Microsoft Azure Security Engineer Associate AZ-500 Practice Question
A security engineer must allow an external audit firm to inspect the configuration of every virtual machine in an Azure subscription. Auditors must be able to read networking, extension, and OS settings but must be blocked from cost data, resource changes, and secrets. Which single Azure built-in role should you assign at the subscription scope to meet these requirements with least privilege?
Reader at the subscription scope
Virtual Machine Reader at the subscription scope
Virtual Machine Contributor at the subscription scope
The Virtual Machine Reader built-in role grants read-only actions on Microsoft.Compute/virtualMachines and related resources such as network interfaces, disks, and extensions. It does not include Microsoft.CostManagement or Key Vault permissions and cannot modify resources. The Reader role can view most resource types, including cost data, which violates the requirement. The Security Reader role focuses on security information and lacks detailed VM configuration access. Virtual Machine Contributor allows create, update, and delete operations, exceeding the read-only need.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Can you explain what the Virtual Machine Reader role does in more detail?
Open an interactive chat with Bash
Why is the Reader role inappropriate for this scenario?
Open an interactive chat with Bash
How does the Virtual Machine Contributor role differ from the Virtual Machine Reader role?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure identity and access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .