Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You manage an Azure virtual machine scale set (VMSS) that must read data from an Azure Storage account by using Azure role-based access control (Azure RBAC). The VMSS will be deleted and recreated during automated test cycles, but you need the identity that has the Storage Data Reader role assignment to persist across these cycles without having to recreate the role assignment each time. Which approach should you take?
Enable a system-assigned managed identity on the VMSS and grant that identity the Storage Blob Data Reader role.
Create a user-assigned managed identity, grant it the Storage Blob Data Reader role on the storage account, and associate the identity with the VMSS.
Generate a service principal with a client secret, store the secret on the VMSS, and assign the Storage Blob Data Reader role to the service principal.
Use the storage account access keys and store them in the VMSS as environment variables.
A user-assigned managed identity is created as an independent Azure resource. You can attach the same identity to one or more compute resources, and its lifetime is not tied to any individual resource. Therefore, if the VMSS is deleted, the identity and its role assignment (Storage Blob Data Reader) remain, and reattaching the identity after the VMSS is recreated immediately restores access.
In contrast, a system-assigned managed identity is automatically created inside the VMSS resource and is deleted when the VMSS is deleted, so its role assignment would need to be recreated. Service principals that use client secrets or embedding storage account access keys do not satisfy the requirement because they either require secret management or bypass managed identity entirely.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a user-assigned managed identity?
Open an interactive chat with Bash
Why is a system-assigned managed identity not suitable in this scenario?
Open an interactive chat with Bash
What is the Storage Blob Data Reader role in Azure RBAC?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure identity and access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .