nerdexam
Microsoft

AZ-500 · Question #388

Hotspot Question You have the role assignments shown in the following exhibit. Use the drop-down menus to select the answer choice that completes each statement based on the information presented in…

The correct answer is Monitored storage's services are File services only. = Yes; Protected storage accounts are storage3 and storage5 only. = Yes; Only Admin1 can delete VM1. = Yes; Admin1 only can create new resource groups. = Yes. The answers are all 'Yes' based on the role assignments shown in the exhibit. Each statement accurately reflects the permissions and configurations derived from the RBAC role assignments: File services monitoring scope, specific protected storage accounts (storage3 and…

Submitted by jian89· Mar 6, 2026Manage Azure identities and governance - specifically implementing and managing Azure Role-Based Access Control (RBAC) to control access to Azure resources at various scopes (subscription, resource group, resource level)

Question

Hotspot Question You have the role assignments shown in the following exhibit. Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic. NOTE: Each correct selection is worth one point. Answer:

Exhibits

AZ-500 question #388 exhibit 1
AZ-500 question #388 exhibit 2
AZ-500 question #388 exhibit 3
AZ-500 question #388 exhibit 4

Answer Area

  • Monitored storage's services are File services only.Yes
  • Protected storage accounts are storage3 and storage5 only.Yes
  • Only Admin1 can delete VM1.Yes
  • Admin1 only can create new resource groups.Yes

Explanation

The answers are all 'Yes' based on the role assignments shown in the exhibit. Each statement accurately reflects the permissions and configurations derived from the RBAC role assignments: File services monitoring scope, specific protected storage accounts (storage3 and storage5), VM1 deletion rights limited to Admin1 (Owner role on VM1), and resource group creation restricted to Admin1 (who holds a subscription-level role permitting this action). RBAC roles are inherited hierarchically - subscription-level roles apply to all child resources, while resource-level roles are scoped only to that specific resource.

Topics

#Azure RBAC#Role Assignments#Azure Storage Security#Azure Resource Management

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice