Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AZ-104 All Questions

View all questions & answers for the AZ-104 exam

Exam AZ-104 topic 2 question 53 discussion

Actual exam question from Microsoft's AZ-104
Question #: 53
Topic #: 2
[All AZ-104 Questions]

You have an Azure subscription named Subscription1 that contains a virtual network named VNet1. VNet1 is in a resource group named RG1.
Subscription1 has a user named User1. User1 has the following roles:
✑ Reader
✑ Security Admin
✑ Security Reader
You need to ensure that User1 can assign the Reader role for VNet1 to other users.
What should you do?

  • A. Remove User1 from the Security Reader role for Subscription1. Assign User1 the Contributor role for RG1.
  • B. Assign User1 the Owner role for VNet1.
  • C. Assign User1 the Contributor role for VNet1.
  • D. Assign User1 the Network Contributor role for VNet1.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
MentalG
Highly Voted 2 years, 5 months ago
B. Owner correct Owner = Grants full access to manage all resources, including the ability to assign roles in Azure RBAC. Contributor = Grants full access to manage all resources, but does NOT allow you to assign roles in Azure RBAC. (you cannot add users or changes their rights) User Access Administrator = Lets you manage user access to Azure resources. Reader = View all resources, but does not allow you to make any changes. Security Admin = View and update permissions for Security Center. Same permissions as the Security Reader role and can also update the security policy and dismiss alerts and recommendations. Network Contributor = Lets you manage networks, but not access to them. (so you can add VNET, subnet, etc)
upvoted 47 times
...
NaoVaz
Highly Voted 2 years ago
Selected Answer: B
B) "Assign User1 the Owner role for VNet1." From the provided options, only the Owner role scoped at the resource level gives the ability to assign other roles to other users.
upvoted 5 times
...
SeMo0o0o0o
Most Recent 1 month ago
Selected Answer: B
B is corerct
upvoted 1 times
...
Jedi_sg2000
4 months, 3 weeks ago
https://learn.microsoft.com/en-us/entra/identity/users/licensing-group-advanced#limitations-and-known-issues The feature can only be used with security groups, and Microsoft 365 groups that have securityEnabled=TRUE.
upvoted 1 times
...
3c5adce
5 months ago
D. Assign User1 the Network Contributor role for VNet1. Explanation: Assigning User1 the Network Contributor role for VNet1 would enable them to assign the Reader role for VNet1 to other users. The Network Contributor role grants permissions to manage network resources, including the ability to assign roles within the scope of the virtual network (VNet1). This role aligns with the requirement to allow User1 to assign the Reader role for VNet1 to other users.
upvoted 1 times
...
kijoksip
6 months, 3 weeks ago
This is what ChatGPT says: To ensure that User1 can assign the Reader role for VNet1 to other users, you should assign User1 the "Network Contributor" role for VNet1. This role grants the necessary permissions to manage all aspects of virtual networks, including assigning roles to other users. So, the correct action is: D. Assign User1 the Network Contributor role for VNet1.
upvoted 2 times
...
Rednevi
1 year ago
Selected Answer: B
the Contributor role in Azure does not have the permission to assign roles to other users or manage access control for other users. The Contributor role can perform actions such as creating, modifying, and deleting resources within the scope of a resource group or subscription, but it cannot manage access control. To grant the ability to assign roles and manage access control for Azure resources, you would typically need to assign the User Access Administrator or Owner roles to a user or group. These roles have the necessary permissions to manage access control, including the assignment of roles to other users.
upvoted 4 times
...
Codelawdepp
1 year, 1 month ago
Selected Answer: B
This question comes up so often and is easy to answer: Only owners or User Access Administrators can assign roles to other users
upvoted 4 times
...
Mehedi007
1 year, 2 months ago
Selected Answer: B
"Grants full access to manage all resources, including the ability to assign roles in Azure RBAC." https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#owner
upvoted 1 times
...
raj24051961
1 year, 3 months ago
within provided solution , the Owner role can assign role for other users B. Owner is answer
upvoted 1 times
...
Athul07
1 year, 4 months ago
C. Assign User1 the Contributor role for VNet1. To ensure that User1 can assign the Reader role for VNet1 to other users, you should assign User1 the Contributor role for VNet1. The Contributor role grants permissions to manage all resources within a specific scope, including the ability to assign roles to other users. By assigning User1 the Contributor role for VNet1, User1 will have the necessary permissions to assign the Reader role for VNet1 to other users. Assigning User1 the Owner role for VNet1 (option B) would grant excessive permissions, allowing User1 to make any changes to VNet1 and its resources, which may not be desired.
upvoted 1 times
...
myarali
1 year, 7 months ago
Selected Answer: B
B. Owner correct Owner: Grants full access to manage all resources, including the ability to assign roles in Azure RBAC. User Access Administrator: Lets you manage user access to Azure resources. Conributor: Grants full access to manage all resources, but does not allow you to assign roles in Azure RBAC, manage assignments in Azure Blueprints, or share image galleries. Reader: View all resources, but does not allow you to make any changes. Network Contributor: Lets you manage networks, but not access to them.
upvoted 2 times
...
zellck
1 year, 8 months ago
Selected Answer: B
B is the answer.
upvoted 3 times
...
EmnCours
2 years, 1 month ago
Selected Answer: B
Correct Answer: B
upvoted 2 times
...
vetrivelm
2 years, 5 months ago
Answer B is correct. Owner Has full access to all resources including the right to delegate access to others.
upvoted 2 times
...
sjb666
2 years, 5 months ago
Selected Answer: B
Answer is B. Contributor can't grant access to others
upvoted 1 times
...
Pasmo
2 years, 5 months ago
Selected Answer: B
Answer is correct
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...