Soru

Zorluk: OrtaAzure Policy

A company implements a governance rule requiring that all virtual machines in an Azure subscription must use a specific size SKU. Ten virtual machines of different sizes are already running in the subscription when a new Azure Policy is assigned with a Deny effect for non-allowed sizes. What is the state of the ten existing virtual machines after the policy is applied?

  1. A
    They are automatically shut down to prevent non-compliant resource utilization.
  2. B
    They are automatically resized to the allowed size SKU by Azure Policy.
  3. They continue to run without interruption but are flagged as non-compliant in the compliance dashboard.Cevap
  4. D
    They are excluded from the policy evaluation, and the users who created them have their Azure Role-Based Access Control (RBAC) roles modified to prevent further edits.

Cevap

They continue to run without interruption but are flagged as non-compliant in the compliance dashboard.
When a new Azure Policy is assigned, existing resources are evaluated during compliance scans. If they do not match the policy criteria, they are flagged as non-compliant in the dashboard, but they continue to run without interruption. The Deny effect only blocks the creation of new non-compliant resources or updates to existing resources that would make them non-compliant.

Adım Adım Çözüm

1
Analyze the state of resources prior to policy assignment.
Ten virtual machines with non-compliant sizes are already running in the subscription.
Understanding the starting state helps determine how the policy interacts with active resources.
2
Determine the effect of assigning a new Azure Policy with a Deny effect on existing resources.
The Deny effect prevents new non-compliant resources from being created or updated, but does not retroactively modify or block existing resources.
Azure Policy evaluations only block operations at the time of request (resource creation or update) and do not alter running resources.
3
Identify the compliance reporting behavior for existing non-compliant resources.
Existing resources that violate the policy rules are evaluated during the policy compliance scan and flagged as non-compliant.
This provides administrators with visibility into governance gaps without causing service disruptions.

Anahtar Kavram

Azure Policy evaluation of existing resources
Tahmini Süre:1m 0s
Bu soruyu puanla