Microsoft Certified: Azure Security Engineer AssociateManage security operationsMedium

A security team needs to ensure that all virtual machines in a specific Azure subscription are configured with a particular Network Security Group (NSG) and that this NSG enforces a set of specific inbound and outbound rules. If a VM is deployed without the correct NSG or if the NSG rules deviate from the standard, it should be flagged as non-compliant. Which Azure Policy feature should be used to define and enforce this requirement?

  1. AAzure Policy initiative
  2. BAzure Policy definition
  3. CAzure Policy assignment
  4. DAzure Policy remediation task
Show answer & explanation

Correct answer: B. Azure Policy definition

An Azure Policy definition specifies the conditions a resource must meet and the effect if those conditions are not met. This is where the logic for the required NSG and its rules would be defined.

Why the other options are wrong

  • A. An Azure Policy initiative (or 'policyset') is a collection of policy definitions, not the definition of a single requirement itself.
  • C. An Azure Policy assignment applies a policy definition or initiative to a specific scope, but doesn't define the policy logic.
  • D. An Azure Policy remediation task is used to fix non-compliant resources identified by a policy, it does not define the policy itself.

Azure Policy Definition

An Azure Policy definition is a JSON-based rule that specifies the conditions under which a policy is enforced and the effect that takes place if those conditions are met.

  • Defines the 'what' of the policy.
  • Contains the policy rules, parameters, and effect.
  • Can be custom-created or used from built-in definitions.

Memory trick: Definition is the 'rule', initiative is the 'book of rules', assignment is 'where' to apply the book.

More Manage security operations questions