exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 3 question 7 discussion

Actual exam question from Microsoft's AZ-500
Question #: 7
Topic #: 3
[All AZ-500 Questions]

SIMULATION -
You need to grant the required permissions to a user named User2-1234578 to manage the virtual networks in the RG1lod1234578 resource group. The solution must use the principle of least privilege.
To complete this task, sign in to the Azure portal.

Show Suggested Answer Hide Answer
Suggested Answer: See the explanation below.
1. In Azure portal, locate and select the RG1lod1234578 resource group.
2. Click Access control (IAM).
3. Click the Role assignments tab to view all the role assignments at this scope.
4. Click Add > Add role assignment to open the Add role assignment pane.

5. In the Role drop-down list, select the role Virtual Machine Contributor.
Virtual Machine Contributor lets you manage virtual machines, but not access to them, and not the virtual network or storage account they're connected to.
6. In the Select list, select user User2-1234578
7. Click Save to assign the role.
Reference:
https://docs.microsoft.com/en-us/azure/role-based-access-control/role-assignments-portal https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#virtual-machine-contributor

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
F117A_Stealth
Highly Voted 1 year, 5 months ago
Correct Answer: 1. In Azure portal, locate and select the RG1lod1234578 resource group. 2. Click Access control (IAM). 3. Click the Role assignments tab to view all the role assignments at this scope. 4. Click Add > Add role assignment to open the Add role assignment pane. 5. In the Role drop-down list, select the role Network Contributor. Network Contributor Lets you manage networks, but not access to them. 6. In the Select list, select user User2-1234578 7. Click Save to assign the role.
upvoted 29 times
upliftinghut
1 year ago
Should we choose the network instead of resource group in step 1?
upvoted 1 times
...
heatfan900
8 months ago
Correct. The question is requiring the management of virtual networks not VMs. The network contributor role is the right answer.
upvoted 5 times
...
...
Kelly8023
Highly Voted 1 year, 6 months ago
Vote for network contributor
upvoted 7 times
...
[Removed]
Most Recent 1 year, 1 month ago
In another question it was deemed that Network Contributor had too high access to be considered least-privileged. The choice is then a Custom role
upvoted 2 times
...
ltjones12
1 year, 4 months ago
Thank you for all the comments. This one confused me since it was asking to allow the management of Virtual Machines
upvoted 1 times
...
F117A_Stealth
1 year, 5 months ago
Answer isnt 100% correct. Steps are right, but the role required is Network Contributor: Network Contributor: Lets you manage networks, but not access to them.
upvoted 2 times
...
jore041
1 year, 5 months ago
network contributor is the correct role to be able to manage virtual network tho.. https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles?toc=%2Fazure%2Fvirtual-network%2Ftoc.json#network-contributor
upvoted 2 times
...
OpsecDude
1 year, 7 months ago
Only network Contributor is needed to comply with least privilege. Network Contributor: Lets you manage networks, but not access to them.
upvoted 4 times
...
ikidreamz
1 year, 7 months ago
Network contributor (to manage virtual network) , Virtual machine contributor "This role does not grant you management access to the virtual network or storage account" REF- https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#virtual-machine-contributor
upvoted 2 times
...
JakeCallham
1 year, 7 months ago
Doesn't make sense to be bebothered with VM right, only network is needed
upvoted 2 times
...
Tash95
2 years ago
Procedure is correct, but the role would be Virtual Machine Contributor: Lets you manage classic networks, but not access to them.
upvoted 1 times
Subbydavid
2 years ago
Why not Network contributor? Question says manage vnet not manage vm
upvoted 1 times
...
yooi
2 years ago
I guess the role should be Network contributor: Lets you manage networks, but not access to them.
upvoted 5 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago