Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam AZ-104 topic 2 question 5 discussion

Actual exam question from Microsoft's AZ-104
Question #: 5
Topic #: 2
[All AZ-104 Questions]

HOTSPOT -
You have the Azure management groups shown in the following table:

You add Azure subscriptions to the management groups as shown in the following table:

You create the Azure policies shown in the following table:

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: No -
Virtual networks are not allowed at the root and is inherited. Deny overrides allowed.

Box 2: Yes -
Virtual Machines can be created on a Management Group provided the user has the required RBAC permissions.

Box 3: Yes -
Subscriptions can be moved between Management Groups provided the user has the required RBAC permissions.
Reference:
https://docs.microsoft.com/en-us/azure/governance/management-groups/overview https://docs.microsoft.com/en-us/azure/governance/management-groups/manage#moving-management-groups-and-subscriptions

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
fedztedz
Highly Voted 3 years, 4 months ago
Answer is Wrong : It should Be NO NO NO - subscription should be moved by can't be added to 2 groups.
upvoted 236 times
tita_tovenaar
2 years, 9 months ago
not agreed for answer 2. Only virtual networks are mentioned in the policy. Nothing is said about virtual machines. Result: NO - YES - NO
upvoted 20 times
tita_tovenaar
2 years, 9 months ago
sorry, my bad. answer 2 is No.By allowing metworks, you deny all the rest.
upvoted 13 times
...
...
pieronegri
3 years, 4 months ago
you are right, "move" is the right verb.
upvoted 2 times
...
Durden871
1 year, 1 month ago
From Udemy: NYN Explanation 1. The azure policy (not allowed resource types – Virtual networks) is inherited to Subscription1. So, Virtual networks are not allowed to create in Subscription1. 2. Policy assignments get evaluated top-to-bottom. The most restrictive policy assignment will always win, i.e. a DENY on any level will take precedence over an ALLOW on any other level. So the azure policy (not allowed resource types – Virtual networks) will be applied to Subscription2. The deny policy is only for virtual networks. This allows to create a virtual machine by leveraging existing VNet’s. 3. Each management group and subscription can only support one parent. Subscription1 is already part of a management group. We can’t add this to another management group though we can move. https://docs.microsoft.com/en-us/azure/governance/management-groups/overview
upvoted 40 times
alexn76
1 year, 1 month ago
N Y N You can create VM on existing network
upvoted 2 times
KrisJin
11 months, 4 weeks ago
Who told you there is an existing VNET?
upvoted 7 times
Batiste2023
5 months, 2 weeks ago
Who told you there isn't? - Actually, who would make policies like this, if there weren't any VNets available already? (I know, it's a Microsoft scenario, but still...)
upvoted 1 times
ki01
5 months, 1 week ago
no one in their right mind would make policies like these, but this is not a real world tenant in a company. this is an exam question to test if you know how allows and denies trickle down through management groups. No need to get philosophical on this
upvoted 3 times
...
...
...
ggogel
5 months ago
"Allowed Resource Type (Deny): Defines the resource types that you can deploy. Its effect is to deny all resources that aren't part of this defined list." See: https://learn.microsoft.com/en-us/azure/governance/policy/overview#policy-definition So the answer to the second question is NO. Only vNets are in the list, so only vNets can be created. Anything else is denied.
upvoted 4 times
...
...
Zemar
1 year ago
No - Sub1 > Group21 > Group11 > TenantRoot (Not allowed) No - Sub2 > Group12 > TenantRoot (Not allowed) No - Only one management group can be assigned to a subscription (Group21 is already assigned to sub1)
upvoted 15 times
...
avidlearner
8 months, 2 weeks ago
No - Tenant Root not allowed No - Azure policy is a Strict Deny system, Any deny policy on top level is not overridden by lower level allows. Since you are not allowed to create a VNet you can't create a VM without a VNet. No- you don't add a subscription group which is already assigned to other .
upvoted 5 times
Ruzhdi
1 month ago
Answer 2: is Yes - ManagementGroup12 is allowed to create VNet as mentioned in the assignment.
upvoted 1 times
...
...
...
dp846
9 months, 3 weeks ago
overrides property allows you to change the effect of a policy definition without modifying the underlying policy definition
upvoted 1 times
...
...
mlantonis
Highly Voted 2 years, 11 months ago
Allowed Resource Type (Deny): Defines the resource types that you can deploy. Its effect is to deny all resources that aren't part of this defined list. Not allowed resource types (Deny): Prevents a list of resource types from being deployed. Based on the Policies, VNETs are not allowed in the Tenant Root Group scope, so you cannot deploy VNETs. Also, VNETs only allowed in ManagementGroup12 scope, but you cannot deploy any other resource. Box 1: No Subscription1 is a member of ManagementGroup21, ManagementGroup21 is a member of ManagementGroup11, ManagementGroup11 is a member of the Tenant Root Group, The Tenant Root group has ‘Not allowed resource types for virtual network’. Box 2: No: You cannot create a VM, because based on the Policy you can only create VNETs in Sybscription2 (ManagementGroup12). Box 3: No You cannot ADD Subscription1 to ManagementGroup11, but you can MOVE Subscription1 from ManagementGroup21 to ManagmentGroup11. Subscriptions can only be a member of ONE ManagementGroup at a time.
upvoted 211 times
ElDakhli
1 year, 3 months ago
Perfect comment, thank you :)
upvoted 2 times
...
Harssh
2 years, 4 months ago
Box 1 and Box 2 are ok; however, I have a doubt that when all management groups here are under management group Tenant Root Group which has a policy barring Virtual Networks, so how come ManagementGroup12 can allow Virtual network creation in the first place? Do'nt member management groups inherit policies from host management group?
upvoted 1 times
Harssh
2 years, 4 months ago
My question is can a nested management group override policy defined at its parent management group level by creating its own contradictory policy?
upvoted 3 times
SumanSaurabh
1 year, 4 months ago
Exactly, I do have same question. Can some help to understand
upvoted 1 times
...
...
...
joergsi
2 years, 3 months ago
Your reply for box 2 makes no sense because the question is: You can create a VM in Sun 2? And you are saying: Box 2: No: You cannot create a VM, because based on the Policy you can only create VNETs in Sybscription2 (ManagementGroup12). But then the answer needs to be yes based on your argument, correct?
upvoted 4 times
kilowd
1 year, 10 months ago
Allowed Resource Type (Deny): Defines the resource types that you can deploy. Its effect is to deny all resources that aren't part of this defined list.
upvoted 1 times
...
xavigo
1 year, 11 months ago
If you can *only* create VNETS then it follows you cannot create other things like VMs. What's so hard to grasp?
upvoted 6 times
...
...
dp846
9 months, 3 weeks ago
Box 2 : No since overrides property allows you to change the effect of a policy definition without modifying the underlying policy definition
upvoted 2 times
...
...
tashakori
Most Recent 1 month, 1 week ago
No No Yes
upvoted 1 times
...
JoskeVr
1 month, 3 weeks ago
This was on my exam 25/02/2024! I just want to let people know that these questions are still up to date!
upvoted 3 times
...
Wojer
3 months, 1 week ago
Anything assigned on the root will apply to the entire hierarchy, which includes all management groups, subscriptions, resource groups, and resources within that Azure AD tenant
upvoted 1 times
...
Japeth
3 months, 2 weeks ago
Answer is Wrong : It should Be NO YES NO Virtual networks are not allowed to create in Subscription1
upvoted 1 times
...
[Removed]
3 months, 2 weeks ago
I did the lab and the correct answer is No, No, No. For the second question, even if you have explicitly allowed VNETs on the Management Group, the Tenant Root Group policy will override it. This is interesting as initially I thought that if you specifically allow something under the Tenant Root with this policy, it will override the one coming from above but apparently it's not like that.
upvoted 2 times
...
Gpsn
4 months ago
N - Subscription 1 not allowed to create VNET N - Subscription 2 allows only VNET, restricts everything else. Per policy definition of Allowed Resources Type, "If NOT (listOfResourceTypesAllowed), then deny". So, only specified resources will be allowed, nothing else N - Subscription can be associated with only one Management group
upvoted 1 times
...
jlee425
5 months ago
2. Yes If there is an existing virtual network in Subscription2, you could use that network to create a VM
upvoted 2 times
...
psscloud
5 months, 1 week ago
During a VM creation, a VNet and NIC creation are mandatory. Because of the Policy, VM creation would be stopped if a new VNet needs to be created. But if there is any existing VNet available in the resource group already, that can be used to create the VM. In that way, the VM creation shouldn't fail. So, yes, you can create a VM.
upvoted 1 times
...
mattpaul
6 months ago
I passed with these questions and many friends passed too, if you want real exam questions, contact me on [email protected]
upvoted 1 times
...
DWILK
6 months, 1 week ago
I wish MS would be more careful how they phrase things. There's a big difference between move and add
upvoted 2 times
...
sedex
7 months, 3 weeks ago
There seems to be a lot of confusion about the wording of the last part of this question. In my opinion yes, of course you can add Sub1 to MG11. Nothing is stopping you from adding it, it will just no longer be in MG21. Why is this it being argued that a subscription can't exist in 2 MGs when it will obviously only be in 1 after adding it to another?
upvoted 3 times
...
FatFatSam
8 months, 1 week ago
I would like to ask can I create virtual network in subscription 2?
upvoted 1 times
...
MGJG
8 months, 1 week ago
NNN 2.- the order of the policy does not matter, the more restrictive policy wins https://www.stefanroth.net/2020/01/17/azure-policy-how-precedence-works/
upvoted 3 times
...
RickySmith
8 months, 1 week ago
NNN 1.N The policy is inherited. https://learn.microsoft.com/en-us/azure/governance/policy/overview#assignments 2.N Allowed Resource Type (Deny): Defines the resource types that you can deploy. Its effect is to deny all resources that aren't part of this defined list. https://learn.microsoft.com/en-us/azure/governance/policy/overview#policy-definition 3.N A subscription will be a direct member of only one management group. https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/ready/azure-best-practices/organize-subscriptions#azure-management-groups
upvoted 3 times
...
kamalpur
9 months ago
This question is explained in the below video with the concept. https://youtu.be/ajrGaguGg90
upvoted 1 times
avidlearner
8 months, 2 weeks ago
that's a wrong explanation. he says you can create a VM , which you can't because you can't create the VNet on sub2. He says answer is NYN, in my logical opinion it's just not what you can do it's whether it's allowed. Answer should be NNN
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...