exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 2 question 94 discussion

Actual exam question from Microsoft's AZ-500
Question #: 94
Topic #: 2
[All AZ-500 Questions]

You have an Azure subscription that is linked to an Azure AD tenant and contains the resources shown in the following table.



Which resources can be assigned the Contributor role for VM1?

  • A. Managed1 and App1 only
  • B. Group1 and Managed1 only
  • C. Group1, Managed1, and VM2 only
  • D. Group1, Managed1, VM1, and App1 only
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
973b658
Highly Voted 2 years ago
D. https://learn.microsoft.com/en-us/azure/role-based-access-control/role-assignments-steps "You can assign a role to a user, group, service principal, or managed identity. " App1 has service principal. https://learn.microsoft.com/en-us/azure/active-directory/develop/howto-create-service-principal-portal
upvoted 15 times
basak
1 year, 10 months ago
Tested. D is correct.
upvoted 3 times
...
liorh
2 years ago
looks correct to me
upvoted 1 times
...
Franc_Coetzee
2 years ago
The keyword for the Group is "Dynamic", once you make any group a dynamic group, the option to assign roles to it becomes grayed out.
upvoted 12 times
pentium75
11 months ago
"Role-assignable groups" are about Azure AD roles, not Azure RBAC roles.
upvoted 1 times
...
bxlin
1 year, 1 month ago
that is not true. you can assign role to a dynamic group
upvoted 1 times
...
...
...
OrangeSG
Highly Voted 1 year, 8 months ago
Selected Answer: A
The Contributor role can be assigned to any Azure resource, including users, groups, service principals, and managed identities. • Group1 is a dynamic device security group in Azure AD. Dynamic groups are not role-assignable, so Group1 cannot be assigned the Contributor role for VM1. • Managed1 is a managed identity. Managed identities can be assigned the Contributor role for VM1. • VM1 is a virtual machine. Virtual machines can be assigned the Contributor role for themselves. • App1 is an enterprise application in Azure AD. Enterprise applications can be assigned the Contributor role for VM1. Therefore, the only resources that can be assigned the Contributor role for VM1 are Managed1, VM1, and App1.
upvoted 10 times
...
cuongdo1793
Most Recent 1 month ago
Selected Answer: A
❌ Why D. Group1, Managed1, VM1, and App1 only is incorrect: Group1 is a dynamic device group, which can't be used as a principal in RBAC role assignment. VM1 is a resource, not a principal you assign roles to — it's the target of the role assignment. A. Managed1 and App1 only is still the correct choice.
upvoted 1 times
...
JBAnalyst
6 months, 2 weeks ago
Selected Answer: A
You can’t assign RBAC to a “dynamic” group type which is what group 1 is All answers that have group 1 is automatically wrong https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/groups-concept
upvoted 2 times
...
8de3321
7 months ago
Selected Answer: D
I wish this website gave answers instead of making people fight over the options and confuse people trying to write the exam. I paid for this service and this is what I am presented with. What is this exam, if people cannot find the proper answer on the Microsoft website even with access and then expects people to do it under time pressure with very minimal access? This is insane. If this was the exam I would choose option D or something because I don't think Microsoft would make the question too easy to find with the method of elimination.
upvoted 3 times
...
fenth7
7 months ago
Selected Answer: D
d is correct
upvoted 2 times
...
pentium75
11 months ago
Selected Answer: D
This is about an Azure RBAC role, not an Entra ID role. Thus everything, except for VM2 which doesn't have a managed identity, can get it assigned.
upvoted 2 times
...
ACSC
1 year, 3 months ago
Selected Answer: D
Tested for user, group, VM and App. All of them can be assigned Contributor role for VM.
upvoted 2 times
...
cris_exam
1 year, 5 months ago
This question is weird, because it should have a choice for: Managed ID, App1 and VM. Dynamic Entra Sec Groups cannot have roles assigned, all the other can have. The closet answer to truth is A.
upvoted 1 times
...
[Removed]
1 year, 6 months ago
Difference between Azure AD roles and Azure RBAC is as follows: RBAC can have a User, group, or service principal, Managed identity (group nesting is allowed and the group can dynamic as well Azure AD roles only users and groups (group nesting is not allowed as soon as you enable entra roles can be enabled the membership type greys out to assign and group nesting is not allowed. Here contributor is a RBAC role not azure ad role
upvoted 1 times
...
WilianCArias
1 year, 6 months ago
D. https://learn.microsoft.com/en-us/azure/role-based-access-control/role-assignments-steps "You can assign a role to a user, group, service principal, or managed identity. "
upvoted 2 times
...
ManiMessner
1 year, 7 months ago
Selected Answer: D
Tested, D is correct
upvoted 4 times
...
rosef
1 year, 7 months ago
Selected Answer: A
Tested. When creating a group, if you choose dynamic user "Microsoft Entra roles can be assigned to the group" option turns to NO automatically. So when you eliminate group1, answer is A.
upvoted 3 times
xRiot007
11 months, 2 weeks ago
Microsoft Entra roles and RBAC roles are 2 different things.
upvoted 2 times
...
...
wardy1983
1 year, 7 months ago
Answer: D Explanation: Confirmed in my lab. I think VM1 in D should change to VM2 though.
upvoted 1 times
...
ErikPJordan
1 year, 9 months ago
Selected Answer: A
Correct answer is A
upvoted 1 times
...
InnoMaf
1 year, 9 months ago
Correct answer is A role-assignable groups is limited to AD Azure roles https://learn.microsoft.com/en-us/azure/active-directory/roles/groups-concept#restrictions-for-role-assignable-groups
upvoted 2 times
pentium75
11 months ago
"Role-assignable groups" are about Entra roles, not Azure roles.
upvoted 1 times
...
...
vcloudpmp
1 year, 10 months ago
https://learn.microsoft.com/en-us/azure/active-directory/roles/groups-concept Only Global Administrators and Privileged Role Administrators can create a role-assignable group. The membership type for role-assignable groups must be Assigned and can't be an Azure AD dynamic group.Automated population of dynamic groups could lead to an unwanted account being added to the group and thus assigned to the role.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...