Courseiva

AZ-305 Design data storage solutions Practice Question

Exhibit

{
  "statement": "{\"Effect\": \"Deny\", \"Action\": [\"Microsoft.Storage/storageAccounts/blobServices/containers/write\"], \"NotAction\": [], \"Resource\": \"Microsoft.Storage/storageAccounts/*\", \"Condition\": {\"Bool\": {\"acs:RequestAction\": [\"Microsoft.Storage/storageAccounts/blobServices/containers/put\"]}}}",
  "policyName": "DenyContainerCreationWithoutEncryption"
}

Refer to the exhibit. An Azure Policy is assigned to a subscription. A user tries to create a blob container via the Azure portal and receives a deny error. What is the most likely reason?

⚠ Common exam trap

Watch out — candidates often assume the error is due to a missing feature or configuration (like immutability or encryption) rather than recognizing that Azure Policy can directly deny resource creation actions based on custom or built-in policy definitions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The policy denies creation of blob containers

The Azure Policy assigned to the subscription includes a policy definition that explicitly denies the creation of blob containers. When the user attempts to create a blob container via the Azure portal, Azure Policy evaluates the request against the assigned policies and returns a deny error because the action violates the policy rule. This is the most direct and likely reason for the denial.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The policy denies creation of blob containers

    Why this is correct

    The policy definition applies a Deny effect to the action Microsoft.Storage/storageAccounts/blobServices/containers/write and further constrains the condition to requests where the HTTP method is PUT. Since creating a blob container is performed through a PUT request to the containers endpoint, this policy blocks that creation attempt outright. The policy does not evaluate container properties or settings; it simply prevents the write operation itself, so any PUT aimed at creating a container will fail with an authorization/denial error.

  • ✗

    The blob container requires immutable storage

    Why it's wrong here

    Immutable storage, also known as WORM (Write Once, Read Many), is configured through immutability policies on a container or a storage account (e.g., Microsoft.Storage/storageAccounts/blobServices/containers/immutabilityPolicies). The policy in the exhibit references only the containers/write action and the HTTP method PUT, not any immutability-related ARM resource type or property. Therefore, the denial is not caused by a requirement for immutable storage; the policy would deny the container creation regardless of whether immutability is enabled, disabled, or unset, because the condition does not inspect that attribute.

  • ✗

    The user is trying to enable public access on the container

    Why it's wrong here

    Public access for a blob container is controlled by the container's 'publicAccess' property, which governs anonymous read access to blobs and containers. This policy definition, however, does not include any condition on 'publicAccess' or any other property of the container; its only conditions are the resource type and the request method (PUT). Even if the user was attempting to enable public access on a new container, the underlying write request is what gets denied, not the public access setting—the policy would equally deny a PUT request that sets publicAccess to 'None' or omits it, so the cause is the write operation itself.

  • ✗

    The storage account does not have encryption enabled

    Why it's wrong here

    Storage Service Encryption (SSE) is enabled for all Azure Storage accounts by default and is configured at the storage account level, not via a container-level write operation. The policy under consideration is scoped to 'Microsoft.Storage/storageAccounts/blobServices/containers/write' and checks only for the HTTP method being PUT, making no reference to the 'encryption' property or any storage account settings. If encryption were not enabled, the error would typically be an Azure Policy denial on the storage account resource type (e.g., Microsoft.Storage/storageAccounts) with an encryption condition, which is not the case here. Thus, this option incorrectly attributes the denial to a storage-account-level encryption requirement that the policy never inspects.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.