Refer to the exhibit. You deployed an Azure Storage account with this ARM template. Users outside the allowed IP range receive '403 Forbidden' errors. What is the MOST likely cause?
When the network ACL default action for an Azure Storage account is set to 'Deny', it explicitly blocks all network traffic to the storage account by default. This means that only requests originating from IP addresses or Virtual Network subnets that are explicitly added to the allowed list will be permitted. Any client attempting to access the storage account from an unlisted network source will receive a 403 Forbidden error, as their request is understood but explicitly unauthorized by the network security configuration.
Why this answer
The default action for network ACLs in Azure Storage is 'Deny' when no explicit rules match. Since the ARM template only allows traffic from the IP range 203.0.113.0/24, all other IP addresses are implicitly denied, resulting in 403 Forbidden errors for users outside that range.
Exam trap
The trap here is that candidates often focus on the IP rule (option C) as the direct cause, but the real issue is the default action being set to 'Deny', which makes the rule an exclusive allow list rather than a permissive one.
How to eliminate wrong answers
Option A is wrong because the access tier (Cool vs. Hot) affects storage costs and retrieval latency, not network access control; it cannot cause 403 errors. Option B is wrong because the minimum TLS version (TLS1_2) enforces encryption protocol requirements for client connections, but it does not block IP addresses; a client using TLS 1.2 would still be allowed if its IP is permitted.
Option C is wrong because the IP rule allowing only 203.0.113.0/24 is the explicit allow rule, but it is not the cause of the 403 error—the error occurs because the default action (Deny) blocks all other IPs, not because the rule itself is restrictive.