SC-100 Design security solutions for infrastructure Practice Question
Exhibit
{
"properties": {
"displayName": "Deny public IP on NICs",
"policyType": "Custom",
"mode": "All",
"policyRule": {
"if": {
"allOf": [
{
"field": "type",
"equals": "Microsoft.Network/networkInterfaces"
},
{
"field": "Microsoft.Network/networkInterfaces/ipConfigurations[*].publicIPAddress.id",
"exists": "true"
}
]
},
"then": {
"effect": "Deny"
}
}
}
}Refer to the exhibit. A company applies this Azure Policy to their subscription. An administrator tries to create a VM with a public IP address. What will happen?
⚠ Common exam trap
SC-100 often tests the difference between Azure Policy effects — candidates confuse Deny (blocks creation) with Audit (logs non-compliance) or Modify (changes the resource), and pick 'alert generated' or 'automatically removed' incorrectly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The VM creation will be denied
Azure Policy with a 'Deny' effect blocks the non-compliant resource creation request at the Azure Resource Manager layer, so the VM creation with a public IP will be denied. The policy is evaluated during the ARM template/resource deployment, and if the resource violates the rule, the request fails with a policy violation error. This is the intended behavior of a Deny-effect policy assignment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The public IP will be automatically removed
Why it's wrong here
The Azure Policy Deny effect is evaluated before the resource is created, meaning it blocks the entire deployment operation rather than intervening post-provisioning. If the NIC template includes a public IP, the deny rule rejects the NIC creation, and because the VM cannot function without a NIC, the VM creation also fails. Azure Policy does not perform any form of automatic remediation, such as removing a public IP from a resource that already exists or is being created.
- ✓
The VM creation will be denied
Why this is correct
The policy explicitly prohibits the creation of network interfaces that are configured with a public IP, and since a virtual machine must have at least one NIC to boot, any VM deployment that attempts to attach a public IP to its primary NIC will be blocked. The deny effect causes the entire deployment request to fail with a conflict or forbidden error, preventing both the NIC and the VM from being created. This is a hard failure, not a soft warning, because the policy's effect is Deny, not Audit or Modify.
- ✗
The VM will be created, but an alert will be generated
Why it's wrong here
The Deny effect in Azure Policy does not generate an alert; it aborts the resource creation before any resource is provisioned. In contrast, the Audit effect would log a compliance warning and allow the VM to be created, but here the policy is configured with Deny, so the deployment simply fails. No alert is issued because Azure Policy does not have a built-in alerting mechanism for denied operations; the only feedback is the error message returned to the deployment pipeline.
- ✗
The policy will only apply to VMs in a specific resource group
Why it's wrong here
The policy assignment is scoped to the entire subscription, not to a single resource group, so it applies to all VMs and NICs created in any resource group under that subscription. Even if the scope were narrowed to one resource group, the policy would still deny affected deployments within that group, but that is not the case in this exhibit. The scope is clearly the subscription, making this answer incorrect because the policy is not limited to a specific resource group.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.