Understanding Azure Built-in Role Assignments

5 questions Pass: 70% +15 pts

Quiz covering Managing Security Controls for Identity

Understanding Azure Built-in Role Assignments

5 questions | Pass: 70% | Earn 15 points

Questions in this quiz

A preview of the 5 questions covered. Start the quiz above to answer them, check your score, and read the explanations.

  1. 1

    Which Azure built-in role allows a user to view all existing resources within a subscription but strictly prohibits them from making any changes, creating new resources, or managing access permissions?

  2. 2

    An IT manager needs to delegate the task of managing Role-Based Access Control (RBAC) permissions for a specific Resource Group to a team lead. The team lead should be able to assign roles to others but should not have the permission to create, delete, or modify the actual resources (like Virtual Machines) within that group. Which role should be assigned?

  3. 3

    A developer is assigned the 'Reader' role at the Subscription level to ensure they can see the environment. However, they also need full management rights (create, delete, update) for a specific Resource Group named 'Dev-Project-01'. What is the effective permission of the developer for resources within 'Dev-Project-01'?

  4. 4

    Your organization wants to allow a junior admin to manage Virtual Machines, including starting, stopping, and restarting them, as well as changing the VM size. However, they should not be able to modify the Virtual Network or the Storage Account associated with the VM. Which built-in role is most appropriate?

  5. 5

    A third-party auditor needs to evaluate your security posture. They require permissions to view security policies and alerts in Microsoft Defender for Cloud, and they also need the ability to update security policies to remediate findings. However, they must not be able to delete resources or manage RBAC assignments. Which role provides the minimum necessary permissions?