Courseiva

SC-100 Practice Question: Design security solutions for applications and data

Your organization is using Microsoft Defender for Cloud to secure applications running on Azure. You need to ensure that all Azure Storage accounts have secure transfer required enabled. What is the BEST way to enforce this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign an Azure Policy initiative that includes the built-in policy 'Secure transfer to storage accounts should be enabled' with a 'Deny' effect.

The best way to enforce that all Azure Storage accounts have secure transfer required enabled is to assign an Azure Policy initiative that includes the built-in policy 'Secure transfer to storage accounts should be enabled' with a 'Deny' effect (option C). Azure Policy is the native governance service that evaluates resource properties and can block non-compliant deployments, so a Deny effect prevents creation or modification of storage accounts that do not have secure transfer required enabled. A custom recommendation in Defender for Cloud (option A) only provides visibility and alerts; it does not enforce the setting. Azure Blueprints (option B) can orchestrate policy assignments but is not itself the enforcement mechanism, and it is being deprecated in favor of template specs and deployment stacks. Granting the Storage Account Contributor role (option D) relies on manual action and does not guarantee enforcement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a custom recommendation in Microsoft Defender for Cloud to alert when storage accounts do not have secure transfer required.

    Why it's wrong here

    Defender for Cloud recommendations—including custom ones—are detective controls that evaluate resources against known baselines and surface non-compliance as alerts or secure-score findings, but they do not prevent a non-compliant resource from being created. Building a custom recommendation requires writing a KQL query and integrating it into the compliance dashboard, yet it still lacks a Deny effect and cannot enforce configuration changes at provisioning time. Without pairing it with Azure Policy, a storage account missing secure transfer can still be deployed, leaving the environment exposed until manual remediation occurs.

  • ✗

    Use Azure Blueprints to apply the setting to all subscriptions.

    Why it's wrong here

    Azure Blueprints has been deprecated by Microsoft and is being retired; it is no longer the recommended tool for governance, and using it now would be an architectural dead-end. Even when Blueprints was active, it could only assign policies and role-based access control artifacts—it did not directly modify resource properties like 'Secure transfer required' on a storage account. Blueprints applied artifacts only at assignment time, offering no continuous enforcement or compliance drift detection, which Azure Policy provides. For modern infrastructure-as-code governance, Azure Policy and Deployment Stacks are the replacements, so this option is incorrect.

  • ✓

    Assign an Azure Policy initiative that includes the built-in policy 'Secure transfer to storage accounts should be enabled' with a 'Deny' effect.

    Why this is correct

    Assigning an Azure Policy initiative that contains the built-in policy 'Secure transfer to storage accounts should be enabled' with a Deny effect is the correct preventive control. Azure Policy evaluates resource creation and update requests during the ARM API call, and the Deny effect rejects any storage account that does not have the 'Secure transfer required' property set to true, returning an error before the resource is provisioned. This ensures non-compliant storage accounts are never created, and assigning it at a management group or subscription scale provides consistent enforcement across the entire environment. An initiative bundles together multiple policies, enabling comprehensive compliance with frameworks like the Azure Security Benchmark while the Deny effect specifically blocks insecure configurations.

  • ✗

    Grant the 'Storage Account Contributor' role to a security group that will manually enable the setting.

    Why it's wrong here

    Granting the 'Storage Account Contributor' role to a security group is an identity and access management (IAM) action, not a configuration enforcement mechanism. It simply authorizes the group to manage storage accounts, but relies on human operators to remember to enable secure transfer, which introduces the risk of human error and configuration drift. This approach is manual, unscalable across many subscriptions, and provides no continuous compliance monitoring or automated blocking of non-compliant resources. Additionally, it grants broad management permissions that expand the attack surface, making it both an ineffective and overly permissive solution to the stated requirement.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.