Courseiva
hardMultiple Choice

SC-100 Practice Question: A company uses Azure Policy to enforce compliance

A company uses Azure Policy to enforce compliance. They have a custom policy that denies creation of storage accounts without encryption enabled. A developer reports that they cannot create a storage account even though they specified encryption. What is the most likely cause?

⚠ Common exam trap

A common mix-up: candidates assume permission issues (Option A) or scope problems (Option D) are the cause, but the real issue is a misconfigured condition in the policy definition that fails to correctly match the encryption property.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The policy's 'then' block uses 'deny' but the condition logic evaluates the 'encryption' property incorrectly

The most likely cause is that the policy's condition logic incorrectly evaluates the 'encryption' property. Azure Policy uses JSON-based condition expressions to check resource properties; if the condition does not match the actual property path (e.g., 'properties.encryption.enabled' vs. 'properties.encryption') or uses an incorrect operator, the deny effect will trigger even when encryption is specified. This is a common misconfiguration in custom policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The developer does not have 'Microsoft.Authorization/policyAssignments/write' permission

    Why it's wrong here

    The Microsoft.Authorization/policyAssignments/write action is required to create or modify policy assignments, not to deploy resources. Resource creation is controlled by separate RBAC write permissions on the resource provider (e.g., Microsoft.Storage/storageAccounts/write). Azure Policy's deny effect is enforced by the policy engine during the deployment request, regardless of whether the user can manage policy assignments. Therefore, this missing permission would not cause the developer's resource creation to be blocked.

  • ✗

    The policy effect is set to 'audit' instead of 'deny'

    Why it's wrong here

    An 'audit' effect only records a compliance message in the activity log when the defined condition is true; it never prevents the resource from being created. If the policy were set to audit, the developer would see a successful deployment and a non-compliant resource marked in compliance reports. Since the developer is facing a deployment failure, the effect must be 'deny' or another blocking effect like 'modify' with a deny action. Thus, this option does not explain the observed behavior.

  • ✓

    The policy's 'then' block uses 'deny' but the condition logic evaluates the 'encryption' property incorrectly

    Why this is correct

    A deny policy can block a resource if the condition evaluates to true, but the condition must reference the correct property path via an Azure Policy alias. In this scenario, the condition likely uses an incorrect field or alias for the encryption property, causing the policy engine to consider the resource non-compliant even when encryption is properly configured. For example, using 'properties.encryption.enabled' instead of the correct alias 'Microsoft.Storage/storageAccounts/encryption.services.blob.enabled' can make the condition always true. This mis-evaluation leads the deny effect to fire incorrectly, preventing the storage account from being created.

  • ✗

    The policy is scoped to a management group that includes the developer's subscription

    Why it's wrong here

    Scoping a policy to a management group ensures that all subscriptions under that management group inherit the policy and are evaluated for compliance. This is the intended behavior for centralized policy management, not a misconfiguration that would cause unexpected blocks. If the policy is correctly defined, resources in a child subscription should be evaluated and denied if non-compliant. The unexpected denial is more likely due to a faulty condition in the policy definition rather than the scope itself.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.