Courseiva

DP-203 Design and implement data storage Practice Question

Exhibit

Refer to the exhibit.

{
  "policyRule": {
    "if": {
      "field": "type",
      "equals": "Microsoft.Storage/storageAccounts"
    },
    "then": {
      "effect": "deny",
      "details": {
        "field": "Microsoft.Storage/storageAccounts/networkAcls.defaultAction",
        "equals": "Allow"
      }
    }
  }
}

Refer to the exhibit. An Azure Policy is defined to enforce network security on storage accounts. What does this policy do?

⚠ Common exam trap

Many candidates confuse the 'defaultAction' property with the presence of IP rules or firewall settings, leading them to think the policy denies accounts with any firewall rules rather than those that allow all networks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Denies storage accounts that allow public network access from all networks

The Azure Policy in the exhibit uses the 'Deny' effect with a condition that checks if the 'networkAcls.defaultAction' property is set to 'Allow'. When 'defaultAction' is 'Allow', the storage account permits traffic from all networks, including the internet. The policy denies such configurations to enforce network security by requiring that public network access be restricted.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Denies storage accounts that do not have any IP rules defined

    Why it's wrong here

    The policy's condition targets accounts lacking IP rules, but the exhibit enforces private endpoint or firewall configuration, so this misreads the rule's effect. It is tempting because IP rules are a genuine network restriction, and denying accounts without them would be correct if the policy aimed to mandate IP allowlists rather than block public access.

  • ✗

    Denies storage accounts that have firewall rules configured

    Why it's wrong here

    Firewall rules are the mechanism the policy permits, not the condition it denies; the exhibit denies accounts where public network access remains enabled. It is tempting because firewall rules and private endpoints both restrict traffic, and a policy denying accounts with no firewall would be correct if the requirement were firewall-based rather than public-access-based.

  • ✗

    Denies storage accounts that have public network access disabled

    Why it's wrong here

    The policy denies accounts where public network access is enabled, so denying accounts that have it disabled inverts the condition. It is tempting because disabling public access is the desired secure state, and a policy denying accounts without that setting would be correct if the intent were to enforce private-only access.

  • ✓

    Denies storage accounts that allow public network access from all networks

    Why this is correct

    The policy's `Deny` effect blocks creation or update of storage accounts whose network ACL default action permits access from all networks, satisfying the stem's network-security enforcement constraint. It evaluates the `networkAcls.defaultAction` property, rejecting any resource where that value equals `Allow` rather than `Deny`.

About these practice questions

One of 509 original DP-203 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.