Microsoft Azure Security Engineer Associate AZ-500 Practice Question

Your organization plans to enforce a new Azure Policy that denies the deployment of any storage account that is not encrypted with customer-managed keys (CMK). Because many existing deployment pipelines have not yet been updated, you need a transition period during which the policy records non-compliant resources but does not block their creation. You also want to avoid changing the policy definition itself during this period.

Which configuration should you apply to the policy assignment to meet these requirements?

  • Set the policy assignment's enforcement mode to "DoNotEnforce".

  • Add a custom non-compliance message to the policy assignment.

  • Create an exemption for the subscription that expires after the transition period.

  • Add the policy to an initiative and leave the initiative in draft state.

Microsoft Azure Security Engineer Associate AZ-500
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot