exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 2 question 87 discussion

Actual exam question from Microsoft's AZ-500
Question #: 87
Topic #: 2
[All AZ-500 Questions]

You have an Azure subscription that contains a user named User1.

You need to ensure that User1 can create managed identities. The solution must use the principle of least privilege.

What should you do?

  • A. Create a management group and assign User1 the Hybrid Identity Administrator Azure Active Directory (Azure AD) role.
  • B. Create a management group and assign User1 the Managed Identity Operator role.
  • C. Create a resource group and assign User1 to the Managed Identity Contributor role.
  • D. Create an organizational unit (OU) and assign User1 the User administrator Azure Active Directory (Azure AD) role.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Seelearndo
Highly Voted 1 year, 9 months ago
Selected Answer: C
A - Wrong - Hybrid Identity Admin cannot create managed identities. Permissions are: Can manage AD to Azure AD cloud provisioning, Azure AD Connect, Pass-through Authentication (PTA), Password hash synchronization (PHS), Seamless Single sign-on (Seamless SSO), and federation settings. B - wrong - Managed Identity Operator cannot create managed identities. Permissions are: Read and Assign User Assigned Identity C - correct: Managed Identity Contributor can Create, Read, Update, and Delete User Assigned Identity. D - incorrect - can create users, but does not follow the principal of least privilege, as the permission set is comprehensive. User administrator can manage all aspects of users and groups. https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles
upvoted 18 times
...
waqqy
Most Recent 3 months ago
Selected Answer: C
C. Create a resource group and assign User1 to the Managed Identity Contributor role. Explanation: Managed Identity Contributor Role: This role allows the user to manage managed identities, including creating and deleting them, within the scope of the assigned resource group. It provides the necessary permissions without granting excessive access1. Principle of Least Privilege: By assigning the Managed Identity Contributor role at the resource group level, you ensure that User1 has the minimum permissions required to perform the task, reducing the risk of unnecessary access to other resources.
upvoted 1 times
...
alfaAzure
1 year, 2 months ago
Selected Answer: B
B. Create a management group and assign User1 the Managed Identity Operator role. The Managed Identity Operator role provides the necessary permissions for managing managed identities within Azure, while following the principle of least privilege. This role allows the user to create, update, and delete managed identities without granting broader permissions than necessary.
upvoted 1 times
Austin6488
6 months, 3 weeks ago
it's wrong, Operator role can't create. https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles Managed Identity Contributor -- Create, Read, Update, and Delete User Assigned Identity Managed Identity Operator -- Read and Assign User Assigned Identity
upvoted 1 times
...
...
Strifelife
1 year, 3 months ago
What's the resource group for ?
upvoted 3 times
...
zellck
1 year, 5 months ago
Selected Answer: C
C is the answer. https://learn.microsoft.com/en-us/azure/active-directory/managed-identities-azure-resources/how-manage-user-assigned-managed-identities?pivots=identity-mi-methods-azp#create-a-user-assigned-managed-identity To create a user-assigned managed identity, your account needs the Managed Identity Contributor role assignment.
upvoted 4 times
...
majstor86
1 year, 7 months ago
Selected Answer: C
C. Create a resource group and assign User1 to the Managed Identity Contributor role.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago