Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You clone the built-in Contributor role to create a custom role. The new role should allow operators to start and stop Azure virtual machines but must prevent them from deleting any VM. According to the Azure role definition schema for custom roles, what is the correct way to block the delete permission?
Remove the "Microsoft.Compute/virtualMachines/delete" operation from the Actions property inherited from Contributor.
Add the "Microsoft.Compute/virtualMachines/delete" operation to the NotActions property of the role definition.
Add the "Microsoft.Compute/virtualMachines/delete" operation to the DataActions property of the role definition.
Add the "Microsoft.Compute/virtualMachines/write" operation to the NotDataActions property of the role definition.
In an Azure custom role, the Actions array grants permissions, while the NotActions array explicitly excludes operations that would otherwise be allowed. Cloning the Contributor role includes broad permissions such as Microsoft.Compute/virtualMachines/delete by default. To keep all Contributor capabilities except VM deletion, list Microsoft.Compute/virtualMachines/delete in the NotActions property. Removing the operation from Actions is ineffective because inherited wildcard entries (such as Microsoft.Compute/*) still grant it. DataActions and NotDataActions apply only to data-plane operations, so they do not affect management-plane actions like VM deletion. Therefore, placing Microsoft.Compute/virtualMachines/delete in NotActions is the correct approach.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the difference between Actions and NotActions in Azure role definitions?
Open an interactive chat with Bash
What are the differences between management-plane and data-plane operations in Azure?
Open an interactive chat with Bash
Why is cloning a built-in role necessary for advanced custom role creation in Azure?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure identity and access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .