exam questions

Exam AZ-400 All Questions

View all questions & answers for the AZ-400 exam

Exam AZ-400 topic 4 question 73 discussion

Actual exam question from Microsoft's AZ-400
Question #: 21
Topic #: 4
[All AZ-400 Questions]

DRAG DROP -

You have a tenant in Microsoft Azure Active Directory (Azure AD), part of Microsoft Entra. The tenant contains three groups named Group1, Group2, and Group3.

You create a new project in Azure DevOps named Project1.

You need to secure the service connections for Project1. The solution must meet the following requirements:

• The members of Group1 must be able to share and unshare a service connection with other projects.
• The members of Group2 must be able to rename a service connection and update the description.
• The members of Group3 must be able to use the service connection within build or release pipelines.
• The principle of least privilege must be followed.

Which permission should you grant to each group? To answer, drag the appropriate permissions to the correct groups. Each permission may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
BakaPon
Highly Voted 1 year, 3 months ago
Group1: Org-level Admin Group2: Project-level Admin Group3: User The organization-level Administrator can do the following administrative tasks: - Manage organization-level users - Edit all the fields of a service connection - Share and unshare a service connection with other projects https://learn.microsoft.com/en-us/azure/devops/pipelines/library/service-endpoints?view=azure-devops&tabs=yaml#organization-level-permissions The project-level Administrator can do the following tasks: - Manage other users and roles at the project-level - Rename a service connection and update the description - Delete a service connection, which removes it from the project https://learn.microsoft.com/en-us/azure/devops/pipelines/library/service-endpoints?view=azure-devops&tabs=yaml#project-level-permissions A User can: - Use the service connection when authoring build or release pipelines or authorize yaml pipelines https://learn.microsoft.com/en-us/azure/devops/pipelines/library/service-endpoints?view=azure-devops&tabs=yaml#user-permissions
upvoted 22 times
cma2109
4 months, 2 weeks ago
why not a creator for second group since it has an option to rename/name service connection and it has less privileges over project-level admin? just thinking
upvoted 1 times
...
Gabsyfire
1 year, 2 months ago
correct
upvoted 2 times
...
...
Alandt
Highly Voted 1 year, 3 months ago
Apologies for the confusion. You're correct. Here's the corrected assignment: Group1: Organization-level Administrator - The Organization-level Administrator role allows members to share and unshare a service connection with other projects. Group2: Creator - The Creator role allows members to rename a service connection and update the description. Group3: User - The User role allows members to use the service connection within build or release pipelines. This setup follows the principle of least privilege, as each group is only granted the permissions necessary for their specific tasks.
upvoted 6 times
...
mouzzy
Most Recent 5 months, 4 weeks ago
Group1: Project Administrator Reason: Members need to share and unshare service connections with other projects, which requires administrative privileges at the project level. Group2: Contributor Reason: Members need to rename a service connection and update its description. Contributors have the necessary permissions to manage service connections without full administrative rights. Group3: User Reason: Members need to use the service connection within build or release pipelines. Users have the necessary permissions to access and use service connections in pipelines.
upvoted 1 times
cma2109
4 months, 2 weeks ago
Project Administrator is different from project-level administrator. Project level administrator has access to control a specific project, wheras project admin has access to control multiple projects. I beleive it should be org level admin since there are three groups.
upvoted 1 times
...
...
marmila
8 months ago
Project-level Administrator Contributor User
upvoted 4 times
...
sondrex
9 months, 2 weeks ago
project-level Administrator Contributor User
upvoted 3 times
...
Misterit
10 months ago
1.Contributor The Contributor role allows members to manage resources, including sharing and unsharing service connections across projects. This role has sufficient privileges for managing service connections but not for more administrative tasks. 2. Project-level Administrator Project-level Administrators can manage various project settings, including renaming and updating descriptions of service connections. This role provides the necessary administrative capabilities specific to the project without granting broader administrative privileges. 3. User Users can utilize the service connections within build or release pipelines. This role ensures they can access the resources needed for their tasks without having permissions to alter the configurations of the service connections.
upvoted 2 times
...
Papee
1 year, 2 months ago
Contributor Creator User With the "Contributor" permission you can share and unshare service connections with other projects. Keep in mind the principle of least privilege. https://learn.microsoft.com/en-us/azure/devops/organizations/security/permissions?view=azure-devops&tabs=preview-page#groups
upvoted 5 times
507101b
9 months, 1 week ago
According to https://learn.microsoft.com/en-us/azure/devops/pipelines/policies/permissions?view=azure-devops#service-connection-permissions there is no Contributor role. Also: “Only the organization-level administrators from user permissions can share the service connection with other projects.” and "Organization-level administrators can unshare a service connection from any shared project.” [https://learn.microsoft.com/en-us/azure/devops/pipelines/policies/permissions?view=azure-devops#set-service-connection-project-permissions]
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago