New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft AZ-500 Exam - Topic 4 Question 86 Discussion

Actual exam question for Microsoft's AZ-500 exam
Question #: 86
Topic #: 4
[All AZ-500 Questions]

You have an Azure subscription that contains the resources shown in the following table.

You need to ensure that ServerAdmins can perform the following tasks:

Create virtual machine to the existing virtual network in RG2 only.

The solution must use the principle of least privilege.

Which two role-based access control (RBAC) roles should you assign to ServerAdmins? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer: D, F

Contribute your Thoughts:

0/2000 characters
Verda
2 months ago
A custom role? Not sure if that's necessary...
upvoted 0 times
...
Marnie
2 months ago
I agree, least privilege is key here!
upvoted 0 times
...
Serina
3 months ago
Wait, why would you give them the Contributor role for the subscription? Seems too broad.
upvoted 0 times
...
Christiane
3 months ago
Definitely need the Network Contributor role for RG2!
upvoted 0 times
...
Kayleigh
3 months ago
I think a custom RBAC role for RG2 makes sense too.
upvoted 0 times
...
Avery
3 months ago
I’m a bit confused about whether we should use the Virtual Machine Contributor role for RG1 or RG2. I need to double-check that.
upvoted 0 times
...
Aileen
4 months ago
I practiced a similar question where we had to assign roles based on least privilege. I think a custom RBAC role might be necessary here.
upvoted 0 times
...
Denae
4 months ago
I feel like the Network Contributor role for RG2 could be part of the solution, but I'm not sure about the second role we need.
upvoted 0 times
...
Ma
4 months ago
I remember that the Contributor role gives broad permissions, but I think we need to limit access to RG2 specifically.
upvoted 0 times
...
Serina
4 months ago
I feel confident I can solve this. The question is clear about the tasks the ServerAdmins need to perform, and the principle of least privilege, so I think the answer is the Network Contributor role for RG2 and a custom RBAC role for RG2.
upvoted 0 times
...
Nobuko
4 months ago
I've got a strategy in mind. Since the requirement is to create VMs in the existing virtual network in RG2, the Network Contributor role for RG2 should be one of the answers. Now I just need to figure out the other role.
upvoted 0 times
...
Ronna
5 months ago
I'm a bit confused about the difference between the Contributor role and the custom RBAC roles. I'll need to research the specific permissions of each to make the best choice.
upvoted 0 times
...
Marvel
5 months ago
Okay, let's think this through step-by-step. The key is to use the principle of least privilege, so we need to identify the minimum permissions required for the ServerAdmins to perform the specified tasks.
upvoted 0 times
...
Wade
5 months ago
Hmm, this seems like a tricky one. I'll need to carefully review the resource information and the required tasks to determine the appropriate RBAC roles.
upvoted 0 times
...
Dylan
7 months ago
Man, these Azure role assignments can get pretty complicated. Good thing we have the principle of least privilege to guide us. B and D it is!
upvoted 0 times
Justine
5 months ago
I think B and D are the correct choices for this scenario.
upvoted 0 times
...
...
Fannie
7 months ago
That makes sense, we should only give ServerAdmins the necessary permissions for their tasks.
upvoted 0 times
...
Clement
7 months ago
I believe we should create a custom RBAC role for RG2 to ensure least privilege.
upvoted 0 times
...
Jimmie
7 months ago
Haha, I bet the exam writers are trying to trick us with all these options. But B and D are the obvious picks here.
upvoted 0 times
...
Dana
7 months ago
I agree, B and D are the correct choices. The question clearly states the requirement is to use the principle of least privilege.
upvoted 0 times
Rosann
7 months ago
Great, so we both agree on the solution. It's important to follow the principle of least privilege in these scenarios.
upvoted 0 times
...
Sunshine
7 months ago
Yes, I agree. Those roles will ensure the ServerAdmins have the necessary permissions without granting unnecessary access.
upvoted 0 times
...
Xuan
7 months ago
I think B and D are the right choices.
upvoted 0 times
...
...
Isidra
8 months ago
B and D seem like the way to go. We need to give the ServerAdmins the least privilege to create VMs in RG2 specifically.
upvoted 0 times
Dallas
7 months ago
Yes, giving ServerAdmins only the Network Contributor role for RG2 and a custom RBAC role for RG2 ensures they have the least privilege to create VMs in that resource group.
upvoted 0 times
...
Catarina
7 months ago
I agree, B and D are the correct choices for this scenario.
upvoted 0 times
...
...
Nikita
8 months ago
I agree with Fannie, but we also need to consider if any custom RBAC roles are needed.
upvoted 0 times
...
Fannie
8 months ago
I think we should assign the Network Contributor role for RG2 to ServerAdmins.
upvoted 0 times
...

Save Cancel