Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionHard
A compliance officer needs to ensure that all Azure Virtual Machines (VMs) deployed in a specific subscription use managed disks and are encrypted with customer-managed keys (CMK) stored in Azure Key Vault. Furthermore, any attempt to deploy a VM without CMK encryption or with unmanaged disks must be explicitly denied. Which Azure Policy effect would achieve the strict denial requirement?
- ADeny
- BDeployIfNotExists
- CModify
- DAudit
Show answer & explanationAnswer & explanation
Correct answer: A. Deny
The 'Deny' effect in Azure Policy is used to prevent the creation or update of resources that do not comply with the policy definition. This directly addresses the requirement to 'explicitly deny' deployments that do not meet the specified encryption and disk type criteria.
Why the other options are wrong
- B. The 'DeployIfNotExists' effect automatically deploys a resource or template if a compliant resource does not exist; it does not deny a non-compliant deployment.
- C. The 'Modify' effect adds or updates properties on a resource during creation or update, or on existing resources, but it does not deny the deployment itself.
- D. The 'Audit' effect only creates a warning event in the activity log for non-compliant resources; it does not prevent deployment.
Azure Policy 'Deny' Effect
The 'Deny' effect in Azure Policy prevents a resource request from succeeding if it doesn't meet the policy definition, ensuring strict compliance at creation or update.
- Prevents non-compliant resource deployments or updates.
- Returns a 403 Forbidden error.
- Used for strict governance where non-compliance is unacceptable.
- One of several effects that can be assigned to a policy definition.
Memory trick: Policies can Audit, Deny, Deploy, or Modify, but 'Deny' means 'NO'.