Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft SC-500 Exam - Topic 2 Question 7 Discussion

You have an Azure subscription named Sub1 that contains a resource group named RG1.RG1 contains a virtual network named VNet1 and a storage account named storage1. Several engineers are assigned the Owner role for Sub1.You need to prevent updates to and deletions from VNet1. The solution must ensure that engineers can continue updating other resources in RG1.Which lock should you apply?
C) a Read-only resource lock at the VNet1 scope
A) a Read-only resource lock at the RG1 scope
B) a Delete resource lock at the RG1 scope
D) a Delete resource lock at the VNet1 scope

Microsoft SC-500 Exam - Topic 2 Question 7 Discussion

Actual exam question for Microsoft's SC-500 exam
Question #: 7
Topic #: 2
[All SC-500 Questions]

You have an Azure subscription named Sub1 that contains a resource group named RG1.

RG1 contains a virtual network named VNet1 and a storage account named storage1. Several engineers are assigned the Owner role for Sub1.

You need to prevent updates to and deletions from VNet1. The solution must ensure that engineers can continue updating other resources in RG1.

Which lock should you apply?

Show Suggested Answer Hide Answer
Suggested Answer: C

Apply a Read-only lock directly to VNet1. Azure management locks operate independently of Azure RBAC and override permissions such as Owner. A ReadOnly lock prevents authorized users from both updating and deleting the locked resource, which exactly satisfies the protection requirement for VNet1. Microsoft documents that a ReadOnly lock effectively restricts authorized users to read operations for the locked resource.

The lock must be scoped specifically to VNet1, not RG1. Locks applied at a parent scope are inherited by child resources. Therefore, applying ReadOnly to RG1 would also prevent modifications to storage1 and other resources in RG1, violating the requirement that engineers must remain able to update those resources.

A Delete lock is insufficient because CanNotDelete permits users to modify a resource while preventing only deletion. The question explicitly requires preventing updates and deletions, so ReadOnly is necessary.

This aligns with the SC-500 governance objective covering enforcement of security controls for Azure resources. The current study guide places governance and security-control enforcement under Manage identity, access, and governance.

===============


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel