Governance, Compliance and Subscription Design
Governance questions test management groups, subscriptions, resource groups, Azure Policy, tagging, compliance, landing zones, and management hierarchy.
How to study for AZ-305
Treat each AZ-305 item as an architecture decision: identify the workload requirement, governance boundary, data shape, recovery objective, and infrastructure tradeoff before choosing.
Core concepts
Concept 1
Governance, Compliance and Subscription Design questions test Azure architecture tradeoff decisions rather than isolated service-name recall.
Exam cue: Identify the requirement, workload type, data shape, access boundary, recovery target, and operational ownership model.
Concept 2
The best answer maps business requirements to identity, governance, data, resilience, compute, network, security, cost, and operations constraints.
Exam cue: Choose the Azure design that satisfies the constraint with the least unnecessary operational burden.
Concept 3
Eliminate answers that ignore governance scope, recovery objectives, data durability, private connectivity, security boundaries, or workload fit.
Exam cue: Prefer Well-Architected choices: secure, reliable, cost-aware, observable, governed, and scalable.
Risk pitfalls and guardrails
Choosing a service before identifying the business driver and nonfunctional requirement.
Guardrail: Avoid answers that pick services without checking governance scope, data model, recovery target, migration dependency, or network boundary.
Solving availability while ignoring identity, data protection, compliance, or cost constraints.
Guardrail: Avoid answers that pick services without checking governance scope, data model, recovery target, migration dependency, or network boundary.
Assuming a migration, networking, or storage pattern is correct without checking workload dependencies.
Guardrail: Avoid answers that pick services without checking governance scope, data model, recovery target, migration dependency, or network boundary.
Memory anchors
Management Group
A management group organizes subscriptions so governance can be applied at scale.
Subscription
A subscription provides an Azure billing, access, and management boundary.
Resource Group
A resource group is a logical container for resources managed together.
Azure Policy
Azure Policy evaluates and can enforce compliance rules for Azure resources.
Policy Initiative
A policy initiative groups policy definitions to manage a compliance objective.
Tagging Strategy
A tagging strategy supports ownership, cost allocation, automation, and governance reporting.
Landing Zone
An Azure landing zone provides a governed foundation for workloads, identity, networking, and operations.
Resource Lock
A resource lock helps prevent accidental modification or deletion.
Compliance Scope
Compliance scope determines which resources are evaluated by a policy or governance control.
Cost Governance
Cost governance uses budgets, tags, policy, and reporting to align spend with accountability.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
You must apply consistent policy and access assignments across many subscriptions through a hierarchy. Which construct should the design use at the top?
Your design must prevent anyone from creating resources in regions outside an approved list. Which Azure Policy effect enforces this?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
