mediumMultiple Choice
SC-100 Practice Question: A security administrator applies the Azure Policy…
Exhibit
Refer to the exhibit.
{
"policyRule": {
"if": {
"allOf": [
{
"field": "type",
"equals": "Microsoft.Storage/storageAccounts"
},
{
"field": "Microsoft.Storage/storageAccounts/supportsHttpsTrafficOnly",
"equals": "false"
}
]
},
"then": {
"effect": "deny"
}
}
}A security administrator applies the Azure Policy definition shown in the exhibit to a management group containing multiple subscriptions. After the policy is assigned, a development team reports they cannot create a new storage account in their subscription. What is the most likely cause?
⚠ Common exam trap
Many exam-takers confuse post-creation network controls (like NSGs) with pre-creation policy enforcement, or assume API version or regional limitations are the cause, when the actual denial stems from a specific property mismatch in the policy rule.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The storage account was created with the 'Secure transfer required' setting disabled.
The Azure Policy definition in the exhibit likely includes an effect (e.g., 'Deny') that requires the 'Secure transfer required' setting to be enabled on storage accounts. When the development team attempts to create a storage account with this setting disabled, the policy denies the request, preventing the creation. This is the most direct cause because Azure Policy enforces compliance rules at resource creation time, and disabling secure transfer violates the policy's condition.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The storage account was created using an older API version that does not support Azure Policy enforcement.
Why it's wrong here
Azure Policy enforces resource configuration at the control plane via Azure Resource Manager (ARM) regardless of the API version used in the creation request. The policy engine evaluates the final state of the resource, reading current property values such as SupportsHttpsTrafficOnly, independent of how the resource was instantiated. Even legacy API versions submit the resource to ARM, which then exposes the resource's schema for policy evaluation. Therefore, an older API version cannot bypass a Deny effect.
- ✗
The storage account was created in a region that does not support the premium tier.
Why it's wrong here
The policy rule specifically targets the SupportsHttpsTrafficOnly property of the storage account, which controls whether HTTPS is required for REST API traffic. Premium tier and region are storage account SKU and location attributes that are unrelated to this property. Azure Policy does not inspect tier or region for this definition, and a storage account in a non-premium region can still have secure transfer enabled. Thus, a region lacking premium tier is not a plausible cause of non-compliance.
- ✗
The storage account was assigned a network security group (NSG) that blocks inbound HTTPS traffic.
Why it's wrong here
Network Security Groups (NSGs) operate at the network layer and filter traffic between subnets and NICs, but Azure Policy evaluates the desired configuration of Azure resources at the control plane. The SupportsHttpsTrafficOnly property is a service setting that determines whether the storage account accepts requests over HTTP; it is independent of inbound traffic rules. Even an NSG that blocks all HTTPS would not change the value of this property or satisfy a policy requiring it to be true. Hence a blocking NSG cannot explain the policy violation.
- ✓
The storage account was created with the 'Secure transfer required' setting disabled.
Why this is correct
This is the correct reason. The Azure Policy definition likely contains a rule that denies or audits storage accounts where SupportsHttpsTrafficOnly is false. When secure transfer is disabled, the storage account accepts HTTP traffic, so the property is set to false and the policy marks the resource as non-compliant. If the policy effect is Deny, the storage account creation would even be blocked at deployment time. Therefore, the storage account was created with the 'Secure transfer required' setting disabled.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.