Courseiva

SC-100 Practice Question: Design security solutions for applications and data

Exhibit

{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "resources": [
    {
      "type": "Microsoft.Storage/storageAccounts/blobServices/containers",
      "apiVersion": "2021-09-01",
      "name": "[concat(parameters('storageAccountName'), '/default/', parameters('containerName'))]",
      "properties": {
        "publicAccess": "None"
      }
    }
  ]
}

Refer to the exhibit. A security architect is reviewing an ARM template that deploys an Azure Storage container. They want to ensure the container is not publicly accessible. What is the security implication of this template?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The template does not configure network rules, so the container may be accessible from the internet, but only to authenticated users

Option D is correct because the ARM template does not define any network rules (such as a virtual network rule or IP firewall rule) for the storage account, so the storage endpoint remains reachable from the internet; however, since public blob access is not enabled, anonymous access is denied and only authenticated requests with valid credentials or SAS tokens can succeed. This means the container is not publicly accessible in the anonymous sense, but the lack of network restrictions still exposes the endpoint to authenticated access from any network. Option A is wrong because nothing in the template enables anonymous public access to the container. Option B is wrong because versioning is a data-protection feature, not a public-access control, and it is not the security implication being asked about. Option C is wrong because encryption at rest is enabled by default for Azure Storage and is unrelated to whether the container is publicly reachable.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The container allows public access

    Why it's wrong here

    The template explicitly sets publicAccess to None on the container, which disables anonymous read/write access. This means the container does not allow public access in the sense of unauthenticated requests. However, the option is incorrect because it ignores the fact that authenticated users can still access the container from the internet if no network rules are configured.

  • ✗

    The template creates a container with versioning enabled

    Why it's wrong here

    The template does not include a versioning property on the storage account or container, so blob versioning is not enabled by this deployment. Versioning is a separate data management feature that preserves snapshots of blobs, and it is unrelated to the security posture being reviewed. Therefore, the claim that the template enables versioning is factually incorrect.

  • ✗

    The template enables encryption at rest

    Why it's wrong here

    The template does not configure any encryption settings, such as encryption key source or infrastructure encryption. While Azure Storage automatically encrypts data at rest using Microsoft-managed keys by default, this template does not explicitly enable or modify encryption. Thus, saying the template enables encryption at rest is misleading and not a valid observation from the ARM template.

  • ✓

    The template does not configure network rules, so the container may be accessible from the internet, but only to authenticated users

    Why this is correct

    The template does not define any network access restrictions, such as virtual network rules, IP rules, or a default action of Deny. As a result, the storage account is reachable from the internet, but because the container's publicAccess is set to None, only authenticated requests (using account keys, SAS, or Microsoft Entra) are accepted. This is a distinct security concern: the storage endpoint is publicly exposed, even though data access requires authentication.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.