SC-100 Practice Question: Design security solutions for applications and data
Exhibit
Refer to the exhibit.
{
"type": "Microsoft.Storage/storageAccounts/blobServices/containers",
"apiVersion": "2021-09-01",
"properties": {
"publicAccess": "None",
"immutabilityPolicy": {
"immutabilityPeriodSinceCreationInDays": 30,
"state": "Locked"
},
"defaultEncryptionScope": "$account-encryption-key",
"denyEncryptionScopeOverride": true
}
}You are reviewing the ARM template snippet for an Azure Storage container. What does the 'denyEncryptionScopeOverride' property set to 'true' ensure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Users cannot override the default encryption scope for blobs in this container.
Option D is correct because setting denyEncryptionScopeOverride to true on a container prevents clients from specifying a different encryption scope when uploading blobs, forcing them to use the container's default encryption scope. This property is specifically about locking the encryption scope at the container level, not about enabling or requiring encryption itself. Option A is wrong because double encryption is configured via infrastructure encryption settings, not this property. Option B is wrong because encryption at rest is always enabled for Azure Storage blobs by default and is not controlled by denyEncryptionScopeOverride. Option C is wrong because customer-managed keys are configured through the account's encryption key source settings, not through this container property.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Double encryption is enabled for the container.
Why it's wrong here
Setting `denyEncryptionScopeOverride` on a container does not enable double encryption. Double encryption, also known as infrastructure encryption, is a storage account-level setting (`requireInfrastructureEncryption`) that adds an extra layer of encryption at the hardware tier. The container property only governs which encryption scope can be used for blob writes, so it is entirely separate from the account-wide infrastructure encryption feature.
- ✗
Encryption at rest is required for all blobs in the container.
Why it's wrong here
Encryption at rest for Azure Storage is always enabled by default for every account and every blob, regardless of this ARM template property. The setting in question does not 'require' encryption at rest, because that encryption is already a non-optional platform guarantee. Rather, the property controls whether clients can override the default encryption scope, which is a different, configurable aspect of data encryption.
- ✗
The container automatically uses a customer-managed key for encryption.
Why it's wrong here
This container property does not automatically select a customer-managed key. The default encryption scope for the container might be configured with either a Microsoft-managed key or a customer-managed key, and the `denyEncryptionScopeOverride` property only enforces that all blobs use that existing default scope. Key type is determined by the encryption scope definition, not by this boolean flag.
- ✓
Users cannot override the default encryption scope for blobs in this container.
Why this is correct
Setting `denyEncryptionScopeOverride` to `true` on a container blocks any client from supplying an encryption scope different from the container's default scope on a per-blob request. As a result, every blob uploaded to this container is encrypted exactly with the default encryption scope, which administrators centrally define and manage. This is essential for compliance scenarios where data must always be encrypted with an approved key or key management policy.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.