Topic module

Governance, Compliance and Subscription Design

Governance questions test management groups, subscriptions, resource groups, Azure Policy, tagging, compliance, landing zones, and management hierarchy.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for AZ-305

Treat each AZ-305 item as an architecture decision: identify the workload requirement, governance boundary, data shape, recovery objective, and infrastructure tradeoff before choosing.

Core concepts

Concept 1

Governance, Compliance and Subscription Design questions test Azure architecture tradeoff decisions rather than isolated service-name recall.

Exam cue: Identify the requirement, workload type, data shape, access boundary, recovery target, and operational ownership model.

Concept 2

The best answer maps business requirements to identity, governance, data, resilience, compute, network, security, cost, and operations constraints.

Exam cue: Choose the Azure design that satisfies the constraint with the least unnecessary operational burden.

Concept 3

Eliminate answers that ignore governance scope, recovery objectives, data durability, private connectivity, security boundaries, or workload fit.

Exam cue: Prefer Well-Architected choices: secure, reliable, cost-aware, observable, governed, and scalable.

Risk pitfalls and guardrails

Choosing a service before identifying the business driver and nonfunctional requirement.

Guardrail: Avoid answers that pick services without checking governance scope, data model, recovery target, migration dependency, or network boundary.

Solving availability while ignoring identity, data protection, compliance, or cost constraints.

Guardrail: Avoid answers that pick services without checking governance scope, data model, recovery target, migration dependency, or network boundary.

Assuming a migration, networking, or storage pattern is correct without checking workload dependencies.

Guardrail: Avoid answers that pick services without checking governance scope, data model, recovery target, migration dependency, or network boundary.

Memory anchors

Management Group

A management group organizes subscriptions so governance can be applied at scale.

Subscription

A subscription provides an Azure billing, access, and management boundary.

Resource Group

A resource group is a logical container for resources managed together.

Azure Policy

Azure Policy evaluates and can enforce compliance rules for Azure resources.

Policy Initiative

A policy initiative groups policy definitions to manage a compliance objective.

Tagging Strategy

A tagging strategy supports ownership, cost allocation, automation, and governance reporting.

Landing Zone

An Azure landing zone provides a governed foundation for workloads, identity, networking, and operations.

Resource Lock

A resource lock helps prevent accidental modification or deletion.

Compliance Scope

Compliance scope determines which resources are evaluated by a policy or governance control.

Cost Governance

Cost governance uses budgets, tags, policy, and reporting to align spend with accountability.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

You must apply consistent policy and access assignments across many subscriptions through a hierarchy. Which construct should the design use at the top?

Your design must prevent anyone from creating resources in regions outside an approved list. Which Azure Policy effect enforces this?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.