AZ-305 exam dumps

AZ-305 practice question 28 of 243

Designing Microsoft Azure Infrastructure Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-305 Question 28

Single answer

You are designing an Azure environment for a development team that needs to deploy and manage virtual machines in a specific resource group called 'DevRG'. They should be able to create and modify resources in 'DevRG' but should not have the ability to access or modify resources in other resource groups or impact the subscription configuration. Which authorization approach should you recommend to grant appropriate access to the development team?

  1. A

    Assign the development group the Owner role at the subscription scope

  2. B

    Assign the development group the Contributor role at the DevRG resource group scope

  3. C

    Use Azure Policies to automatically allow resource creation in DevRG

  4. D

    Assign the Reader role at the DevRG resource group scope

Show answer and explanation

Correct answer: B

Explanation

Granting a role at the resource group level in Azure offers a balanced approach to security and flexibility, following the principle of least privilege. By assigning the development group the Contributor role on the DevRG resource group, you ensure they can create and manage resources only within that scope, without overextending their permissions to the entire subscription or other resource groups. Refer to Microsoft Docs for more details on role-based access control (RBAC) best practices and role assignment scopes: https://learn.microsoft.com/azure/role-based-access-control/role-assignments-portal.

  • A. Incorrect.

    Option 1: Assigning the Owner role at the subscription level gives the development team full control over the entire subscription, which is excessive access. This contradicts the principle of least privilege and could enable unintended changes or configurations outside the DevRG resource group.

  • B. Correct.

    Option 2: Assigning the Contributor role at the resource group level (in this case DevRG) precisely matches the requirement. The team can create, manage, and delete resources within DevRG but has no access to other resource groups or the subscription configuration. This is the recommended least-privileged approach.

  • C. Incorrect.

    Option 3: Azure Policies primarily define and enforce resource governance (such as allowed resource types or naming conventions), but they do not directly grant permissions for deploying or managing resources. Policies are complementary to role assignments, not a replacement.

  • D. Incorrect.

    Option 4: The Reader role only permits viewing resources, not creating or modifying them. This would prevent developers from deploying and managing virtual machines in DevRG.

Timed practice exam

Take a AZ-305 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam