An organization assigns a newly hired auditor the built-in Reader role at the subscription scope. The auditor needs to verify access and compliance settings across all resource groups. Which of the following capabilities will the auditor have? (Select two.)
- View the configurations of all virtual machines and storage accounts in the subscription.Answer
- View which users, groups, and service principals have access permissions assigned to resources.Answer
- CEnforce a restriction that prevents users from deploying virtual machines in unauthorized regions.
- DAssign the Reader role to other team members who join the audit project.
Answer
The auditor can view the configurations of all virtual machines and storage accounts in the subscription, and they can view which users, groups, and service principals have access permissions assigned to resources.
The built-in Reader role allows users to view all resources within the scope of the assignment and read their properties, configurations, and the access control settings (IAM) showing who has role assignments on those resources.
Step-by-Step Solution
Key Concept
Azure Role-Based Access Control (RBAC)
Estimated Time:1m 30s