Microsoft Azure Solutions Architect Expert AZ-305 Practice Question
Contoso has a pay-as-you-go Azure subscription named ContosoProd. A third-party operations team must be able to restart any existing virtual machine in ContosoProd for the next three months. The operations team must not be able to create, delete, or view other resources in the subscription, and their access must require manager approval each time it is used. You need to recommend a solution that meets the requirements while following the principle of least privilege. What should you recommend?
Create a system-assigned managed identity for the vendor and add it to the Reader role at the subscription scope.
Use Azure AD Privileged Identity Management to create an eligible assignment for a custom role that includes only the virtual machine restart action, scoped to the subscription, configured to expire in three months, and require approval for activation.
Apply a ReadOnly resource lock on all storage accounts in the subscription to prevent the vendor from accessing data.
Assign the built-in Virtual Machine Contributor role to the vendor's Azure AD group at the subscription scope.
Azure AD Privileged Identity Management (PIM) lets you make Azure role assignments eligible, define start and end dates, and require approval each time the role is activated. By creating a custom RBAC role that contains only the permission Microsoft.Compute/virtualMachines/restart/action and assigning it as an eligible role through PIM at the subscription scope, the operations team gains just the ability to restart any VM. The assignment can be set to expire after three months, and a manager can be configured as the approver for each activation. The built-in Virtual Machine Contributor role includes additional permissions such as create and delete, violating least-privilege. Resource locks govern resource state, not user permissions, and managed identities are intended for application authentication rather than external operators.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Azure AD Privileged Identity Management (PIM)?
Open an interactive chat with Bash
What is a custom RBAC role in Azure?
Open an interactive chat with Bash
How does the principle of least privilege work in Azure?
Open an interactive chat with Bash
Microsoft Azure Solutions Architect Expert AZ-305
Design identity, governance, and monitoring solutions
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .