exam questions

Exam SC-300 All Questions

View all questions & answers for the SC-300 exam

Exam SC-300 topic 2 question 40 discussion

Actual exam question from Microsoft's SC-300
Question #: 40
Topic #: 2
[All SC-300 Questions]

HOTSPOT
-

You have an Azure subscription that contains the following virtual machine:

• Name: V1
• Azure region: East US
• System-assigned managed identity: Disabled

You create the managed identities shown in the following table.



You perform the following actions:

• Assign Managed1 to V1.
• Create a resource group named RG1 in the West US region.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Markus
Highly Voted 1 year, 9 months ago
YYN. You can use user assigned managed identities in more than one Azure region.
upvoted 18 times
wooyourdaddy
1 year, 9 months ago
Correct regarding managed identities and regions: https://learn.microsoft.com/en-us/azure/active-directory/managed-identities-azure-resources/managed-identities-faq#can-the-same-managed-identity-be-used-across-multiple-regions
upvoted 7 times
...
...
0byte
Highly Voted 1 year ago
YYN Ref first two questions - both are Y because you can assign managed identity to a VM regardless of which region the identity or VM is located - I tested it. Ref the third one - I think N. The catch here is that you cannot assign a role directly to a VM but only to an identity, system or user managed.
upvoted 12 times
Nyamnyam
11 months, 3 weeks ago
Good point on case 3. Initially I thought it should be YYY, but the Identity you assign an owner permission, and not the Virtual Machine. And again, it is even wrongly written: VM1 instead of V1, as in case 1 and 2.
upvoted 1 times
...
...
RemmyT
Most Recent 4 months, 2 weeks ago
Yes Yes No VM1 can be assigned the Owner role for RG1 but only with System-assigned managed identity enabled. If System-assigned managed identity is enabld the role can be assigned to VM directly or to the System-assigned managed identity associated with VM1. In both cases we only can see the ID of system identity.
upvoted 1 times
RemmyT
4 months, 2 weeks ago
NO System-assigned managed identity: Disabled
upvoted 1 times
...
...
AK_1234
1 year ago
- Y - Y - N
upvoted 2 times
...
EmnCours
1 year, 2 months ago
YES YES YES
upvoted 1 times
...
nils241
1 year, 2 months ago
The first two are definite yes / yes. For the third, it depends on the scenario; Scenario 1: I give one of the user assinged identities the owner role. Problem: Every service with the identity would be owern. This would possibly contradict the principle of least privilege. But then it would be Y/ Y /Y Scenario 2: I want only the VM to be Owner and assume that I don't want to give the permission to a User assigned Identity. I don't have a System Assinged Identity, so then: Y /Y / N Since it is not directly stated here whether the assignment of the authorization to a Managed Identity (User assigned) is allowed, I assume an authorization of the VM directly. Therefore I feel more comfortable with Y /Y / N.
upvoted 1 times
...
mali1969
1 year, 4 months ago
You can assign Managed2 to V1 (Yes), but you cannot assign Managed3 to V1 (No). You can assign the owner role for RG1 to V1 (Yes), but there is no VM1 mentioned in the message.
upvoted 1 times
...
dule27
1 year, 4 months ago
YES YES YES
upvoted 1 times
...
ITAdmin2019
1 year, 5 months ago
Just tested this in my lab - the answer is YYY: vm1 created with system assigned identity off (vm1 is in North Europe) useridentity1 created in NorthEurope can be assigned to the VM useridentity2 created in EastUS can be assigned to the VM Adding useridentity1 as an owner to a resource group in Brazil worked fine
upvoted 4 times
...
cris_exam
1 year, 6 months ago
As long as the system-assigned managed identity is disabled on an Azure VM resource, then there is no way to add any user-assigned managed identity. However, the question does tell us that managed-assigned identities get created which it doesn't specify, but they should be USER-assigned managed identities (system-assigned identities cannot be created as stand-alone they are tied to a resource that you deploy), anyhow, then we are told that Managed1 is added to the VM which would mean that the system-assigned identity has been enabled (otherwise it wouldn't work). If so, then all 3 Managed Identities can be added to the VM. Regarding the last statement, it's YES, you can assign the VM with the owner role for the RG, it doesn't impact due to region. In conclusion I say it should be YYY.
upvoted 3 times
nils241
1 year, 2 months ago
You can add "user assigned identitys" without enable "system assigned" on the VM
upvoted 1 times
...
chikorita
1 year, 6 months ago
i feel the same too
upvoted 1 times
...
cris_exam
1 year, 6 months ago
As long as the system-assigned managed identity on the VM is disabled and there is no other subscription/tenant level policy that would deny adding the owner role to a VM. If anybody has a better research, please correct me.
upvoted 1 times
...
...
chikorita
1 year, 6 months ago
can anyone help me understand why 3rd box is marked as NO? i mean it doesnt make sense but its possible to have VM's MI to have roles of its own correct me if wrong plz
upvoted 1 times
...
Arjanussie
1 year, 7 months ago
bad question the table does not see if it is user or system assigned and that makes the difference cross region is only supported for user-assigned since with system assigned each region would have to create its own identity since it's tied to the resource itself
upvoted 2 times
...
hieverybody
1 year, 9 months ago
I believe VM1 should be Managed 1 here. So answer is No.
upvoted 1 times
...
natazar
1 year, 9 months ago
I think it should be YNN
upvoted 1 times
kevin_office
1 year, 9 months ago
please dont just say it should be this and that. u need to justify why it should be YNN so that other users see if u are right or not. u end up confusing people by just saying what u think without stating why!
upvoted 50 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago