Courseiva

SC-100 Practice Question: Design security solutions for applications and data

Exhibit

{
  "properties": {
    "displayName": "Policy to restrict storage account access",
    "policyType": "Custom",
    "mode": "All",
    "parameters": {
      "effect": {
        "type": "String",
        "allowedValues": [
          "Deny",
          "Audit",
          "Disabled"
        ],
        "defaultValue": "Deny"
      }
    },
    "policyRule": {
      "if": {
        "allOf": [
          {
            "field": "type",
            "equals": "Microsoft.Storage/storageAccounts"
          },
          {
            "field": "Microsoft.Storage/storageAccounts/networkAcls.defaultAction",
            "notEquals": "Deny"
          }
        ]
      },
      "then": {
        "effect": "[parameters('effect')]"
      }
    }
  }
}

Refer to the exhibit. You are evaluating a custom Azure Policy definition for storage accounts. The policy is assigned with effect set to 'Deny'. An administrator attempts to create a new storage account with network rules configured to allow all traffic (defaultAction set to Allow). What will happen?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The storage account creation is denied.

The correct answer is A: the storage account creation is denied. Because the Azure Policy definition is assigned with the effect set to 'Deny', Azure Policy evaluates the resource request before deployment and blocks any storage account whose network rules use defaultAction set to Allow, so the create operation fails with a policy violation. Deny is a preventive enforcement effect, not a remediation or audit effect, so it stops the request rather than modifying the resource. Option B is wrong because Azure Policy does not automatically rewrite network rules to deny all traffic, and option C is wrong because audit events are produced by the Audit effect, not Deny. Option D is wrong because Deny actively blocks the noncompliant creation instead of allowing it with no action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The storage account creation is denied.

    Why this is correct

    The Azure Policy definition uses a condition that checks the storage account's networkAcls.defaultAction property, and because the effect is set to 'Deny', the resource provider rejects the create request before any storage account is provisioned. The deployment fails with a policy violation error, and no resource is created.

  • ✗

    The storage account is created, and the network rules are automatically changed to deny all traffic.

    Why it's wrong here

    The 'Deny' effect in Azure Policy does not support remediation or post-creation modification like 'DeployIfNotExists' or 'Modify'. Since the storage account creation is blocked at the Azure Resource Manager layer, there is no existing resource for Azure Policy to alter, so the network rules cannot be changed.

  • ✗

    The storage account is created, and an audit event is generated.

    Why it's wrong here

    An 'Audit' effect would allow the storage account to be created and then log a compliance event, but this policy uses 'Deny', which prevents the create call from succeeding. A denied deployment does not generate an audit event for the resource because the resource never exists; instead, the deployment fails with a policy compliance error.

  • ✗

    The storage account is created successfully, and no action is taken.

    Why it's wrong here

    Azure Policy is enforced synchronously during resource deployment, not asynchronously or as a background check. The condition (defaultAction not equal to 'Deny') is evaluated as part of the PUT request, and the Deny effect forces the create operation to fail, so the storage account cannot be created successfully under any circumstances.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.