You have a resource group named RG1. Prevent the creation of virtual machines in RG1 while still allowing other resources to be created. What should you use?
Choose an answer
Tap an option to check your answer.
Correct answer: an Azure policy.
Why this is the answer
An Azure policy is the correct choice because it allows you to define and enforce rules over your resources to ensure compliance with organizational standards. You can create a custom policy definition that specifically denies the creation of virtual machines within RG1. A lock would prevent any modification or deletion of resources within RG1, not just the creation of virtual machines. An Azure role defines permissions for users or groups to perform actions on resources, but it doesn't prevent resource creation based on type. A tag is used for organizing and categorizing resources, not for enforcing creation rules.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed