exam questions

Exam SC-300 All Questions

View all questions & answers for the SC-300 exam

Exam SC-300 topic 2 question 70 discussion

Actual exam question from Microsoft's SC-300
Question #: 70
Topic #: 2
[All SC-300 Questions]

HOTSPOT
-

You have an Azure subscription that contains the resources shown in the following table.



You need to configure access to Vault1. The solution must meet the following requirements:

• Ensure that User1 can manage and create keys in Vault1.
• Ensure that User2 can access a certificate stored in Vault1.
• Use the principle of least privilege.

Which role should you assign to each user? To answer select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Siraf
Highly Voted 10 months, 1 week ago
- Key Vault Crypto Officer - Key Vault Certificates Officer Key Vault Crypto Officer: Perform any action on the keys of a key vault, except manage permissions. Key Vault Certificates Officer: Perform any action on the certificates of a key vault, except manage permissions. Key Vault Secrets Officer: Perform any action on the secrets of a key vault, except manage permissions. Ref: https://learn.microsoft.com/en-us/azure/key-vault/general/rbac-guide?tabs=azure-cli.
upvoted 6 times
...
penatuna
Most Recent 1 year ago
Correct. Key Vault Certificates Officer DataActions: - Microsoft.KeyVault/vaults/certificates/* - Microsoft.KeyVault/vaults/certificates/* - Microsoft.KeyVault/vaults/certificatecontacts/write Key Vault Crypto Officer DataActions: - Microsoft.KeyVault/vaults/keys/* - Microsoft.KeyVault/vaults/keyrotationpolicies/* Key Vault Secrets Officer DataActions: - Microsoft.KeyVault/vaults/secrets/* https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#key-vault-certificates-officer https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#key-vault-crypto-officer https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#key-vault-secrets-officer
upvoted 3 times
...
JCkD4Ni3L
1 year ago
Correct
upvoted 1 times
...
AK_1234
1 year ago
- Key Vault Crypto Officer - Key Vault Certificates Officer
upvoted 2 times
...
Julesy
1 year ago
Looks good according to docs: https://learn.microsoft.com/en-us/azure/key-vault/general/rbac-guide#azure-built-in-roles-for-key-vault-data-plane-operations User1: manage and create keys in Vault1 - Key Vault Crypto Officer User2: access a certificate stored in Vault1 - Key Vault Certificates Officer
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago