nerdexam
Microsoft

AZ-104 · Question #831

Hotspot Question You have an Azure subscription named Sub1 that contains the resources shown in the following table. The subscription contains the users shown in the following table. VNet2 was…

The correct answer is Admin1 can modify the IP address space of VNet2. = Yes; Admin2 can delete Subnet2. = Yes; Admin3 can delete VNet2. = No. Admin1 is the subscription Owner (or has the Owner role at subscription level), giving them full control over all resources including modifying VNet2's IP address space. Admin2 has the Network Contributor role on VNet1's resource group or at a scope that includes Subnet2…

Submitted by javi_es· Mar 4, 2026Manage Azure identities and governance - specifically managing role-based access control (RBAC) assignments and understanding the permissions granted by built-in roles such as Owner, Network Contributor, and Reader on Azure resources and resource groups.

Question

Hotspot Question You have an Azure subscription named Sub1 that contains the resources shown in the following table. The subscription contains the users shown in the following table. VNet2 was created by using the following cmdlet. For VNet2, Access control (IAM) settings are configured as shown in the following exhibit. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Answer:

Exhibits

AZ-104 question #831 exhibit 1
AZ-104 question #831 exhibit 2
AZ-104 question #831 exhibit 3
AZ-104 question #831 exhibit 4

Answer Area

  • Admin1 can modify the IP address space of VNet2.Yes
  • Admin2 can delete Subnet2.Yes
  • Admin3 can delete VNet2.No

Explanation

Admin1 is the subscription Owner (or has the Owner role at subscription level), giving them full control over all resources including modifying VNet2's IP address space. Admin2 has the Network Contributor role on VNet1's resource group or at a scope that includes Subnet2, granting them permissions to delete subnets within virtual networks. Admin3 has only the Reader role on VNet2 (as configured in the IAM exhibit), which is a read-only role that does not permit deletions or modifications - therefore Admin3 cannot delete VNet2.

Topics

#Azure RBAC#Virtual Network#Role Assignments#Azure IAM

Community Discussion

No community discussion yet for this question.

Full AZ-104 Practice