Courseiva
hardMultiple Choice

SC-100 Practice Question: A company uses Azure Policy to enforce compliance

A company uses Azure Policy to enforce compliance. They want to automatically remediate non-compliant resources by deploying a custom template. Which effect should they use in the policy definition?

⚠ Common exam trap

Watch out — candidates often confuse DeployIfNotExists with Deny, thinking that blocking non-compliant resources is sufficient for remediation, but Deny only prevents future non-compliance and does not fix existing resources.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DeployIfNotExists

The DeployIfNotExists effect is correct because it allows Azure Policy to automatically remediate non-compliant resources by deploying a custom ARM template when the resource is found to be non-compliant. This effect is specifically designed for automatic remediation scenarios, as it triggers a deployment to bring the resource into compliance without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    DeployIfNotExists

    Why this is correct

    DeployIfNotExists is correct because it actively remediates non-compliant resources by deploying an Azure Resource Manager (ARM) template defined in the policy rule. When a resource exists and fails compliance, this effect causes the template to be deployed, such as adding an agent or applying required configuration. It requires a managed identity and a remediation task to fully fix existing resources, making it the only effect among these that actually changes resources to bring them into compliance.

  • ✗

    Audit

    Why it's wrong here

    Audit is wrong because it only records the compliance status of a resource in the Azure Activity Log without making any attempt to modify or repair it. It is useful for generating alerts and compliance reports but leaves the resource in its non-compliant state, so it cannot enforce or remediate configuration. This effect is often chosen for initial monitoring before action is taken.

  • ✗

    Disabled

    Why it's wrong here

    Disabled is wrong because it completely disables the policy effect, meaning the policy definition is present but produces no compliance results or enforcement actions. It is not an enforcement or remediation mechanism; instead, it is a management convenience for temporarily switching off a policy without deleting the definition, so it cannot address any non-compliance.

  • ✗

    Deny

    Why it's wrong here

    Deny is wrong because it only prevents the creation or update of non-compliant resources within the policy scope, returning an error when a request is made. It does not affect resources that already exist, since existing resources are only reconsidered when they are updated or replaced. Therefore, Deny cannot fix current non-compliant deployments, which is exactly the requirement in the policy enforcement scenario.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.