nerdexam
Microsoft

AZ-500 · Question #584

You have an Azure subscription named Sub1 and an Amazon Web Services (AWS) account named AWS1. You create a new user account in Azure named Admin1. You need to ensure that Admin1 can perform the…

The correct answer is B. owner. Connect AWS accounts to Microsoft Defender for Cloud We recommend that you use the autoprovisioning process to install Azure Arc on all of your existing and future EC2 instances. To enable the Azure Arc autoprovisioning, you need Owner permission on the relevant Azure…

Submitted by skyler.x· Mar 6, 2026Secure identity and access

Question

You have an Azure subscription named Sub1 and an Amazon Web Services (AWS) account named AWS1. You create a new user account in Azure named Admin1. You need to ensure that Admin1 can perform the following actions: - Add AWS1 to Microsoft Defender for Cloud. - Enable Azure Arc autoprovisioning for all existing and future Amazon Elastic Compute Cloud (EC2) instances. The solution must follow the principle of least privilege. Which role should you assign to Admin1 at the Sub1 scope?

Options

  • ACrossConnectionManager
  • Bowner
  • CContributor
  • DSecurity Admin
  • EService Connector Contributor

How the community answered

(14 responses)
  • A
    7% (1)
  • B
    71% (10)
  • D
    14% (2)
  • E
    7% (1)

Explanation

Connect AWS accounts to Microsoft Defender for Cloud We recommend that you use the autoprovisioning process to install Azure Arc on all of your existing and future EC2 instances. To enable the Azure Arc autoprovisioning, you need Owner permission on the relevant Azure subscription. https://learn.microsoft.com/en-us/azure/defender-for-cloud/quickstart-onboard-aws

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice