Courseiva

SC-100 Design security solutions for infrastructure Practice Question

Exhibit

{
  "properties": {
    "policyRule": {
      "if": {
        "allOf": [
          {
            "field": "type",
            "equals": "Microsoft.Compute/virtualMachines"
          },
          {
            "field": "Microsoft.Compute/virtualMachines/storageProfile.osDisk.managedDisk",
            "exists": "true"
          }
        ]
      },
      "then": {
        "effect": "deny",
        "details": {
          "field": "Microsoft.Compute/virtualMachines/storageProfile.osDisk.managedDisk.storageAccountType",
          "notIn": ["Standard_LRS", "Premium_LRS"]
        }
      }
    },
    "parameters": {}
  }
}

Refer to the exhibit. You are reviewing an Azure Policy definition. What does this policy do?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Denies virtual machines with managed disks if the OS disk type is not Standard_LRS or Premium_LRS

The correct option is C: the policy denies virtual machines with managed disks when the OS disk type is not Standard_LRS or Premium_LRS. This matches a typical Azure Policy definition that evaluates the managed disk's storage account type (for example, the field Microsoft.Compute/disks sku.name) and uses a deny effect to block any value outside the allowed set of Standard_LRS and Premium_LRS. Option A is wrong because encryption at host is controlled by a different setting (encryptionAtHost) and is not what this disk-type policy enforces. Option B is wrong because the policy targets managed disks, not unmanaged disks, and it does not allow unmanaged disks. Option D is wrong because the policy does not deny all VMs without managed disks; it only denies managed-disk VMs whose OS disk SKU is not Standard_LRS or Premium_LRS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Requires all virtual machines to use encryption at host

    Why it's wrong here

    This option incorrectly identifies the policy's action. The policy under review contains no clauses referencing encryption at host; its sole focus is on the OS disk's storage SKU for managed-disks-only VMs. Encryption at host is enforced by separate policy definitions with fields such as 'encryptionAtHost' and would not be inferred from a disk-type condition. Therefore, this interpretation does not describe the policy's actual deny effect.

  • ✗

    Allows only virtual machines with unmanaged disks

    Why it's wrong here

    The policy does not restrict deployments to unmanaged disks; rather, it applies only to managed-disk VMs and checks the OS disk's storage account type against 'Standard_LRS' and 'Premium_LRS'. VMs with a managed OS disk of an allowed SKU are fully compliant and permitted, so the policy cannot be said to allow only unmanaged disks. Unmanaged-disk VMs may simply fall outside the policy's condition scope, but they are not the exclusive beneficiaries.

  • ✓

    Denies virtual machines with managed disks if the OS disk type is not Standard_LRS or Premium_LRS

    Why this is correct

    This is the accurate interpretation. The policy definition's condition evaluates the 'Microsoft.Compute/virtualMachines' resource to see if a managed OS disk exists, and if so, it further checks whether the 'storageAccountType' of that managed disk is 'Standard_LRS' or 'Premium_LRS'. When the managed disk exists and its type is not in that allowed list, the policy's 'deny' effect blocks the deployment or update operation. This directly matches the statement, making it the correct answer.

  • ✗

    Denies all virtual machines without managed disks

    Why it's wrong here

    This option incorrectly expands the policy's scope to all VMs lacking managed disks. The policy's condition is specifically designed to trigger only when a managed disk is present; if no 'managedDisk' field exists under the OS disk profile, the subsequent storage-account-type comparison is not evaluated. Consequently, VMs using unmanaged disks are not denied by this policy, so this broad statement misrepresents both the condition and the effect.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.