AZ-500 · Question #442
SIMULATION You need to ensure that a user named user2-28681041 can manage the properties of the virtual machines in the RG1lod28681041 resource group. The solution must use the principle of least…
The Virtual Machine Contributor role is the correct choice because it grants permissions to manage virtual machine properties (start, stop, resize, configure, etc.) without providing access to the underlying virtual network or storage resources, nor to the resource group itself…
Question
Exhibit
Explanation
The Virtual Machine Contributor role is the correct choice because it grants permissions to manage virtual machine properties (start, stop, resize, configure, etc.) without providing access to the underlying virtual network or storage resources, nor to the resource group itself - perfectly aligning with the principle of least privilege. Assigning this role at the RG1lod28681041 resource group scope ensures user2-28681041 can manage all VMs within that group without needing broader subscription-level access. Using Access Control (IAM) with a scoped role assignment is the Azure RBAC standard approach for delegating specific permissions.
Topics
Community Discussion
No community discussion yet for this question.
