Check your knowledge

Completed
1.

If a Policy is applied with the deny option to a Resource group, what happens to already existing noncompliant resources in that group?

2.

What happens when you have a Policy set as deny at the Subscription level and the same Policy set as audit at the Resource group level?

3.

You have an Azure Policy applied at the Subscription level, but one of your AKS clusters needs to be exempt from a specific policy, what's the best way to handle that?