AZ-305 exam dumps

AZ-305 practice question 31 of 243

Designing Microsoft Azure Infrastructure Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-305 Question 31

Single answer

You manage a production Azure subscription for your organization. A separate department needs read-only access to all virtual machines within this subscription. The goal is to grant and revoke permissions quickly and easily as new members join or leave that department. Which solution should you recommend for authorizing this department's access to your production VMs?

  1. A

    Assign each user from the department the Reader role at the subscription scope individually.

  2. B

    Create an Azure Active Directory (Azure AD) security group for the department and assign the built-in Reader role to that group at the subscription scope.

  3. C

    Configure a Conditional Access policy requiring multi-factor authentication (MFA) for the department's users to ensure read-only access.

  4. D

    Create a custom role with read-only permissions on VMs and assign it at the resource group level for each VM.

Show answer and explanation

Correct answer: B

Explanation

Using a built-in role (Reader) at the appropriate scope (subscription) and assigning it to an Azure AD security group is a best-practice solution. Azure role-based access control (RBAC) encourages managing permissions via groups to simplify administration. For further information, refer to the Microsoft documentation on role assignments and best practices for using Azure RBAC (https://learn.microsoft.com/azure/role-based-access-control/).

  • A. Incorrect.

    Option 1: Incorrect. While assigning the Reader role individually would work functionally, this approach is cumbersome to maintain. Each user must be added or removed manually, which can lead to errors or inconsistencies over time.

  • B. Correct.

    Option 2: Correct. Assigning the built-in Reader role to a dedicated Azure AD security group at the subscription scope is the recommended approach. It is easy to manage, as you can simply add or remove users from the group without changing role assignments. This aligns with Azure RBAC best practices of using groups wherever possible.

  • C. Incorrect.

    Option 3: Incorrect. Conditional Access policies requiring MFA are about authentication rather than Azure RBAC authorization. MFA improves security but does not by itself grant read-only access to resources or manage authorization policies.

  • D. Incorrect.

    Option 4: Incorrect. While creating a custom role is feasible if the built-in roles do not meet requirements, the built-in Reader role already provides the necessary read-only permissions. Assigning permissions at each resource group is also less efficient than doing so at the subscription level when you want consistent read access across all resources.

Timed practice exam

Take a AZ-305 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam