Courseiva

SC-100 Design security solutions for infrastructure Practice Question

Exhibit

{
  "properties": {
    "policyRule": {
      "if": {
        "field": "type",
        "equals": "Microsoft.Network/networkSecurityGroups/securityRules"
      },
      "then": {
        "effect": "deny",
        "details": {
          "field": "properties.destinationPortRange",
          "notIn": ["22", "3389"]
        }
      }
    }
  }
}

Refer to the exhibit. You are reviewing an Azure Policy definition. What does this policy accomplish?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Denies creation of network security rules that allow traffic to ports other than 22 and 3389

The correct option is D: the policy denies creation of network security rules that allow traffic to ports other than 22 and 3389. Azure Policy definitions with a deny effect evaluate the properties of a resource being deployed—here, the destinationPortRange of a network security rule—and block the deployment when the condition is met, so rules permitting any port outside 22 and 3389 are rejected. Option A is wrong because the policy does not require ports to fall within a range; it blocks rules that allow ports other than the two specified. Option B is wrong because the policy targets NSG rule definitions in Azure Resource Manager, not live inbound traffic flows. Option C is wrong because the policy does not permit or allow traffic; it only denies noncompliant rule creation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Requires that all network security rules have destination port range between 22 and 3389

    Why it's wrong here

    This option misstates the policy's condition: the definition does not require each security rule's destinationPortRange property to be a numeric interval between 22 and 3389. Azure Policy's deny effect triggers only when the rule's destination port value is not exactly '22' or '3389', so a rule using a range like '100-200' would violate the policy just as much as one using port 443. It neither validates that a range falls within 22-3389 nor permits ranges that contain those ports; it demands the destination port be one of the two listed values.

  • ✗

    Denies all inbound traffic except SSH and RDP

    Why it's wrong here

    Azure Policy with the deny effect operates at the Azure Resource Manager control plane, not the data plane, so it cannot 'deny all inbound traffic' in the network path. What actually gets denied is the creation or update of a network security rule resource whose destination port is outside the allowed list; no packet inspection, NSG flow evaluation, or traffic blocking is performed by the policy. Inbound traffic to 22/3389 will only be allowed if an existing NSG rule explicitly permits it—the policy neither enforces such a rule nor blocks traffic on its own.

  • ✗

    Allows only SSH and RDP inbound traffic

    Why it's wrong here

    This option incorrectly frames the policy as a positive allow mechanism. Azure Policy never creates or enables NSG rules; it only evaluates resource definitions against conditions and can deny noncompliant resources. Here, the policy blocks any security rule that would allow ports other than 22 and 3389, but it does not add any allow rules for SSH or RDP, nor does it affect the existing NSG rules' priority or action. Allowing traffic remains the job of NSG rules; the policy merely prevents certain future rules from being written.

  • ✓

    Denies creation of network security rules that allow traffic to ports other than 22 and 3389

    Why this is correct

    This is correct because the policy definition uses the 'deny' effect on Microsoft.Network/networkSecurityGroups/securityRules whose destinationPortRange or destinationPortRanges include values not in ['22', '3389']. When a user or service attempts to create or update an NSG rule that permits traffic to any port other than 22 or 3389, the Resource Manager deployment is rejected before the rule is applied, making it impossible to add such a rule to an NSG. The policy does not, however, automatically delete existing noncompliant rules; it applies at deployment time, so already-existing rules that violate the condition remain until manually changed or removed.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.