AZ-900 Cloud Governance & Compliance
Practice Test 2026–2027 | Azure Policy,
Governance Tools, Compliance &
Detailed Answers
1. A company wants to ensure that its Azure resources are deployed only to
approved geographic locations. Which Azure governance feature is most
appropriate?
A. Azure Advisor
B. Azure Policy
C. Azure Monitor
D. Azure Service Health
Answer: Azure Policy
Rationale: Azure Policy can evaluate resources against organizational rules,
including allowed locations, resource types, SKUs, and configurations.
2. An organization needs to prevent users from creating resources in regions
that are not approved by corporate policy. What should it use?
A. Resource locks
B. Azure Policy
,C. Azure Monitor
D. Azure Service Health
Answer: Azure Policy
Rationale: Azure Policy can deny deployments that violate organizational
requirements such as permitted Azure regions.
3. Which Azure governance capability helps enforce standards across multiple
subscriptions?
A. Azure Policy
B. Azure Storage Explorer
C. Azure Load Balancer
D. Azure DNS
Answer: Azure Policy
Rationale: Azure Policy definitions and initiatives can be assigned at
management group, subscription, resource group, or resource scope.
4. A company wants to prevent accidental deletion of a production storage
account. Which feature should it use?
A. Azure Policy
B. Resource lock
C. Azure Advisor
D. Microsoft Purview
Answer: Resource lock
Rationale: Resource locks can prevent deletion or modification of Azure
resources regardless of user permissions, depending on the lock type.
5. Which resource lock prevents both deletion and modification of a
resource?
,A. Read-only lock
B. Delete lock
C. CanNotDelete lock
D. Resource Group lock
Answer: Read-only lock
Rationale: A read-only lock prevents users from modifying or deleting the locked
resource.
6. Which resource lock allows users to modify a resource but prevents
deletion?
A. Read-only
B. CanNotDelete
C. ModifyOnly
D. PreventWrite
Answer: CanNotDelete
Rationale: A CanNotDelete lock allows authorized users to make changes while
preventing deletion of the resource.
7. A resource group contains several production resources. An administrator
applies a CanNotDelete lock to the resource group. What is the primary
effect?
A. Resources cannot be modified
B. Resources cannot be deleted through normal deletion operations
C. Only the resource group is protected
D. Users cannot read the resources
Answer: Resources cannot be deleted through normal deletion operations
Rationale: A CanNotDelete lock at the resource-group scope helps prevent
deletion of the resource group and its resources while still permitting
modifications.
, 8. Which Azure service provides recommendations for improving security,
performance, reliability, and cost efficiency?
A. Azure Advisor
B. Azure Policy
C. Azure Arc
D. Azure Resource Graph
Answer: Azure Advisor
Rationale: Azure Advisor analyzes Azure resources and provides personalized
recommendations across cost, security, reliability, performance, and operational
excellence.
9. A company wants to identify underutilized virtual machines to reduce
unnecessary spending. Which service can provide recommendations?
A. Azure Advisor
B. Microsoft Purview
C. Azure Policy
D. Azure Service Health
Answer: Azure Advisor
Rationale: Azure Advisor can identify cost optimization opportunities, including
underutilized resources.
10.Which Azure feature is primarily designed to organize and manage
resources hierarchically?
A. Management groups
B. Availability zones
C. Virtual networks
D. Resource locks
Answer: Management groups