Courseiva

SC-100 Practice Question: Design security solutions for applications and data

Exhibit

{
  "properties": {
    "policyRule": {
      "if": {
        "allOf": [
          {
            "field": "type",
            "equals": "Microsoft.Storage/storageAccounts"
          },
          {
            "field": "Microsoft.Storage/storageAccounts/supportsHttpsTrafficOnly",
            "equals": "false"
          }
        ]
      },
      "then": {
        "effect": "deny"
      }
    }
  }
}

Refer to the exhibit. A security architect is reviewing an Azure Policy definition. What is the effect of this policy?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Denies creation or update of storage accounts that do not require HTTPS traffic

The correct answer is C: the policy denies creation or update of storage accounts that do not require HTTPS traffic. In Azure Policy, a Deny effect blocks the request at the resource provider during create or update operations when the resource does not satisfy the condition, so a storage account with supportsHttpsTrafficOnly set to false would be rejected. Option A is incorrect because Modify effects change properties via remediation and do not block the request. Option B is incorrect because Audit only records non-compliance without preventing deployment. Option D is incorrect because DeployIfNotExists remediation tasks are triggered after evaluation and do not deny the original request.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Modifies storage accounts to enable HTTPS traffic only

    Why it's wrong here

    This option confuses the 'deny' effect with a remediation or modification capability. Azure Policy with a 'deny' effect never alters the resource configuration; it only blocks the create or update request if the desired 'supportsHttpsTrafficOnly' setting is false. Because the policy is evaluated during resource provisioning, any non-compliant storage account is rejected before it exists. Changing an existing account to require HTTPS would require a separate 'modify' or 'deployIfNotExists' policy definition.

  • ✗

    Audits storage accounts that do not require HTTPS traffic

    Why it's wrong here

    The 'audit' effect only logs a compliance warning and does not prevent the creation or update of a non-compliant resource. This policy definition explicitly uses the 'deny' effect, which actively stops the deployment of storage accounts that have the property 'supportsHttpsTrafficOnly' set to false or absent. Audit would simply record the resource as non-compliant in the Azure Policy compliance report, but the resource would still be provisioned. Therefore, saying it audits is inaccurate; it enforces a hard block.

  • ✓

    Denies creation or update of storage accounts that do not require HTTPS traffic

    Why this is correct

    The 'deny' effect is the correct behavior for this policy definition. When a request to create or update a storage account arrives at Azure Resource Manager, the policy engine checks whether the property 'supportsHttpsTrafficOnly' is set to 'true'. If the property is false or omitted, the entire create or update operation is rejected with a policy violation error. This ensures that no new or updated storage account can be deployed without requiring HTTPS traffic, providing a strong security control.

  • ✗

    Deploys a remediation task to enable HTTPS traffic only

    Why it's wrong here

    Remediation tasks are only meaningful for policy definitions that use the 'deployIfNotExists' or 'modify' effects, because those effects can apply changes to existing non-compliant resources. A 'deny' effect has no remediation action; it simply blocks non-compliant requests at the point of evaluation. Since this policy uses 'deny', there is no remediation task that could enable HTTPS traffic only on existing accounts. Enabling HTTPS on existing storage accounts would require a separate policy definition with a 'modify' effect or an out-of-band script.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.