Soru

Zorluk: OrtaAzure Policy

A security compliance officer wants to identify which existing Azure Key Vaults do not have soft-delete enabled. The officer wants to view a list of non-compliant resources in a dashboard without blocking new deployments, modifying resource configurations, or restricting user access permissions. Which configuration or feature should be implemented to meet these requirements?

  1. An Azure Policy definition with the Audit effectCevap
  2. B
    An Azure Policy definition with the Deny effect
  3. C
    An Azure Role-Based Access Control (RBAC) role assignment
  4. D
    A ReadOnly resource lock applied to the subscription

Cevap

An Azure Policy definition with the Audit effect
The correct answer is the configuration of an Azure Policy definition with the Audit effect. Azure Policy is used to evaluate resources and report compliance. When the Audit effect is used, the policy generates warning events in the compliance dashboard for non-compliant resources, but it does not restrict deployment actions or modify any resource configurations.

Adım Adım Çözüm

1
Analyze the requirement to evaluate specific resource properties (Key Vault soft-delete) and report compliance without modifying configurations.
Identify that resource compliance and property evaluation are governed by Azure Policy.
Azure Policy is the primary service designed to enforce corporate standards and evaluate compliance across resources.
2
Differentiate between Azure Policy, Azure RBAC, and Resource Locks to rule out incorrect governance tools.
Determine that Azure RBAC only controls user access, and resource locks only prevent deletion or modification, making them unsuitable for compliance reporting.
This rules out RBAC and Resource Lock options as they do not assess resource configuration states.
3
Select the correct Azure Policy effect that reports non-compliance without blocking deployment activities.
The Audit effect logs compliance data without blocking actions, whereas the Deny effect blocks the deployment.
This meets the specific constraint of identifying non-compliant resources without disrupting deployments.

Anahtar Kavram

Azure Policy effects and compliance reporting
Tahmini Süre:1m 0s
Bu soruyu puanla