Microsoft Azure Solutions Architect Expert AZ-305 Practice Question

Your company runs several Azure subscriptions that host production App Service web apps. A group of support engineers must be able to restart any web app during an incident. They must not have permissions to change configuration or deploy code. Access must be requested on demand, limited to two hours per activation, and all activations must be auditable. Which authorization approach should you recommend?

  • Generate a user-delegation SAS token for each web app's deployment slot and give the tokens to the support engineers.

  • Create and assign an Azure Policy initiative that allows the Restart action on App Service resources.

  • Create a custom Azure RBAC role that contains only the restart and stop actions for Microsoft.Web sites and assign it to the support engineers as an eligible assignment by using Azure AD Privileged Identity Management with a two-hour maximum activation.

  • Permanently assign the built-in Website Contributor role to the support engineers at the subscription scope.

Microsoft Azure Solutions Architect Expert AZ-305
Design identity, governance, and monitoring solutions
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot