Courseiva
Secure networking →mediumMultiple Choice

AZ-500 Secure networking Practice Question

Exhibit

Refer to the exhibit.

```json
{
  "properties": {
    "policyRule": {
      "if": {
        "field": "type",
        "equals": "Microsoft.Network/virtualNetworks"
      },
      "then": {
        "effect": "deny",
        "details": {
          "field": "Microsoft.Network/virtualNetworks/subnets",
          "existenceCondition": {
            "field": "Microsoft.Network/virtualNetworks/subnets/networkSecurityGroup",
            "exists": "false"
          }
        }
      }
    },
    "parameters": {}
  }
}
```

You are an Azure security engineer. Your team has assigned the Azure Policy shown in the exhibit. A developer creates a new virtual network with a subnet that does not have a Network Security Group (NSG) associated. What will happen when the policy is evaluated?

⚠ Common exam trap

It's easy for candidates to confuse the 'Deny' effect with 'Audit' or 'Append' effects, mistakenly thinking the virtual network will be created with a warning or that Azure will automatically remediate the missing NSG.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The virtual network creation fails because a subnet lacks an NSG.

The Azure Policy in the exhibit is configured with a 'Deny' effect for virtual networks that have subnets without an associated Network Security Group (NSG). When the developer attempts to create a virtual network with a subnet lacking an NSG, the policy evaluation triggers a denial of the entire virtual network creation operation. This is because the policy's condition checks each subnet for the presence of an NSG, and if any subnet is non-compliant, the 'Deny' effect prevents the resource from being created.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A default NSG is automatically associated with the subnet.

    Why it's wrong here

    Azure does not automatically create or associate a default NSG with a subnet. Subnets have no built-in NSG unless one is explicitly attached, and Azure Policy will not inject a default resource to satisfy a deny effect. The policy evaluates the incoming virtual network deployment as-is, sees a subnet without an NSG, and blocks the entire request, so the premise of an auto-created default NSG is false.

  • ✓

    The virtual network creation fails because a subnet lacks an NSG.

    Why this is correct

    A policy with the 'deny' effect prevents the entire virtual network resource from being deployed when any of its subnets lacks a network security group. During deployment, Azure Resource Manager evaluates the policy against the full resource definition; because the subnet does not reference an NSG, the whole virtual network creation fails atomically. This is the correct outcome because the deny effect stops non-compliant resources from ever being provisioned.

  • ✗

    The virtual network is created, but the subnet is denied.

    Why it's wrong here

    The deny effect does not allow a virtual network to be created while only the offender subnet is skipped. Azure Policy treats the virtual network and its subnets as a single resource definition during evaluation, so if any subnet is non-compliant, the entire virtual network is denied. Partial deployment or a 'denied subnet' is not how policy enforcement works; the resource is all-or-nothing.

  • ✗

    The virtual network is created, and a non-compliant alert is generated.

    Why it's wrong here

    A deny effect does not create the resource and then generate a non-compliance alert; it blocks the deployment before any resource is provisioned. An alert or audit event only occurs with the 'audit' effect, which logs compliance status but does not prevent creation. Therefore, the virtual network would not exist at all, and there is no resource to report as non-compliant.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.