AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Exhibit
{"properties":{"displayName":"Deploy Microsoft Defender for Cloud security contacts","policyType":"BuiltIn","mode":"All","description":"Deploys security contact settings for subscriptions.","metadata":{"version":"1.0.0","category":"Security Center"},"parameters":{},"policyRule":{"if":{"field":"type","equals":"Microsoft.Subscription"},"then":{"effect":"deployIfNotExists","details":{"type":"Microsoft.Security/securityContacts","name":"default","existenceCondition":{"field":"Microsoft.Security/securityContacts/email","notEquals":""},"deployment":{"properties":{"template":{"$schema":"https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#","contentVersion":"1.0.0.0","resources":[{"type":"Microsoft.Security/securityContacts","name":"default","properties":{"email":"security@contoso.com","phone":"555-1234","alertNotifications":{"state":"On","minimalSeverity":"High"},"notificationsByRole":{"state":"On","roles":["Owner"]}}}]}}}}}}Refer to the exhibit. You assign this policy to a subscription that already has a security contact configured with email 'admin@contoso.com'. What will be the outcome?
⚠ Common exam trap
Watch out — candidates often assume Azure Policy will enforce a specific configuration value (like the email address) and overwrite any existing setting, but 'DeployIfNotExists' only cares about the existence of the resource, not its properties, unless the policy rule explicitly includes a property match condition.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy will not modify the existing security contact because it already exists.
The Azure Policy definition shown uses the 'DeployIfNotExists' effect, which only deploys a resource (in this case, a security contact) if it does not already exist. Since the subscription already has a security contact configured with email 'admin@contoso.com', the policy will detect its presence and skip the deployment, leaving the existing contact unchanged. This behavior is by design to avoid overwriting existing configurations that may have been set manually or by other processes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The policy will not modify the existing security contact because it already exists.
Why this is correct
The deployIfNotExists effect first evaluates the existence condition—here, checking whether a security contact with a non-empty email already exists. Because that condition is true, the policy skips the deployment template entirely, leaving the existing security contact unchanged. As a result, the policy is compliant and no modification occurs to the already-provisioned contact.
- ✗
The policy will fail because the security contact already exists.
Why it's wrong here
A deployIfNotExists policy does not treat an existing resource as an error; the existence condition is designed to prevent deployment when the resource is already present. Since a security contact with a non-empty email exists, the policy evalutes to true and no deployment is triggered, so the policy succeeds and remains non-compliant. The policy will not fail—it only fails on deployment errors if the existence condition were false and the template could not deploy.
- ✗
The subscription will become non-compliant because the email does not match.
Why it's wrong here
The policy's existence condition only tests whether a security contact exists with a non-empty email address; it does not inspect the value of that email. Therefore, even if the existing contact's email differs from the one defined in the policy, the contact still satisfies the existence condition, and the policy marks the subscription as compliant. Non-compliance would only occur if no such contact existed, not because of an email mismatch.
- ✗
The policy will overwrite the existing security contact with the one in the policy.
Why it's wrong here
The deployIfNotExists effect explicitly skips deployment when the existence condition is satisfied, meaning an existing resource is never overwritten or updated by the policy's ARM template. Because a security contact with a non-empty email already exists, the policy does not execute the deployment action that would replace its properties. The word 'ifNotExists' is the key: it only deploys when the resource is absent, so overwriting is impossible in this scenario.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.