Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

Exhibit

Refer to the exhibit.

```json
{
  "type": "Microsoft.Storage/storageAccounts/blobServices/containers",
  "apiVersion": "2021-04-01",
  "name": "[parameters('storageAccountName')]/default/[parameters('containerName')]",
  "properties": {
    "publicAccess": "None"
  }
}
```

Refer to the exhibit. You are reviewing an ARM template snippet for an Azure Storage container. Which security best practice does this configuration enforce?

⚠ Common exam trap

Candidates often confuse the container-level `publicAccess` property with storage account-level firewall rules or encryption settings, leading them to select options that describe unrelated security features.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disables anonymous public access to the container

The ARM template snippet sets the `publicAccess` property of the container to `None`. This explicitly disables anonymous public access to the container, enforcing the security best practice of preventing unauthenticated access to Azure Storage data. By default, Azure Storage containers allow anonymous read access if enabled at the account level, but this configuration overrides that to block any public requests.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Disables anonymous public access to the container

    Why this is correct

    In an ARM template for Azure Storage, the `publicAccess` property of a container is set to 'None', which explicitly blocks any anonymous read requests to the blob data within that container. This configuration ensures that clients must present valid authentication credentials—such as an account key, a shared access signature (SAS), or an Microsoft Entra ID identity—to access the container's contents. Setting `publicAccess` to 'None' is a critical security control that prevents unauthorized exposure of stored data.

  • ✗

    Allows public access from the internet

    Why it's wrong here

    The container's `publicAccess` property is set to 'None', meaning the container is not open to anonymous internet access. Without this setting, a request to a blob URL without authentication would receive a 403 (AuthorizationFailure) response rather than the blob content. Therefore, the ARM template is not allowing public access from the internet; it is doing the opposite by enforcing a private access model for the container.

  • ✗

    Configures a firewall rule to restrict access to specific IPs

    Why it's wrong here

    Firewall rules in Azure Storage are configured at the storage account level using the `networkAcls` property, which contains `ipRules` and `defaultAction`, not at the container level. The ARM template snippet does not include any such network ACL or IP rule definitions, so it cannot be restricting access by IP address. The only access-related setting in the snippet is the container's `publicAccess` property, which controls anonymous access, not network-level filtering.

  • ✗

    Enables encryption at rest for the container

    Why it's wrong here

    Encryption at rest is enabled at the storage account level using Azure Storage Service Encryption, typically via the `encryption` property on the storage account resource, not per container. The snippet only shows a container resource with `publicAccess` set to 'None'; there is no `encryption` or `encryptionScope` element present. Therefore, this ARM template cannot be configuring or enabling encryption at rest for the container—it is solely managing public access permission.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.