Which Azure feature should a security manager use to ensure only specific roles can deploy virtual machines?
Choose an answer
Tap an option to check your answer.
Correct answer: Azure Policy.
Why this is the answer
Azure Policy is the correct choice because it allows you to define and enforce organizational standards and compliance at scale. You can create a policy definition that specifies which roles are permitted to deploy virtual machines, ensuring that only authorized users can perform this action. Azure Monitor is used for collecting, analyzing, and acting on telemetry data from your Azure and on-premises environments, not for enforcing deployment permissions. Azure Resource Graph provides an efficient and performant way to query across all your Azure resources, which is useful for inventory and discovery but doesn't control deployments. Azure App Service is a fully managed platform for building, deploying, and scaling web apps and APIs, and is unrelated to enforcing deployment policies for virtual machines.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed