You need to run a script inside an Azure virtual machine after deployment to install application prerequisites. Which feature should you use?
The Custom Script Extension is an Azure VM extension that uses the Azure Guest Agent to download and execute a script on the VM, either during initial deployment via ARM template or on a running VM. It supports PowerShell and Bash, runs with system privileges, and is the standard way to run post-deployment configuration tasks like installing software or applying settings.
Why this answer
The Custom Script Extension (CSE) is the correct feature because it allows you to run a script inside an Azure VM after deployment, making it ideal for installing application prerequisites. CSE downloads and executes scripts on the VM, supporting both Windows (via PowerShell) and Linux (via Bash) environments, and can be applied during initial provisioning or to an existing VM.
Exam trap
The trap here is that candidates often confuse Azure Policy (a governance tool) with the Custom Script Extension (a VM-level execution tool), mistakenly thinking Policy can run scripts to enforce configurations inside the VM, when in reality Policy only audits or remediates Azure resource properties, not guest OS actions.
Why the other options are wrong
Azure Policy is used to enforce compliance rules and audit resource configurations, not to run scripts inside a VM after deployment.
Boot diagnostics captures serial console output and screenshots to troubleshoot VM boot failures, but it cannot run scripts or install software after deployment.
A proximity placement group is used to reduce network latency between Azure resources by ensuring they are physically close, not for running scripts or installing software on a VM after deployment.
When would these options actually be correct?
You need to ensure that all VMs in a subscription are deployed with a specific tag or have encryption enabled. Azure Policy would be used to audit or enforce those rules.
You need to troubleshoot why an Azure VM is not booting correctly after a configuration change. Boot diagnostics would provide the necessary logs and screenshots to identify the issue.
When the question asks how to minimize network latency between VMs in a high-performance computing workload, a proximity placement group would be the correct answer.
Why candidates pick the wrong answer
Candidates may confuse policy enforcement with post-deployment configuration tasks, thinking a policy can trigger script execution.
Candidates may confuse boot diagnostics with post-deployment configuration tools, thinking it can execute scripts during the boot process.
Candidates might confuse 'placement' with 'deployment' tasks, thinking it involves post-deployment configuration, or they may not fully understand the purpose of proximity placement groups.