DP-203 Design and implement data storage Practice Question
Exhibit
Refer to the exhibit.
{
"policyRule": {
"if": {
"field": "type",
"equals": "Microsoft.Storage/storageAccounts"
},
"then": {
"effect": "deny",
"details": {
"field": "Microsoft.Storage/storageAccounts/networkAcls.defaultAction",
"equals": "Allow"
}
}
}
}Refer to the exhibit. An Azure Policy is defined to enforce network security on storage accounts. What does this policy do?
⚠ Common exam trap
Many candidates confuse the 'defaultAction' property with the presence of IP rules or firewall settings, leading them to think the policy denies accounts with any firewall rules rather than those that allow all networks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Denies storage accounts that allow public network access from all networks
The Azure Policy in the exhibit uses the 'Deny' effect with a condition that checks if the 'networkAcls.defaultAction' property is set to 'Allow'. When 'defaultAction' is 'Allow', the storage account permits traffic from all networks, including the internet. The policy denies such configurations to enforce network security by requiring that public network access be restricted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Denies storage accounts that do not have any IP rules defined
Why it's wrong here
The policy's condition targets accounts lacking IP rules, but the exhibit enforces private endpoint or firewall configuration, so this misreads the rule's effect. It is tempting because IP rules are a genuine network restriction, and denying accounts without them would be correct if the policy aimed to mandate IP allowlists rather than block public access.
- ✗
Denies storage accounts that have firewall rules configured
Why it's wrong here
Firewall rules are the mechanism the policy permits, not the condition it denies; the exhibit denies accounts where public network access remains enabled. It is tempting because firewall rules and private endpoints both restrict traffic, and a policy denying accounts with no firewall would be correct if the requirement were firewall-based rather than public-access-based.
- ✗
Denies storage accounts that have public network access disabled
Why it's wrong here
The policy denies accounts where public network access is enabled, so denying accounts that have it disabled inverts the condition. It is tempting because disabling public access is the desired secure state, and a policy denying accounts without that setting would be correct if the intent were to enforce private-only access.
- ✓
Denies storage accounts that allow public network access from all networks
Why this is correct
The policy's `Deny` effect blocks creation or update of storage accounts whose network ACL default action permits access from all networks, satisfying the stem's network-security enforcement constraint. It evaluates the `networkAcls.defaultAction` property, rejecting any resource where that value equals `Allow` rather than `Deny`.
Go deeper
Related to this question
About these practice questions
One of 509 original DP-203 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.