Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You administer an Azure Container Registry (ACR) named contosoacr that holds several image repositories, including one named dev. An on-premises build server must be able to pull images from the dev repository only and must not be able to list or access any other repositories in the registry. You also want to issue short-lived credentials that are independent of Azure Active Directory. What should you do?
Create a scope map that grants content/read on the dev repository, generate an ACR token associated with the scope map, and supply the token's password to the build server.
Enable anonymous pull on contosoacr and use an Azure Storage firewall rule to restrict access to the dev repository path.
Enable the admin user for contosoacr and share the admin username and password with the build server.
Assign the built-in Azure role AcrPull to the build server's service principal at the registry scope.
ACR tokens let you create repository-scoped, non-Azure-AD credentials. By first defining a scope map that grants only the content/read (pull) action on the dev repository and then creating a token linked to that scope map, you obtain a username/password pair that is limited to that repository. The credentials can be regenerated or revoked at any time, providing the desired short-lived access. Assigning the AcrPull role at registry scope or enabling the admin user would grant access to every repository. Anonymous pull cannot be restricted to a single repository and does not meet the security goal.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a scope map in Azure Container Registry?
Open an interactive chat with Bash
What is an ACR token, and how is it used?
Open an interactive chat with Bash
Why can't anonymous pull or admin access be used for this scenario?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .