exam questions

Exam AZ-104 All Questions

View all questions & answers for the AZ-104 exam

Exam AZ-104 topic 6 question 26 discussion

Actual exam question from Microsoft's AZ-104
Question #: 26
Topic #: 6
[All AZ-104 Questions]

HOTSPOT -
You have the following custom role-based access control (RBAC) role.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
fabio79
Highly Voted 2 years, 6 months ago
For Me N,Y,Y. Microsoft.Compute/virtualMachines/* Perform all virtual machine actions including create, update, delete, start, restart, and power off virtual machines. Execute scripts on virtual machines.
upvoted 148 times
djhyfdgjk
11 months, 4 weeks ago
How will you create VM without permissions on any RG ?
upvoted 5 times
dendenp
6 months, 1 week ago
POLICY IS APPLIED AT SUB LEVEL
upvoted 2 times
...
...
humnahibataynge
2 years, 6 months ago
correct
upvoted 2 times
...
lebowski
2 years, 5 months ago
I do agree
upvoted 1 times
...
Dhanishetty
2 years, 2 months ago
How about permissions regarding resource groups. I guess user has only read permission for resource groups
upvoted 3 times
...
...
klexams
Highly Voted 2 years, 4 months ago
N - ms.auth/*/write is NOT allowed. Y - ms.comp/vm/* is allowed. Y - ms.net/netint/* is allowed.
upvoted 69 times
...
Dankho
Most Recent 4 months, 2 weeks ago
Y,N,Y The hard one is #2 and you don't have the following to write to a resource group: Microsoft.Resources/subscriptions/resourceGroups/write
upvoted 1 times
Dankho
4 months, 2 weeks ago
I meant NNY
upvoted 2 times
...
...
Dankho
4 months, 2 weeks ago
You can argue that 2 is no because you need to write to a resource group and this doesn't exist: Microsoft.Resources/subscriptions/resourceGroups/write
upvoted 1 times
...
[Removed]
5 months ago
WRONG.. No Yes Yes
upvoted 3 times
...
joolitan
5 months, 2 weeks ago
Users that are assigned to Role1 can assign Role1 to user = No ( notAction = Authorization/elevateAccess/Action ) User that are assigned Role1 can deploy new virtual machine = Yes ( action = Compute/virtualMachine/* ) Users that are assigned in Role1 can set a static IP address to a virtual machine = Yes ( action = Network/networkinterface/* )
upvoted 2 times
...
[Removed]
6 months, 3 weeks ago
N-Y-Y Box 1: N Microsoft.Authorization notAction - user can't assign roles Box 2: Yes Role1 in this question has the attributes needed by "Virtual Machine Contributor role" necessary to create VMs, including Microsoft.Resource attributes as below: Microsoft.Resources/deployments/* Microsoft.Resources/subscriptions/resourceGroups/read Therefore, Role1 can indeed create VMs Reference: https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles/compute#virtual-machine-contributor Box 3: Yes - static IP shall be under NIC, and user has Microsoft.Network/networkInterfaces/*
upvoted 2 times
...
SofiaLorean
8 months, 4 weeks ago
should be N,Y,Y
upvoted 1 times
...
Forkbeard
9 months, 2 weeks ago
N-Y-Y Users that are assigned Role1 can assign Role1 to users: no, because "Microsoft.Authorization/elevateAccess/Action" is under "notAction". Source: https://learn.microsoft.com/en-us/azure/role-based-access-control/role-definitions#notactions Users that are assigned Role1 can deploy new virtual machines: yes, because onder "actions" we have "Microsoft.Resources/deployments/*". Source: https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles/compute#virtual-machine-contributor Users that are assigned Role1 can set a static IP address on a virtual machine: yes, because onder "actions" we have "Microsoft.Network/networkinterfaces/*". Source: https://docs.metallic.io/metallic/azure_resource_provider_usage.html
upvoted 4 times
...
LovelyGroovey
10 months, 2 weeks ago
I think the answer is No-No-Yes. The key word is “notAction” It says Role1 can not do these: “notAction”: [ “Microsoft.Authorization/*/Delete”, “Microsoft.Authorization/*/Write”, “Microsoft.Authorization/elevateAccess/Action” I say Yes to Role1 can set a static IP address on a virtual machine, because it does not say you can not do it in "notAction"
upvoted 3 times
...
Amir1909
11 months, 2 weeks ago
No Yes Yes
upvoted 1 times
...
KotNinja
1 year, 4 months ago
Users that are assigned Role1 can assign Role1 to users: No (due to a lack of specific roleAssignments permissions and notActions restrictions). Users that are assigned Role1 can deploy new virtual machines: Yes (supported by "Microsoft.Compute/virtualMachines/*"). Users that are assigned Role1 can set a static IP address on a virtual machine: Yes (supported by "Microsoft.Network/networkInterfaces/*").
upvoted 5 times
...
Josete1106
1 year, 7 months ago
N Y Y is correct!
upvoted 2 times
...
RandomNickname
1 year, 8 months ago
Box 1: N Because doesn't have: Microsoft.Authorization/*/Write - Create roles, role assignments, policy assignments, policy definitions and policy set definitions Box 2; Yes Has been assigned; Microsoft.Compute/virtualMachines/* - Perform all virtual machine actions including create, update, delete, start, restart, and power off virtual machines. Execute scripts on virtual machines. Box 3: Y Has been assigned; Microsoft.Network/networkInterfaces/* - Create and manage network interfaces See; https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles
upvoted 4 times
...
friendlyvlad
1 year, 9 months ago
I think it should be NNY. The user cannot assign to the role1 other users since ms.auth/*/write is not allowed. The user cannot create a VM since she is a reader at the RG level. The user with the Reader role on a resource group does not have permission to create a virtual machine (VM) within that resource group. The Reader role is a read-only role that only allows the user to view the resources and their configurations within the resource group. However, she can modify the IP address of the existing VM because she is a VM Contributor.
upvoted 4 times
...
SIAMIANJI
1 year, 9 months ago
Correct answer is N, Y, Y
upvoted 1 times
...
SIAMIANJI
1 year, 10 months ago
The correct answer is N, Y, Y
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago