exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 2 question 54 discussion

Actual exam question from Microsoft's AZ-500
Question #: 54
Topic #: 2
[All AZ-500 Questions]

HOTSPOT -
You plan to implement an Azure function named Function1 that will create new storage accounts for containerized application instances.
You need to grant Function1 the minimum required privileges to create the storage accounts. The solution must minimize administrative effort.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/managed-identities-azure-resources/overview https://docs.microsoft.com/en-us/azure/active-directory/managed-identities-azure-resources/howto-assign-access-portal

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Fred64
Highly Voted 3 years, 10 months ago
minimize admin effort=> system assign MI minimum required priviledge => Custom role. All other role have too much priviledges
upvoted 56 times
...
Troublemaker
Highly Voted 1 year, 7 months ago
In Exam - 28/7/2023
upvoted 10 times
hellboycze
1 year, 7 months ago
well, today is 25.7. :D and i am reading questions
upvoted 8 times
...
...
stonwall12
Most Recent 1 week, 3 days ago
Answer: 1. System-assigned MI 2. Custom RBAC Reason: 1. A system-assigned managed identity offers automatic Azure management with lifecycle tied to the Azure Function, requiring minimal administrative effort. 2. Custom RBAC role assignment allows defining the exact minimum permissions needed for storage account creation, following the principle of least privilege more strictly than built-in roles or classic administrator roles which might provide excess permissions. Reference: 1. https://learn.microsoft.com/en-us/azure/app-service/overview-managed-identity 2. https://learn.microsoft.com/en-us/azure/role-based-access-control/custom-roles
upvoted 1 times
...
zellck
1 year, 9 months ago
1. System-assigned managed identity 2. Custom RBAC role assignment https://learn.microsoft.com/en-us/azure/active-directory/managed-identities-azure-resources/overview#managed-identity-types https://learn.microsoft.com/en-us/azure/role-based-access-control/custom-roles If the Azure built-in roles don't meet the specific needs of your organization, you can create your own custom roles. Just like built-in roles, you can assign custom roles to users, groups, and service principals at management group, subscription, and resource group scopes.
upvoted 4 times
...
icebw22
1 year, 11 months ago
correct both system or user managed identity would work, but question states less admin so system managed identity wins
upvoted 1 times
153a793
4 months, 2 weeks ago
agree with the justification. if question ask better managed option then user managed identity would be better option
upvoted 1 times
...
...
majstor86
1 year, 11 months ago
System Assigned Managed Identity Custom role (RBAC)
upvoted 3 times
...
F117A_Stealth
2 years, 3 months ago
minimize admin effort=> system assign MI minimum required priviledge => Custom role. All other role have too much priviledges
upvoted 2 times
...
salmantarik
2 years, 8 months ago
Minimized admin effort 1 - SAMI 2- RBAC (Custom role)
upvoted 2 times
...
asfgsertweg
2 years, 10 months ago
- User assigned MI, because accounts will be reused for multiples instances - Customized roles to reduce the scope of privilege
upvoted 7 times
...
Eltooth
2 years, 11 months ago
I’d go for SAMI and custom role to minimise privileges over admin effort.
upvoted 1 times
...
zioggs
3 years, 3 months ago
Exam - 4/11/21
upvoted 3 times
...
Jco
3 years, 4 months ago
#exam question # 29 Sep
upvoted 2 times
...
TonytheTiger
3 years, 5 months ago
## Exam Question - 17 Sept 2021 ##
upvoted 2 times
...
francis6170
3 years, 5 months ago
Got this in the AZ-500 exam (Sept 2021)!
upvoted 3 times
...
teehex
3 years, 9 months ago
Two steps you'd need to do: - Enable System-assigned Managed Identity (SAMI) in your Azure function app (https://docs.microsoft.com/en-us/azure/app-service/overview-managed-identity?tabs=dotnet#add-a-system-assigned-identity) - Assign it a custom role (Microsoft.Storage/storageAccounts...) with least privilege.
upvoted 7 times
...
Cyberbug2021
3 years, 10 months ago
Correct answers
upvoted 4 times
...
macco455
3 years, 11 months ago
Seems like you could use a normal RBAC role for this and assign the managed identity to it instead of creating an entirely new role just for storage account creation.
upvoted 4 times
A365
3 years, 11 months ago
agree, there is a built in role to create storage accounts: https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#storage-account-contributor
upvoted 6 times
rooban
3 years ago
IMHO that's too many permissions. It can create AND MANAGE storage accounts, manage deployments etc. So it seems we have to choose either to do a bit of extra administrative work setting up the correct permissions or grant excessive permissions. I believe MS always wants us to strive for minimum required permissions so custom seems more appropriate.
upvoted 1 times
...
Fred64
3 years, 10 months ago
The scenario is: minimum required priviledge. Where do you take into account this reequirement?
upvoted 4 times
...
...
macco455
3 years, 11 months ago
Also, creating a custom role will be more administrative effort than is needed for this.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago