exam questions

Exam AZ-303 All Questions

View all questions & answers for the AZ-303 exam

Exam AZ-303 topic 2 question 5 discussion

Actual exam question from Microsoft's AZ-303
Question #: 5
Topic #: 2
[All AZ-303 Questions]

HOTSPOT -
You have a hierarchy of management groups and Azure subscriptions as shown in the following table.

You create the Azure resources shown in the following table.

You have the Owner role. You assign roles to users as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: Yes -
You have assigned the role, so you can remove it.

Box 2: Yes -
Contributor role: Grants full access to manage all resources, but does not allow you to assign roles in Azure RBAC.

Box 3: No -
Reference:
https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#contributor

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
betamode
Highly Voted 4 years ago
Correct answer is N, Y, Y. First box is No because User1 didn't get contributor role on RG1 directly. It was given to user1 as an inheritance from Management Group1. An inherited permission can be revoked only at the level where it was granted (Management Group1 in this case). So, there is no way to revoke this permission from user1 except revoking it at Management group level. I've tried this in my lab and this is the error received - "Inherited role assignments cannot be removed. Open the scope where the role was assigned and remove it from there."
upvoted 93 times
Dileep75
3 years, 5 months ago
i agree with you
upvoted 2 times
...
rdemontis
3 years, 11 months ago
it's difficult to find official documentation to demonstrate this. So I've decided to reproduce the identical situation in azure and I confirm what you said! Correct answers are N Y Y
upvoted 16 times
...
rsamant
3 years, 4 months ago
Correct. Tested
upvoted 3 times
...
...
erickim007
Highly Voted 4 years ago
Answer should No: As owner, you cannot remove inherited RBAC permission assignment. Yes: Contributor can action on resources on subscription Yes: Even if we have inherited role assignment, as owner you can provide higher (i.e. contributor) role to user and process role assignment to children resource (i.e resource group).
upvoted 46 times
TSMRE
4 years ago
An answer like this was originally the highest rated on the post before it was removed, and is the answer I agree with
upvoted 7 times
...
...
rxlicon
Most Recent 1 year, 10 months ago
N - Inherited permission needs to be revoked at Management Group Y - Contributor role can delete VM Y- Owner can assign higher role than inherited
upvoted 1 times
...
rxlicon
1 year, 10 months ago
An inherited permission can be revoked only at the level where it was granted (Management Group1 in this case). "Inherited role assignments cannot be removed. Open the scope where the role was assigned and remove it from there."
upvoted 1 times
...
itvinoth83
3 years, 3 months ago
On Exam, 28-03-2022
upvoted 1 times
...
justfordevelopment
3 years, 3 months ago
In the exam on 12-03-2022. Total 50 questions including case study. "Litware Acquired Fabricam" case study.
upvoted 1 times
...
SamaTech
3 years, 4 months ago
For box 1: Inherited permission needs to be revoked at Management Group and can't be deleted but can't we explicitly deny User 1 access on this RG. This will overwrite the contributor access . And change the answer to Y. Any comments ?
upvoted 1 times
...
ElettroAle
3 years, 5 months ago
NYY, tested
upvoted 1 times
...
plmmsg
3 years, 6 months ago
The answer is No, Yes, Yes
upvoted 1 times
...
lorrenzo
3 years, 7 months ago
The answer is NYY. The first is N because you can block an inherited permission only if you remove it from the level where it was defined.
upvoted 1 times
...
Abhishek1950
3 years, 7 months ago
I would say No Yes Yes
upvoted 1 times
...
syu31svc
3 years, 10 months ago
I would say No Yes Yes 1. Contributor role for User1 is inherited from ManagementGroup1. So, we cannot remove at the resource group level. 2. User2 is contributor for RG2. So, User2 can delete the VM2 that is inside RG2. 3. You can add a role at resource level though user has different inherited access
upvoted 4 times
...
AZ_Apprentice
3 years, 11 months ago
If you see a message that inherited role assignments cannot be removed, you are trying to remove a role assignment at a child scope. You should open Access control (IAM) at the scope where the role was assigned and try again. A quick way to open Access control (IAM) at the correct scope is to look at the Scope column and click the link next to (Inherited). https://docs.microsoft.com/en-us/azure/role-based-access-control/role-assignments-remove
upvoted 1 times
...
hamzeh69
3 years, 11 months ago
Pass exam, come today in my exam 6/7/2021, answered NYY
upvoted 3 times
...
souvik123
3 years, 11 months ago
N - Inherited permission needs to be revoked at Management Group Y - Contributor role can delete VM Y- Owner can assign higher role than inherited
upvoted 1 times
...
shashu07
4 years ago
Yes, Yes, Yes 1. Yes : Going between the question its stats that " You have the Owner role. You assign roles to users as shown in the following table." owner assigned the role, so owner can remove it 2. Yes : Since user 2 is having Contributor 3. Yes : Being a owner, You can also assigned Contributor role
upvoted 2 times
GuyForget
3 years, 8 months ago
1. The role was assigned at the management group level, not on RG1. The owner could take their access away from the management group, but not an inherited resource (i.e. RG1).
upvoted 2 times
...
...
ChottoBhoot
4 years ago
The answer is N,Y,Y. Thats what I understood. 1) Inherited permission cannot be removed from the level which has inherited it from it's parent. 2) Contributor role on Management group, so yes, can delete VM 3) Azure says RBAC is additive , broader/higher access on parent level would be effective for all child, but a higher privilege in granular level/child level can overwrite parents least privilege. That means, Management Group has reader access for user A but we can assign User A contributor role in Subscription level and contributor would be effective role from Subscription and it's childs. Betamode is right I see.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...