Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceHard
A company wants to ensure that all newly created Azure storage accounts within a specific subscription automatically have encryption at rest configured with customer-managed keys (CMK) from an Azure Key Vault. If a storage account is created without CMK, it should be flagged as non-compliant, and the deployment should be allowed to proceed. What Azure Policy effect should be used?
- AModify
- BAudit
- CDeployIfNotExists
- DDeny
Show answer & explanationAnswer & explanation
Correct answer: B. Audit
The 'Audit' effect identifies non-compliant resources without blocking their creation. In this scenario, the company wants to flag non-compliant storage accounts but allow deployment to proceed, which is precisely what 'Audit' does.
Why the other options are wrong
- A. 'Modify' would automatically update the storage account to use CMK, which goes beyond merely flagging and allowing the deployment to proceed as specified.
- C. 'DeployIfNotExists' would attempt to remediate by deploying CMK, but the requirement is to 'flag as non-compliant' while still allowing deployment, not to automatically fix it.
- D. 'Deny' would block the deployment of any storage account not configured with CMK, which contradicts the requirement to allow deployment to proceed.
Azure Policy 'Audit' Effect
An Azure Policy effect that creates a warning event in the activity log when a resource is non-compliant, without stopping the resource request.
- Identifies non-compliant resources.
- Does not block resource creation or modification.
- Useful for reporting and understanding compliance posture without enforcement.
Memory trick: Policy acts as a watchful auditor, noting non-compliance without blocking the door.