mediumMultiple Choice
SC-100 Practice Question: Implementing a cloud security governance strategy
A company is implementing a cloud security governance strategy. They need to ensure that all Azure resources are compliant with internal security policies before deployment. Which approach should they use?
⚠ Common exam trap
Many exam-takers confuse Azure Policy with Azure Blueprints, thinking Blueprints enforce compliance, but Blueprints only package and deploy policies—the actual enforcement comes from the Policy definitions themselves.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign Azure Policy definitions with 'deny' effect at the subscription scope
Azure Policy with the 'deny' effect is the correct approach because it proactively prevents the deployment of any resource that violates defined security policies at the subscription scope. This ensures compliance before deployment by evaluating the resource against policy rules during the creation or update operation, blocking the request if non-compliant. Unlike reactive measures, this enforces governance at the point of deployment without requiring post-deployment remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure Azure Firewall to block non-compliant resources
Why it's wrong here
Azure Firewall operates at the network layer, inspecting and filtering IP addresses, ports, and protocols after a resource is deployed and generating traffic. It has no visibility into Azure Resource Manager provisioning requests, so it cannot prevent a non-compliant storage account or VM from being created; it can only block its subsequent network communication. Compliance violations that don't create traffic, or resources that remain idle, evade firewall checks entirely.
- ✓
Assign Azure Policy definitions with 'deny' effect at the subscription scope
Why this is correct
Assigning a policy with the 'deny' effect at subscription scope makes Azure Resource Manager evaluate every create/update operation against the policy rule before provisioning. If a resource is non-compliant, the platform rejects the request with a 403 or similar error, so no infrastructure is ever deployed that violates governance. Because this happens in the control plane, it works uniformly for portal, CLI, PowerShell, templates, and DevOps pipelines, closing the gap that manual or network-based controls leave open.
- ✗
Deploy resources using Azure Blueprints
Why it's wrong here
Azure Blueprints orchestrates a collection of ARM templates, policy assignments, role assignments, and resource groups to stand up a full environment, but the blueprint object itself does not continuously inspect or deny individual resource configurations after deployment. Although an included policy can enforce compliance, Blueprints is just the composition and deployment mechanism; it adds no ongoing enforcement beyond the policies it happens to reference. Without a deny policy, a Blueprint deployment can still produce non-compliant artifacts if templates drift, and Blueprints cannot retroactively block non-compliant resources that are later modified.
- ✗
Use Azure DevOps pipelines with manual approval gates
Why it's wrong here
Manual approval gates in Azure DevOps introduce a human checkpoint into a pipeline, but they depend on an approver reviewing a stage and deciding to release; they are not an automated, deterministic rule evaluated by Azure. Once a resource is created, including a non-compliant one, the pipeline's gate has already done its only job and cannot block changes made through other paths like the portal or direct API calls. Manual approval also creates latency and is vulnerable to subjective judgment, so it does not provide the continuous, guaranteed compliance enforcement that policy-based 'deny' does.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.