exam questions

Exam AZ-104 All Questions

View all questions & answers for the AZ-104 exam

Exam AZ-104 topic 2 question 53 discussion

Actual exam question from Microsoft's AZ-104
Question #: 53
Topic #: 2
[All AZ-104 Questions]

You have an Azure subscription named Subscription1 that contains a virtual network named VNet1. VNet1 is in a resource group named RG1.
Subscription1 has a user named User1. User1 has the following roles:
✑ Reader
✑ Security Admin
✑ Security Reader
You need to ensure that User1 can assign the Reader role for VNet1 to other users.
What should you do?

  • A. Remove User1 from the Security Reader role for Subscription1. Assign User1 the Contributor role for RG1.
  • B. Assign User1 the Owner role for VNet1.
  • C. Assign User1 the Contributor role for VNet1.
  • D. Assign User1 the Network Contributor role for VNet1.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
MentalG
Highly Voted 2 years, 10 months ago
B. Owner correct Owner = Grants full access to manage all resources, including the ability to assign roles in Azure RBAC. Contributor = Grants full access to manage all resources, but does NOT allow you to assign roles in Azure RBAC. (you cannot add users or changes their rights) User Access Administrator = Lets you manage user access to Azure resources. Reader = View all resources, but does not allow you to make any changes. Security Admin = View and update permissions for Security Center. Same permissions as the Security Reader role and can also update the security policy and dismiss alerts and recommendations. Network Contributor = Lets you manage networks, but not access to them. (so you can add VNET, subnet, etc)
upvoted 56 times
...
NaoVaz
Highly Voted 2 years, 5 months ago
Selected Answer: B
B) "Assign User1 the Owner role for VNet1." From the provided options, only the Owner role scoped at the resource level gives the ability to assign other roles to other users.
upvoted 6 times
...
b411470
Most Recent 3 months, 1 week ago
Selected Answer: B
Anything with 'Contributor' in the role cannot do anything with users.
upvoted 1 times
...
[Removed]
6 months ago
Selected Answer: B
B is corerct
upvoted 1 times
...
Jedi_sg2000
9 months, 3 weeks ago
https://learn.microsoft.com/en-us/entra/identity/users/licensing-group-advanced#limitations-and-known-issues The feature can only be used with security groups, and Microsoft 365 groups that have securityEnabled=TRUE.
upvoted 1 times
...
3c5adce
10 months ago
D. Assign User1 the Network Contributor role for VNet1. Explanation: Assigning User1 the Network Contributor role for VNet1 would enable them to assign the Reader role for VNet1 to other users. The Network Contributor role grants permissions to manage network resources, including the ability to assign roles within the scope of the virtual network (VNet1). This role aligns with the requirement to allow User1 to assign the Reader role for VNet1 to other users.
upvoted 1 times
...
kijoksip
11 months, 3 weeks ago
This is what ChatGPT says: To ensure that User1 can assign the Reader role for VNet1 to other users, you should assign User1 the "Network Contributor" role for VNet1. This role grants the necessary permissions to manage all aspects of virtual networks, including assigning roles to other users. So, the correct action is: D. Assign User1 the Network Contributor role for VNet1.
upvoted 2 times
Jay_D_Lincoln
1 month ago
This is why we should not blindly trust AI as reference. --- Only owners or User Access Administrators can assign roles to other users. ---
upvoted 1 times
...
...
Rednevi
1 year, 5 months ago
Selected Answer: B
the Contributor role in Azure does not have the permission to assign roles to other users or manage access control for other users. The Contributor role can perform actions such as creating, modifying, and deleting resources within the scope of a resource group or subscription, but it cannot manage access control. To grant the ability to assign roles and manage access control for Azure resources, you would typically need to assign the User Access Administrator or Owner roles to a user or group. These roles have the necessary permissions to manage access control, including the assignment of roles to other users.
upvoted 4 times
...
Codelawdepp
1 year, 6 months ago
Selected Answer: B
This question comes up so often and is easy to answer: Only owners or User Access Administrators can assign roles to other users
upvoted 5 times
...
Mehedi007
1 year, 7 months ago
Selected Answer: B
"Grants full access to manage all resources, including the ability to assign roles in Azure RBAC." https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#owner
upvoted 1 times
...
[Removed]
1 year, 8 months ago
within provided solution , the Owner role can assign role for other users B. Owner is answer
upvoted 1 times
...
Athul07
1 year, 9 months ago
C. Assign User1 the Contributor role for VNet1. To ensure that User1 can assign the Reader role for VNet1 to other users, you should assign User1 the Contributor role for VNet1. The Contributor role grants permissions to manage all resources within a specific scope, including the ability to assign roles to other users. By assigning User1 the Contributor role for VNet1, User1 will have the necessary permissions to assign the Reader role for VNet1 to other users. Assigning User1 the Owner role for VNet1 (option B) would grant excessive permissions, allowing User1 to make any changes to VNet1 and its resources, which may not be desired.
upvoted 1 times
...
myarali
2 years ago
Selected Answer: B
B. Owner correct Owner: Grants full access to manage all resources, including the ability to assign roles in Azure RBAC. User Access Administrator: Lets you manage user access to Azure resources. Conributor: Grants full access to manage all resources, but does not allow you to assign roles in Azure RBAC, manage assignments in Azure Blueprints, or share image galleries. Reader: View all resources, but does not allow you to make any changes. Network Contributor: Lets you manage networks, but not access to them.
upvoted 2 times
...
zellck
2 years, 1 month ago
Selected Answer: B
B is the answer.
upvoted 3 times
...
EmnCours
2 years, 6 months ago
Selected Answer: B
Correct Answer: B
upvoted 2 times
...
vetrivelm
2 years, 10 months ago
Answer B is correct. Owner Has full access to all resources including the right to delegate access to others.
upvoted 2 times
...
sjb666
2 years, 10 months ago
Selected Answer: B
Answer is B. Contributor can't grant access to others
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago