A company named AeroSpace Dynamics is designing a governance strategy for its Azure environment. The environment consists of multiple subscriptions under a single management group.
You must enforce the following compliance requirements:
1. All resource groups must have an Owner tag. If a resource group is created without this tag, the tag must be automatically added and set to a default value during resource group creation.
2. All Azure SQL databases must have vulnerability assessment configured. If a database is deployed without it, the vulnerability assessment settings must be deployed automatically.
You need to recommend the Azure Policy effects that will satisfy these requirements without blocking resource creation.
Which two policy effects should you recommend? (Select two.)
- ModifyCevap
- DeployIfNotExistsCevap
- CDeny
- DAuditIfNotExists