptions. Solution: You create a policy initiative and assignments that are scoped to resource groups. Does this meet the goal?

Options

  • AYes
  • BNo

How the community answered

(22 responses)
  • A
    23% (5)
  • B
    77% (17)

Explanation

Option B (No) is correct because scoping the policy initiative assignments to resource groups is too narrow - the requirement is to deploy the policy definitions as a group to all three subscriptions, meaning the assignments must be scoped at the subscription level (or management group level) to cover all resources across each subscription.

Why Option A (Yes) is wrong: Scoping assignments to resource groups would only apply the policies to specific resource groups within the subscriptions, not to the subscriptions in their entirety. This means resources outside those resource groups would be left unprotected, failing to meet the goal of full subscription coverage.

The correct solution would be to create a policy initiative and assign it with scope set to each of the three subscriptions (or ideally a management group containing all three), ensuring uniform policy enforcement across all resources.

Memory tip: Think of scope as a "coverage umbrella" - if you need to cover three subscriptions, your umbrella must be at least subscription-sized or larger (management group). A resource group scope is like a small umbrella that only covers part of the subscription, leaving gaps in your security policy enforcement.

Topics

#Azure Policy#Policy Initiatives#Policy Scope#Multi-subscription Management

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice