Courseiva

SC-100 Design security solutions for infrastructure Practice Question

Exhibit

{
  "properties": {
    "displayName": "Deny public IP on NICs",
    "policyType": "Custom",
    "mode": "All",
    "policyRule": {
      "if": {
        "allOf": [
          {
            "field": "type",
            "equals": "Microsoft.Network/networkInterfaces"
          },
          {
            "field": "Microsoft.Network/networkInterfaces/ipConfigurations[*].publicIPAddress.id",
            "exists": "true"
          }
        ]
      },
      "then": {
        "effect": "Deny"
      }
    }
  }
}

Refer to the exhibit. A company applies this Azure Policy to their subscription. An administrator tries to create a VM with a public IP address. What will happen?

⚠ Common exam trap

SC-100 often tests the difference between Azure Policy effects — candidates confuse Deny (blocks creation) with Audit (logs non-compliance) or Modify (changes the resource), and pick 'alert generated' or 'automatically removed' incorrectly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The VM creation will be denied

Azure Policy with a 'Deny' effect blocks the non-compliant resource creation request at the Azure Resource Manager layer, so the VM creation with a public IP will be denied. The policy is evaluated during the ARM template/resource deployment, and if the resource violates the rule, the request fails with a policy violation error. This is the intended behavior of a Deny-effect policy assignment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The public IP will be automatically removed

    Why it's wrong here

    The Azure Policy Deny effect is evaluated before the resource is created, meaning it blocks the entire deployment operation rather than intervening post-provisioning. If the NIC template includes a public IP, the deny rule rejects the NIC creation, and because the VM cannot function without a NIC, the VM creation also fails. Azure Policy does not perform any form of automatic remediation, such as removing a public IP from a resource that already exists or is being created.

  • ✓

    The VM creation will be denied

    Why this is correct

    The policy explicitly prohibits the creation of network interfaces that are configured with a public IP, and since a virtual machine must have at least one NIC to boot, any VM deployment that attempts to attach a public IP to its primary NIC will be blocked. The deny effect causes the entire deployment request to fail with a conflict or forbidden error, preventing both the NIC and the VM from being created. This is a hard failure, not a soft warning, because the policy's effect is Deny, not Audit or Modify.

  • ✗

    The VM will be created, but an alert will be generated

    Why it's wrong here

    The Deny effect in Azure Policy does not generate an alert; it aborts the resource creation before any resource is provisioned. In contrast, the Audit effect would log a compliance warning and allow the VM to be created, but here the policy is configured with Deny, so the deployment simply fails. No alert is issued because Azure Policy does not have a built-in alerting mechanism for denied operations; the only feedback is the error message returned to the deployment pipeline.

  • ✗

    The policy will only apply to VMs in a specific resource group

    Why it's wrong here

    The policy assignment is scoped to the entire subscription, not to a single resource group, so it applies to all VMs and NICs created in any resource group under that subscription. Even if the scope were narrowed to one resource group, the policy would still deny affected deployments within that group, but that is not the case in this exhibit. The scope is clearly the subscription, making this answer incorrect because the policy is not limited to a specific resource group.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.