Valid AZ-104 Dumps shared by ExamDiscuss.com for Helping Passing AZ-104 Exam! ExamDiscuss.com now offer the newest AZ-104 exam dumps, the ExamDiscuss.com AZ-104 exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com AZ-104 dumps with Test Engine here:
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an Azure subscription that contains 10 virtual networks. The virtual networks are hosted in separate resource groups. Another administrator plans to create several network security groups (NSGs) in the subscription. You need to ensure that when an NSG is created, it automatically blocks TCP port 8080 between the virtual networks. Solution: You assign a built-in policy definition to the subscription. Does this meet the goal?
Correct Answer: B
Resource policy definition used by Azure Policy enables you to establish conventions for resources in your organization by describing when the policy is enforced and what effect to take. By defining conventions, you can control costs and more easily manage your resources. Reference: https://docs.microsoft.com/en-us/azure/azure-policy/policy-definition
Recent Comments (The most recent comments are at the top.)
Sam - Feb 02, 2024
Question says built in def which may not be correct. it has to be cutom policy def
Sam - Feb 02, 2024
Use a custom policy definition.
The solution provided in the scenario may or may not meet the goal, depending on the policy definition assigned to the subscription.
Assigning a policy definition to the subscription means that the policy will apply to all resources within that subscription, including the virtual networks and network security groups. Therefore, if a policy definition exists that blocks TCP port 8080 between virtual networks, assigning it to the subscription would ensure that the policy is enforced whenever an NSG is created.
However, if there is no such policy definition that blocks TCP port 8080 between virtual networks, or if the policy definition does not cover NSGs, then assigning a policy definition to the subscription would not meet the goal of automatically blocking TCP port 8080 between virtual networks when an NSG is created.
Therefore, the answer to the question is B. No, the solution provided does not necessarily meet the goal. More information is needed about the specific policy definition being assigned to the subscription to determine if it will meet the goal....
Sam - Feb 02, 2024
Correct Answer: A - Yes
You need to use a custom policy definition, because there is not a built-in policy.
Resource policy definition used by Azure Policy enables you to establish conventions for resources in your organization by describing when the policy is enforced and what effect to take. By defining conventions, you can control costs and more easily manage your resources.
Recent Comments (The most recent comments are at the top.)
Question says built in def which may not be correct. it has to be cutom policy def
Use a custom policy definition.
The solution provided in the scenario may or may not meet the goal, depending on the policy definition assigned to the subscription.
Assigning a policy definition to the subscription means that the policy will apply to all resources within that subscription, including the virtual networks and network security groups. Therefore, if a policy definition exists that blocks TCP port 8080 between virtual networks, assigning it to the subscription would ensure that the policy is enforced whenever an NSG is created.
However, if there is no such policy definition that blocks TCP port 8080 between virtual networks, or if the policy definition does not cover NSGs, then assigning a policy definition to the subscription would not meet the goal of automatically blocking TCP port 8080 between virtual networks when an NSG is created.
Therefore, the answer to the question is B. No, the solution provided does not necessarily meet the goal. More information is needed about the specific policy definition being assigned to the subscription to determine if it will meet the goal....
Correct Answer: A - Yes
You need to use a custom policy definition, because there is not a built-in policy.
Resource policy definition used by Azure Policy enables you to establish conventions for resources in your organization by describing when the policy is enforced and what effect to take. By defining conventions, you can control costs and more easily manage your resources.
Reference:
https://docs.microsoft.com/en-us/azure/azure-policy/policy-definition
https://docs.microsoft.com/en-us/azure/governance/policy/samples/built-in-policies