Microsoft Azure Administrator Associate AZ-104 Practice Question
You assign the Reader role to a user at the subscription scope in Azure. Which statement best describes the user's resulting access within that subscription?
The user has no access to any resource until a separate role assignment is made at the resource-group level.
The user can read resources only at the subscription level and not inside any resource groups.
The user gains permission to create, modify, and delete all resources in the subscription.
The user can read (but not modify) every resource in every resource group within the subscription.
In Azure RBAC, role assignments are hierarchical. An assignment at a parent scope (such as a subscription) is automatically inherited by all child scopes-every resource group and resource contained in the subscription. Because the Reader role is read-only, the user can view, but not modify, every resource in every resource group under that subscription. Assignments that add broader permissions (such as Contributor) must be made separately if write access is required.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Azure Role-Based Access Control (RBAC)?
Open an interactive chat with Bash
What are scopes in Azure RBAC?
Open an interactive chat with Bash
How can I manage permissions effectively in Azure?
Open an interactive chat with Bash
Microsoft Azure Administrator Associate AZ-104
Manage Azure identities and governance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access