Topic module

Subscriptions, Azure Policy, Tags and Cost Controls

Governance questions test Azure Policy, resource locks, tags, resource groups, subscriptions, budgets, alerts, Advisor cost recommendations, and cost organization.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for AZ-104

Treat each AZ-104 item as an admin workflow: identify the scope, resource type, access boundary, deployment method, monitoring signal, or recovery requirement.

Core concepts

Concept 1

Subscriptions, Azure Policy, Tags and Cost Controls questions reward operational Azure administration judgment rather than simple service-name recall.

Exam cue: Identify the Azure scope: tenant, management group, subscription, resource group, resource, subnet, or identity.

Concept 2

The best answer identifies the scope, resource type, access path, deployment method, monitoring signal, and recovery requirement.

Exam cue: Match the tool to the administrative task: manage access, deploy, secure, monitor, back up, or troubleshoot.

Concept 3

Eliminate answers that confuse RBAC with policy, public access with private access, monitoring with backup, or templates with manual changes.

Exam cue: Prefer least privilege, repeatable deployment, protected storage, private networking, and validated recovery.

Risk pitfalls and guardrails

Using Azure Policy when the question asks who is allowed to perform an action.

Guardrail: Avoid answers that confuse RBAC with Policy, tags with network controls, dashboards with backup, or public exposure with secure private access.

Opening public access when private endpoints, service endpoints, or NSGs meet the requirement.

Guardrail: Avoid answers that confuse RBAC with Policy, tags with network controls, dashboards with backup, or public exposure with secure private access.

Assuming backup exists before checking vault, policy, retention, and restore validation.

Guardrail: Avoid answers that confuse RBAC with Policy, tags with network controls, dashboards with backup, or public exposure with secure private access.

Memory anchors

Azure Policy

Azure Policy evaluates and can enforce resource compliance with organizational rules.

Policy Assignment

A policy assignment applies a policy definition at a selected scope.

Resource Lock

A resource lock helps prevent accidental deletion or modification.

Tag

A tag labels resources with name-value pairs for cost, ownership, automation, or organization.

Resource Group

A resource group is a logical container for Azure resources managed together.

Subscription

A subscription provides billing, access, and management boundary for Azure resources.

Budget

A budget tracks spending and can trigger alerts when thresholds are reached.

Cost Alert

A cost alert notifies stakeholders when spend or usage meets configured conditions.

Advisor Cost

Azure Advisor can recommend cost optimization opportunities.

Governance Scope

Governance scope determines where policy, tags, or locks apply.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

A company wants all newly created storage accounts in one subscription to require secure transfer. Which governance control should be assigned?

Several related policy definitions must be assigned and reported as one compliance package. What should the administrator create?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.