exam questions

Exam SC-100 All Questions

View all questions & answers for the SC-100 exam

Exam SC-100 topic 2 question 1 discussion

Actual exam question from Microsoft's SC-100
Question #: 1
Topic #: 2
[All SC-100 Questions]

You are evaluating an Azure environment for compliance.
You need to design an Azure Policy implementation that can be used to evaluate compliance without changing any resources.
Which effect should you use in Azure Policy?

  • A. Deny
  • B. Modify
  • C. Append
  • D. Disabled
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
[Removed]
Highly Voted 2 years, 4 months ago
The question is misleadingly worded. The question asks which effect can be used to report on compliance without changing anything. The Azure Policy "effect" used to do this is "Audit", which is not one of the provided options. There isn't an "effect" setting in the choices that matches the criteria. However, "Disabled" and "Enabled" are the two Azure Policy "enforcement" setting options. If an Azure Policy's "enforcement" is set to "Disabled", any "effect" set on this Azure Policy will report but will not make changes. "Disabled" is the best answer available, although technically incorrect because "Disabled" isn't an Azure Policy "effect".
upvoted 28 times
AWSPro24
3 months, 1 week ago
This is the correct answer. If you set enforcementMode to disabled resources are still evaluated but log activity isn't created. audit works as well. https://learn.microsoft.com/en-us/azure/governance/policy/concepts/effect-disabled
upvoted 1 times
...
Fal991l
2 years, 1 month ago
I am on your side
upvoted 2 times
...
epomatti
1 year, 2 months ago
1. You're confused between "effect" and an "enforcement mode". 2. Policy definitions that use the Disabled effect have the default compliance state Compliant after assignment. The only possible answer is A - Deny.
upvoted 3 times
...
Joanale
1 year, 3 months ago
100% correct, please guys report this question if still no see the option "audit".
upvoted 1 times
...
...
Gar23
Highly Voted 2 years, 7 months ago
Selected Answer: D
It has to be disabled since deny will send the compliance report as non-complaint.
upvoted 27 times
BlackZeros
1 year, 9 months ago
https://learn.microsoft.com/en-us/azure/governance/policy/concepts/effects#deny-evaluation
upvoted 2 times
...
...
sweetykaur
Most Recent 2 months, 2 weeks ago
Selected Answer: D
The correct effect to use in Azure Policy for evaluating compliance without changing any resources is D. Disabled. When a policy is set to the "Disabled" effect, it will not enforce any changes but can still be used to evaluate and report on the compliance state of the resources. This allows you to monitor compliance without making any modifications to the resources.
upvoted 1 times
...
Dan91
6 months ago
Selected Answer: A
A: Deny makes the most sense. The questions states you need to evaluate compliance. D: Disabled has a default compliance state of "compliant". From an auditing perspective this wouldn't make sense.
upvoted 4 times
...
Brainrot
6 months, 1 week ago
Key word without changing resources. I think it has to be Append because of this. append effect in Azure Policy can be used to evaluate compliance. When a policy definition using the append, effect is evaluated, it doesn’t modify existing resources. Instead, it marks any resource that meets the specified conditions as non-compliant. This allows you to identify resources that do not meet your policy requirements without making immediate changes to them.
upvoted 1 times
...
ariania
7 months, 2 weeks ago
Deny marks resources as non-compliant during evaluation but does not make changes to existing resources. It enforces compliance by preventing the creation or modification of non-compliant resources but can be used for evaluation purposes as well, without altering existing resources. Modify changes the resource, so it's not applicable when you don't want to make any changes. Append adds fields to the resource during creation or update, but its main function is to enforce certain configurations, and it's not solely for compliance evaluation. Disabled doesn't evaluate compliance at all and marks everything as compliant by default, which doesn't fulfill the goal of evaluating compliance. Thus, Deny is the best option for evaluating compliance without modifying any resource
upvoted 1 times
ariania
7 months, 2 weeks ago
Disabled (effect): Completely stops policy evaluation and marks everything as compliant. enforcementMode (assignment setting): Keeps the policy evaluating compliance but doesn’t enforce any action, logging, or modification to resources. To go back to your original question, the Disabled effect would mark everything as compliant and wouldn’t evaluate compliance at all. The enforcementMode (disabled) is a different setting entirely, used to evaluate compliance without enforcement, which seems closer to what you're looking for in some situations but isn't one of the options in your question. Since enforcementMode isn't an effect, in the context of your question, A. Deny remains the correct answer, as it evaluates compliance and marks non-compliant resources without changing existing ones.
upvoted 2 times
...
...
oreoale
1 year ago
Answer is D - https://learn.microsoft.com/en-us/azure/governance/policy/concepts/effects#disabled
upvoted 1 times
...
kazaki
1 year, 1 month ago
It is not disabled it isn’t deny it is audit
upvoted 2 times
...
PierreTang
1 year, 2 months ago
Selected Answer: A
Deny. "During evaluation of existing resources, resources that match a deny policy definition are marked as non-compliant." https://learn.microsoft.com/en-us/azure/governance/policy/concepts/effects#deny-evaluation
upvoted 1 times
...
cris_exam
1 year, 2 months ago
Selected Answer: A
The key words from this question are "evaluating compliance". This can be done with DENY, because it doesn't allow any resource change but blocks it before happening with a 403 error and logs the block for a later review to see the non-compliant activity. https://learn.microsoft.com/en-us/azure/governance/policy/concepts/effects#deny-evaluation MS words it like below, fulfilling the requirements of the given question while checking if an Azure environment IS or NOT compliant. "During evaluation of existing resources, resources that match a deny policy definition are marked as non-compliant."
upvoted 2 times
...
epomatti
1 year, 2 months ago
Selected Answer: A
You guys are hallucinating. The question clearly asks which EFFECT (not an enforcement mode) should be used to evaluate resources without changing them. The only option available is DENY. The effect "Disabled" will always show as compliant: https://learn.microsoft.com/en-us/azure/governance/policy/concepts/effects#disabled The questions is NOT asking for enforcement mode: "Policy definitions that use the Disabled effect have the default compliance state Compliant after assignment." https://learn.microsoft.com/en-us/azure/governance/policy/concepts/assignment-structure#enforcement-mode
upvoted 2 times
...
Arockia
1 year, 3 months ago
"Disabled" effect ensures that the policy is applied for evaluation purposes but does not enforce any specific actions or modifications on the resources themselves. This allows you to gather compliance data and assess the configuration of resources in your Azure environment without impacting their current state.
upvoted 2 times
...
UberTech_1888
1 year, 9 months ago
Keyword = "Evaluating"
upvoted 1 times
...
Ario
1 year, 9 months ago
D is Correct , Using the "Disabled" effect in Azure Policy is particularly useful for scenarios where you want to assess compliance and gather information without making any immediate changes or disruptions to the resources
upvoted 1 times
...
zellck
1 year, 11 months ago
Selected Answer: D
D is the answer. https://learn.microsoft.com/en-us/azure/governance/policy/concepts/effects#disabled This effect is useful for testing situations or for when the policy definition has parameterized the effect. This flexibility makes it possible to disable a single assignment instead of disabling all of that policy's assignments.
upvoted 1 times
NinjaSchoolProfessor
1 year, 9 months ago
D as you stated is correct. What the question is missing is a reference to the enforcement mode. You can use the enforcement mode Disabled (DoNotEnforce) on your policy assignment to prevent the effect from triggering or activity log entries from being created. This step gives you a chance to evaluate the compliance results of the new policy on existing resources without impacting work flow. https://learn.microsoft.com/en-us/azure/governance/policy/concepts/evaluate-impact#audit-existing-resources
upvoted 1 times
...
...
alifrancos
2 years ago
Selected Answer: D
the Deny effect, prevent ressources from creation if that not match the policy, but if it match it will be created or modified, i think that'is clear
upvoted 1 times
...
Fal991l
2 years, 1 month ago
Selected Answer: A
ChatGPT: If you have to choose only one between Disabled and Deny, and the question does not provide any further details or constraints, then the best answer would be Deny. The Deny effect is a more appropriate and specific choice for evaluating compliance without changing any resources in an Azure environment, as it explicitly blocks non-compliant resources from being created or modified while not modifying any existing resources. This can help ensure that the environment remains in compliance and does not drift away from the desired state.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago