Microsoft Azure Security Engineer Associate AZ-500 Practice Question

You have an Azure subscription that contains several resource groups used by different development teams. A new security policy requires that developers can perform these tasks in their own resource group only:

  • View any resource configuration, including private keys stored in Azure Key Vault.
  • Create or modify resources that do NOT expose data actions (for example, create a virtual network).

You decide to create a single custom Azure role and assign it at the developers' resource-group scope. Which set of JSON properties correctly meets the requirements?

  • Actions, DataActions, and AssignableScopes.

  • Actions and AssignableScopes only.

  • Actions, NotActions, and AssignableScopes.

  • Actions, DataActions, NotDataActions, and AssignableScopes.

Microsoft Azure Security Engineer Associate AZ-500
Secure identity and access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot