Courseiva

AZ-500 Secure compute, storage, and databases Practice Question

Exhibit

Refer to the exhibit.

{
  "properties": {
    "policyRule": {
      "if": {
        "allOf": [
          {
            "field": "type",
            "equals": "Microsoft.Storage/storageAccounts"
          },
          {
            "field": "Microsoft.Storage/storageAccounts/supportsHttpsTrafficOnly",
            "equals": "false"
          }
        ]
      },
      "then": {
        "effect": "deny"
      }
    }
  }
}

You are reviewing an Azure Policy definition. You need to determine the effect of this policy when a user attempts to create a new storage account with 'Secure transfer required' set to 'Disabled'. What happens?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The creation request is denied.

The correct answer is B: the creation request is denied. This policy uses a Deny effect, which blocks any request that violates the policy rule—here, creating a storage account with 'Secure transfer required' set to Disabled—so the deployment fails before the resource is provisioned. Option A is wrong because Deny does not remediate or modify the request; auto-enabling would require a Modify or DeployIfNotExists effect. Option C is wrong because generating an audit event corresponds to the Audit effect, which only logs non-compliance without blocking. Option D is wrong because Deny actively prevents the non-compliant creation rather than allowing it silently.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The storage account is created but 'Secure transfer required' is automatically enabled.

    Why it's wrong here

    This is incorrect because a policy with the Deny effect operates at request evaluation time and does not apply or enable resource properties. The Deny effect only blocks the create or update operation when the condition is true; it never retroactively modifies a property like 'Secure transfer required' on a newly created storage account. Automatically enabling that setting would require a different effect such as Modify or DeployIfNotExists, not Deny.

  • ✓

    The creation request is denied.

    Why this is correct

    This is correct: when the Azure Policy definition contains the effect 'deny', the policy engine evaluates the incoming resource creation request and, if the defined condition (for example, a storage account lacking 'Secure transfer required') is true, the request is rejected before any resource is provisioned. The operation fails with an error such as 403 Forbidden or a policy enforcement error, and no storage account is created. Policy enforcement is deterministic and prevents the non-compliant resource from entering the environment.

  • ✗

    The creation is allowed but an audit event is generated.

    Why it's wrong here

    This describes the behavior of the Audit effect, not Deny. An Audit effect writes a warning to the Azure Activity Log when a non-compliant resource is created, but it does not block the creation operation, so the storage account would still exist without the required setting. Since the policy in question has the Deny effect, the creation would not be allowed, and no audit event would be the primary outcome because the request is stopped.

  • ✗

    The creation is allowed and no action is taken.

    Why it's wrong here

    This would be possible only if the policy effect were set to Disabled, meaning the definition is not evaluated for compliance, or if the policy did not match the resource being deployed. A Deny effect never results in 'no action taken'—it actively blocks the request by returning a denial response to the calling client. Additionally, 'no action taken' is not a valid Azure Policy effect, so this outcome cannot occur for any active policy effect.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.