SC-100 Practice Question: Design security solutions for applications and data
Exhibit
{
"type": "Microsoft.Authorization/policyAssignments",
"apiVersion": "2022-06-01",
"name": "audit-sql-encryption",
"properties": {
"policyDefinitionId": "/providers/Microsoft.Authorization/policyDefinitions/94f9d178-d4e6-4a96-bc6d-1234567890ab",
"parameters": {},
"scope": "/subscriptions/12345678-1234-1234-1234-123456789012/resourceGroups/prod-rg",
"enforcementMode": "Default"
}
}Refer to the exhibit. You are auditing an Azure subscription. The Azure Policy assignment above is targeting a resource group. The policy definition ID corresponds to a built-in policy that audits if SQL databases have transparent data encryption (TDE) enabled. What is the effect of this policy assignment?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy audits SQL databases for TDE and marks non-compliant resources.
Option D is correct because the built-in policy definition audits whether SQL databases have transparent data encryption (TDE) enabled, and an audit-effect policy evaluates resources and flags non-compliant ones in the compliance report without blocking or modifying them. Since the assignment targets a resource group, it evaluates the SQL databases within that scope and marks those lacking TDE as non-compliant. Option A is wrong because audit policies do not remediate or enable TDE; that would require a DeployIfNotExists or Modify effect. Option B is incorrect because 'audit' is the effect, not merely a reporting mode, and the policy still evaluates and flags resources. Option C is wrong because the assignment targets a resource group, not a management group, so its scope is limited to that resource group.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The policy automatically enables TDE on non-compliant SQL databases.
Why it's wrong here
This is incorrect because Azure Policy effects are not capable of performing resource modification unless explicitly defined as a DeployIfNotExists or Modify effect with a remediation task. The 'audit' effect only evaluates the resource properties against the policy rule and reports compliance results; it does not automatically enable Transparent Data Encryption (TDE) on a non-compliant SQL database. No write operations are performed by auditing—the resource remains unchanged, and any remediation requires a separate, manually triggered remediation action or a different policy effect.
- ✗
The policy is only reported as audit, not enforced.
Why it's wrong here
This statement is misleading because the 'audit' effect is still an enforced policy action in Azure Policy—it actively evaluates resources and generates compliance results. EnforcementMode is set to Default, meaning the policy is applied normally to all resources within the assignment scope, and audit results are recorded and reported. The term 'enforced' does not necessarily mean 'action is taken to change the resource'; it means the policy rule is actively applied and compliance is continuously evaluated. Thus, saying it is 'only reported as audit, not enforced' incorrectly conflates enforcement with remediation.
- ✗
The policy applies to all resources in the management group.
Why it's wrong here
This is wrong because the policy assignment's scope is explicitly a specific resource group, not a management group. The exhibit (not fully shown in text, but referenced) clearly indicates the scope field is set to a single resource group. Azure Policy assignments are always scoped to a management group, subscription, or resource group, and in this case the scope is limited to a particular resource group. Therefore, the policy does not apply to all resources in any management group—it only applies to resources (including SQL databases) contained within that assigned resource group.
- ✓
The policy audits SQL databases for TDE and marks non-compliant resources.
Why this is correct
This is correct. The Azure Policy assignment uses the 'audit' effect to evaluate whether SQL databases have Transparent Data Encryption (TDE) enabled. If a database does not have TDE enabled, the policy marks that resource as non-compliant in the Azure Policy compliance dashboard and potentially integrates with Azure Monitor for alerts and reports. The 'audit' effect only evaluates and reports—it does not automatically remediate the non-compliant database, but it does accomplish the goal of identifying and flagging resources that fail to meet the intent of the policy. This matches the behavior shown in the exhibit where the policy is configured with an audit effect and assigned to a resource group.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.