HOTSPOT - Which virtual networks in Sub1 can User9 modify and delete in their current state? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Hot Area:
Suggested Answer:
Box 1: VNET4 and VNET1 only - RG1 has only Delete lock, while there are no locks on RG4. RG2 and RG3 both have Read-only locks.
Box 2: VNET4 only - There are no locks on RG4, while the other resource groups have either Delete or Read-only locks. Note: As an administrator, you may need to lock a subscription, resource group, or resource to prevent other users in your organization from accidentally deleting or modifying critical resources. You can set the lock level to CanNotDelete or ReadOnly. In the portal, the locks are called Delete and Read-only respectively. ✑ CanNotDelete means authorized users can still read and modify a resource, but they can't delete the resource. ✑ ReadOnly means authorized users can read a resource, but they can't delete or update the resource. Applying this lock is similar to restricting all authorized users to the permissions granted by the Reader role. Scenario: Sub1 contains six resource groups named RG1, RG2, RG3, RG4, RG5, and RG6. User9 creates the virtual networks shown in the following table. Sub1 contains the locks shown in the following table. Reference: https://docs.microsoft.com/en-us/azure/azure-resource-manager/resource-group-lock-resources
I think that is a typo error, because
lock3 and 4 can't be assigned simultaneously.
two different lock types cannot be assigned to a single resource group simultaneously. Azure resource locks allow only one type of lock to be applied to a resource or resource group at a time. You can choose either:
CanNotDelete lock: Authorized users can read and modify the resource, but cannot delete it.
ReadOnly lock: Authorized users can only read the resource, but cannot modify or delete it.
This question appeared in Feb 2024 exam, there were 6 sub questions based on given case study, however here only 1 question is asked. It is only of the 6 questions that was asked.
1. VNET4 and VNET1 only
2. VNET4 only
https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/lock-resources?tabs=json
- CanNotDelete means authorized users can read and modify a resource, but they can't delete it.
- ReadOnly means authorized users can read a resource, but they can't delete or update it. Applying this lock is similar to restricting all authorized users to the permissions that the Reader role provides.
We don't know the scope of role assignment for User9. Owner role should be assigned to. He/She was able to create VNET2 and VNET3 on Read-only subscriptions! So he probably God and can do impossible tasks. How we can judge such users? If he able to create, lets assume that he will be able to change...
Answers are correct.
RG1: delete lock
RG2: read only lock
RG3: read only + delete locks
RG4: no lock
So
Answer: You can only modify 1 and 4 only.
A: You can only delete VNet4 only because it is the only one with no attached VMs and in a RG with no lock.
box 1 is incorrect. Vnet4 can be modifies since there is no lock applied to the RG4. There is a Delete lock on RG1 and 3 which makes them editable. Therefore, the correct answer is Vnet1,3 and 4
He meant for box1 - vnet 1 and 3 and box2 - vnet 4
upvoted 1 times
...
...
...
This section is not available anymore. Please use the main Exam Page.AZ-500 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
dadageer
Highly Voted 3 years, 11 months agodiirn
Highly Voted 3 years, 10 months agomacco455
3 years, 10 months agoITFranz
5 months, 1 week agondv4461
Most Recent 11 months, 3 weeks agoTheProfessor
1 year, 4 months agozellck
1 year, 9 months agomajstor86
1 year, 11 months agokoreshio
2 years, 3 months agoDiallo18
2 years, 3 months agoTonytheTiger
3 years, 4 months agokakakayayaya
3 years, 5 months agochikorita
1 year, 11 months agosinslam
3 years, 6 months agothienvupt
3 years, 7 months agoMarioMK
3 years, 8 months agoCustodian
2 years, 7 months ago3abmula
3 years, 8 months agow00t
3 years, 5 months ago