Free Microsoft AZ-104 Exam Braindumps (page: 21)

You have an Azure subscription named Subscription1 that contains a virtual network named VNet1. VNet1 is in a resource group named RG1.
Subscription1 has a user named User1. User1 has the following roles: Reader
Security Admin Security Reader
You need to ensure that User1 can assign the Reader role for VNet1 to other users. What should you do?

  1. Remove User1 from the Security Reader role for Subscription1. Assign User1 the Contributor role for RG1.
  2. Assign User1 the Access Administrator role for VNet1.
  3. Remove User1 from the Security Reader and Reader roles for Subscription1. Assign User1 the Contributor role for Subscription1.
  4. Assign User1 the Network Contributor role for RG1.

Answer(s): B

Explanation:

The User Access Administrator role enables the user to grant other users access to Azure resources.
Note:
There are several versions of this question in the exam. The question has three possible correct answers:
* Assign User1 the Access Administrator role for VNet1.
* Assign User1 the User Access Administrator role for VNet1.
Assign User1 the Owner role for VNet1.
Other incorrect answer options you may see on the exam include the following:
* Assign User1 the Contributor role for VNet1.
* Remove User1 from the Security Reader and Reader roles for Subscription1. Assign User1 the Contributor role for Subscription1.
Remove User1 from the Security Reader role for Subscription1. Assign User1 the Contributor role for RG1.


Reference:

https://docs.microsoft.com/en-us/azure/role-based-access-control/overview https://learn.microsoft.com/en-us/azure/role-based-access-control/rbac-and-directory-admin-roles



HOTSPOT (Drag and Drop is not supported)
You have three Azure subscriptions named Sub1, Sub2, and Sub3 that are linked to a Microsoft Entra tenant.
The tenant contains a user named User1, a security group named Group1, and a management group named MG1. User1 is a member of Group1.
Sub1 and Sub2 are members of MG1. Sub1 contains a resource group named RG1. RG1 contains five Azure functions.
You create the following role assignments for MG1: Group1: Reader
User1: User Access Administrator
You assign User1 the Virtual Machine Contributor role for Sub1 and Sub2. You assign User1 the Contributor role for RG1.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:



Box 1: Yes
The RG1 Resource Group contains five Azure functions.
The Management Group MG1 contains the role assignment: Group1 is Reader for RG1.
The Reader role is an Azure Resource Manager role that permits users to view storage account resources, but not modify them. It does not provide read permissions to data in Azure Storage, but only to account management resources.
Box 2: Yes
The Management Group MG1 contains the role assignment User1: User Access Administrator Sub1 is a member of MG1.
Sub1 contains a resource group named RG1.
The User Access Administrator role enables the user to grant other users access to Azure resources. This switch can be helpful to regain access to a subscription.
You can use User Access Administrator role to give another user the Owner role in the subscription. Box 3: No
User Access Administrator only lets you manage user access to Azure resource


Reference:

https://learn.microsoft.com/en-us/azure/role-based-access-control/rbac-and-directory-admin-roles https://learn.microsoft.com/en-us/azure/role-based-access-control/role-assignments-portal-subscription-admin



You have an Azure subscription that contains the resources shown in the following table.


You need to assign User1 the Storage File Data SMB Share Contributor role for share1. What should you do first?

  1. Enable identity-based data access for the file shares in storage1.
  2. Modify the security profile for the file shares in storage1.
  3. Select Default to Microsoft Entra authorization in the Azure portal for storage1.
  4. Configure Access control (IAM) for share1.

Answer(s): A



You have an Azure subscription named Subscription1 that contains a virtual network named VNet1. VNet1 is in a resource group named RG1.
Subscription1 has a user named User1. User1 has the following roles: Reader
Security Admin Security Reader
You need to ensure that User1 can assign the Reader role for VNet1 to other users. What should you do?

  1. Remove User1 from the Security Reader role for Subscription1. Assign User1 the Contributor role for RG1.
  2. Assign User1 the User Access Administrator role for VNet1.
  3. Remove User1 from the Security Reader and Reader roles for Subscription1.
  4. Assign User1 the Contributor role for VNet1.

Answer(s): B

Explanation:

The User Access Administrator role enables the user to grant other users access to Azure resources.
Note:
There are several versions of this question in the exam. The question has three possible correct answers:
* Assign User1 the Access Administrator role for VNet1.
* Assign User1 the User Access Administrator role for VNet1.
Assign User1 the Owner role for VNet1.
Other incorrect answer options you may see on the exam include the following:
* Assign User1 the Contributor role for VNet1.
* Remove User1 from the Security Reader and Reader roles for Subscription1. Assign User1 the Contributor role for Subscription1.
Remove User1 from the Security Reader role for Subscription1. Assign User1 the Contributor role for RG1.


Reference:

https://docs.microsoft.com/en-us/azure/role-based-access-control/overview https://learn.microsoft.com/en-us/azure/role-based-access-control/rbac-and-directory-admin-roles



Viewing page 21 of 137
Viewing questions 81 - 84 out of 553 questions



Post your Comments and Discuss Microsoft AZ-104 exam prep with other Community members:

AZ-104 Exam Discussions & Posts