AZ-305 Design data storage solutions Practice Question
Exhibit
{
"statement": "{\"Effect\": \"Deny\", \"Action\": [\"Microsoft.Storage/storageAccounts/blobServices/containers/write\"], \"NotAction\": [], \"Resource\": \"Microsoft.Storage/storageAccounts/*\", \"Condition\": {\"Bool\": {\"acs:RequestAction\": [\"Microsoft.Storage/storageAccounts/blobServices/containers/put\"]}}}",
"policyName": "DenyContainerCreationWithoutEncryption"
}Refer to the exhibit. An Azure Policy is assigned to a subscription. A user tries to create a blob container via the Azure portal and receives a deny error. What is the most likely reason?
⚠ Common exam trap
Watch out — candidates often assume the error is due to a missing feature or configuration (like immutability or encryption) rather than recognizing that Azure Policy can directly deny resource creation actions based on custom or built-in policy definitions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy denies creation of blob containers
The Azure Policy assigned to the subscription includes a policy definition that explicitly denies the creation of blob containers. When the user attempts to create a blob container via the Azure portal, Azure Policy evaluates the request against the assigned policies and returns a deny error because the action violates the policy rule. This is the most direct and likely reason for the denial.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The policy denies creation of blob containers
Why this is correct
The policy definition applies a Deny effect to the action Microsoft.Storage/storageAccounts/blobServices/containers/write and further constrains the condition to requests where the HTTP method is PUT. Since creating a blob container is performed through a PUT request to the containers endpoint, this policy blocks that creation attempt outright. The policy does not evaluate container properties or settings; it simply prevents the write operation itself, so any PUT aimed at creating a container will fail with an authorization/denial error.
- ✗
The blob container requires immutable storage
Why it's wrong here
Immutable storage, also known as WORM (Write Once, Read Many), is configured through immutability policies on a container or a storage account (e.g., Microsoft.Storage/storageAccounts/blobServices/containers/immutabilityPolicies). The policy in the exhibit references only the containers/write action and the HTTP method PUT, not any immutability-related ARM resource type or property. Therefore, the denial is not caused by a requirement for immutable storage; the policy would deny the container creation regardless of whether immutability is enabled, disabled, or unset, because the condition does not inspect that attribute.
- ✗
The user is trying to enable public access on the container
Why it's wrong here
Public access for a blob container is controlled by the container's 'publicAccess' property, which governs anonymous read access to blobs and containers. This policy definition, however, does not include any condition on 'publicAccess' or any other property of the container; its only conditions are the resource type and the request method (PUT). Even if the user was attempting to enable public access on a new container, the underlying write request is what gets denied, not the public access setting—the policy would equally deny a PUT request that sets publicAccess to 'None' or omits it, so the cause is the write operation itself.
- ✗
The storage account does not have encryption enabled
Why it's wrong here
Storage Service Encryption (SSE) is enabled for all Azure Storage accounts by default and is configured at the storage account level, not via a container-level write operation. The policy under consideration is scoped to 'Microsoft.Storage/storageAccounts/blobServices/containers/write' and checks only for the HTTP method being PUT, making no reference to the 'encryption' property or any storage account settings. If encryption were not enabled, the error would typically be an Azure Policy denial on the storage account resource type (e.g., Microsoft.Storage/storageAccounts) with an encryption condition, which is not the case here. Thus, this option incorrectly attributes the denial to a storage-account-level encryption requirement that the policy never inspects.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.