AZ-500 · Question #279
Case Study 2 - Contoso, Ltd Overview Contoso, Ltd. is a consulting company that has a main office in Montreal and two branch offices in Seattle and New York. The company hosts its entire server…
This hotspot question tests knowledge of Azure role assignments, locks, policies, and PIM configurations within Contoso's dual-subscription Azure environment. Candidates must evaluate specific statements about resource management capabilities and determine whether each is…
Question
Exhibit
Answer Area
- Virtual networks that User9 can modify:VNET4 onlyVNET4 and VNET1 onlyVNET4, VNET3, and VNET1 onlyVNET4, VNET3, VNET2, and VNET1
- Virtual networks that User9 can delete:VNET4 onlyVNET4 and VNET1 onlyVNET4, VNET3, and VNET1 onlyVNET4, VNET3, VNET2, and VNET1
Explanation
This hotspot question tests knowledge of Azure role assignments, locks, policies, and PIM configurations within Contoso's dual-subscription Azure environment. Candidates must evaluate specific statements about resource management capabilities and determine whether each is correct (Yes) or incorrect (No) based on the given environment details.
Approach. To answer correctly, candidates must cross-reference the existing environment details - including user roles, resource group locks (ReadOnly vs. Delete), Azure Policy assignments (allowed/denied actions), and PIM eligibility - against each statement being evaluated. For example, a ReadOnly lock prevents creation or deletion of resources even for Owners, while a Delete lock only prevents deletion. Azure Policy denying a resource type overrides any RBAC permissions, making it impossible to deploy that resource regardless of role. PIM requires eligible assignments to be activated before they grant access, so users with eligible (not active) roles cannot perform privileged actions until activation.
Concept tested. Azure governance controls including RBAC role assignments, resource locks (ReadOnly vs. Delete), Azure Policy deny effects, and Azure AD Privileged Identity Management (PIM) eligible vs. active role assignments - and how these interact to permit or block specific management actions.
Reference. https://learn.microsoft.com/en-us/azure/role-based-access-control/overview | https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/lock-resources | https://learn.microsoft.com/en-us/azure/governance/policy/overview | https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-configure
Topics
Community Discussion
No community discussion yet for this question.
