Courseiva

SC-100 Design security solutions for infrastructure Practice Question

Exhibit

Refer to the exhibit.

{
  "properties": {
    "policyRule": {
      "if": {
        "field": "type",
        "equals": "Microsoft.Compute/virtualMachines"
      },
      "then": {
        "effect": "modify",
        "details": {
          "roleDefinitionIds": [
            "/providers/Microsoft.Authorization/roleDefinitions/b24988ac-6180-42a0-ab88-20f7382dd24c"
          ],
          "operations": [
            {
              "operation": "addOrReplace",
              "field": "Microsoft.Compute/virtualMachines/storageProfile.osDisk.managedDisk.diskEncryptionSet.id",
              "value": "/subscriptions/12345/resourceGroups/rg-keys/providers/Microsoft.Compute/diskEncryptionSets/des-production"
            }
          ]
        }
      }
    }
  }
}

Refer to the exhibit. You are reviewing an Azure Policy definition that is assigned to a subscription. What is the primary effect of this policy?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It modifies the OS disk to use a specific disk encryption set.

The policy uses the 'modify' effect to add or replace the disk encryption set ID on any virtual machine's OS disk managed disk. This ensures VMs use a specific encryption set. 'deployIfNotExists' would deploy a resource, 'audit' would only log, 'deny' would block creation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    It modifies the OS disk to use a specific disk encryption set.

    Why this is correct

    This statement is correct. The policy definition uses the 'modify' effect, which updates an existing resource in place. Specifically, it sets the `diskEncryptionSet.id` property on the OS disk to the customer-managed key encryption set identifier specified in the policy parameters. This action, performed during evaluation or via a remediation task, applies encryption to the OS disk without creating a new disk or deploying any additional resources.

  • ✗

    It deploys a disk encryption set to each virtual machine.

    Why it's wrong here

    Incorrect. A disk encryption set (DES) is a separate Azure resource that must be created beforehand and referenced by its resource ID; Azure Policy's 'modify' effect only alters properties of an existing resource and cannot provision new resources like a DES. The policy only assigns the DES identifier to the OS disk's `diskEncryptionSet.id` field, making the VM use the already-existing DES. If deployment of a DES were intended, the effect would be 'deployIfNotExists' with a 'request' to create the resource, not 'modify'.

  • ✗

    It denies creation of virtual machines without the specified disk encryption set.

    Why it's wrong here

    Incorrect. The 'deny' effect blocks creation of non-compliant resources entirely, but this policy uses the 'modify' effect, which allows the VM to be created and then automatically corrects the non-compliant OS disk by setting the `diskEncryptionSet.id` property. Deny would prevent the deployment and require manual reconfiguration, whereas 'modify' is a remediation effect that brings the resource into compliance after the fact. The policy definition shows `effect: modify`, not `deny`.

  • ✗

    It audits virtual machines that do not use the specified disk encryption set.

    Why it's wrong here

    Incorrect. The 'audit' effect only generates a compliance log entry when a VM does not use the specified disk encryption set, without making any changes. In contrast, the policy under review uses the 'modify' effect, which proactively updates the OS disk's `diskEncryptionSet.id` property to the specified DES, actually enforcing the encryption requirement. Audit acts as a read-only checker; 'modify' actively remediates, as shown by the `effect: modify` in the definition.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.