All practice questions
14 questions
Arrange the levels of the Azure resource hierarchy in order from the highest scope (broadest access) to the lowest scope (most granular access).
Drag items to arrange them in the correct order
You are designing a subscription governance and delegated administration solution for a new Azure landing zone. The solution must meet the following requirements:
- Establish a new management boundary for a dedicated business unit.
- Implement a custom Azure RBAC role named 'Resource Lock Manager' that allows managing resource locks but prevents deletion of any resources. This role must only be assignable within this new management boundary.
- Ensure that the operations team members can only active this role on-demand to align with the principle of least privilege.
- Use a Microsoft Entra ID group to minimize direct role assignments to individual users.
Which sequence of configuration steps should you perform to implement the solution?
Drag items to arrange them in the correct order
An organization is designing a subscription governance model to allow network security administrators to manage network security rules across multiple subscriptions. To follow the principle of least privilege, the administrators must only be able to elevate their access on-demand using Just-In-Time (JIT) access. You need to configure this administrative model. In which order should you perform the configuration steps?
Drag items to arrange them in the correct order
An enterprise is implementing a subscription governance strategy. You need to create a custom Azure RBAC role named 'VM Operator' that allows users to manage virtual machines but prevents them from modifying associated virtual networks. The role must be assignable across all subscriptions in a specific Management Group named 'Production-MG'.
Which sequence of steps should you perform to define, create, and assign this custom RBAC role?
Drag items to arrange them in the correct order
Your company is designing a governance solution for a multi-subscription Azure environment. A security team requires a custom RBAC role named 'Network Security Operator' to manage network security groups (NSGs) across all subscriptions in a specific department. These subscriptions are organized under a single department-level management group. You need to implement the custom role following the principle of least privilege. What is the correct sequence of steps to configure and assign this custom role?
Drag items to arrange them in the correct order
An organization is establishing a new governance model for their Azure environment. They need to delegate administrative permissions for managing virtual networks to a network operations team while adhering to the principle of least privilege. You need to configure a custom RBAC role and a new Management Group structure. Arrange the steps in the correct order to configure and delegate these permissions, starting with establishing the scope boundary and ending with granting user access.
Drag items to arrange them in the correct order
Your company has an Azure subscription containing multiple development environments. You need to delegate the management of virtual machines to a development operations team. The team must be able to perform all virtual machine operations except deleting virtual machines. The delegation must follow the principle of least privilege, apply only to the development subscription, and be assigned to a Microsoft Entra ID security group. You decide to create a custom RBAC role to meet these requirements.
In which order should you perform the steps to configure and apply the custom role?
Drag items to arrange them in the correct order
An organization wants to delegate custom permissions to a development team. The team needs the ability to restart and manage virtual machines across all subscriptions nested under the 'R&D' management group. You must design a custom role that permits virtual machine management operations but explicitly prevents virtual network configuration modifications. The custom role must be scope-constrained so it can only be assigned to subscriptions under the 'R&D' management group. You need to create this custom role and assign it to the development team's Microsoft Entra ID group. Which sequence of actions should you perform?
Drag items to arrange them in the correct order
An enterprise is designing a subscription governance model to manage resources across multiple departments. You need to implement a management group hierarchy and delegate resource access using a custom Azure RBAC role. The solution must ensure that administrative access is inherited across all department subscriptions and adheres to the principle of least privilege.
Which sequence of steps should you perform?
Drag items to arrange them in the correct order
You are designing the resource hierarchy for a new department in Azure to ensure proper subscription governance. You need to organize the resources from the top-level management structure down to the individual resources in the correct logical order according to Azure's resource hierarchy. Order the steps required to establish this hierarchy and deploy the resources.
Drag items to arrange them in the correct order
Your organization has an Azure management group hierarchy consisting of a root management group and several child management groups. You are designing a governance strategy and need to implement a custom Azure RBAC role named 'Billing Reader Custom' for a specific child management group named 'Finance-MG'. The role must be assignable only within 'Finance-MG' and its descendants. You need to create this custom role and assign it to a Microsoft Entra security group named 'Finance Auditors' for a specific subscription under 'Finance-MG'. Which sequence of steps should you perform to create and assign the custom role?
Drag items to arrange them in the correct order
An enterprise plans to integrate a newly acquired subsidiary's standalone Azure subscription into its corporate Management Group structure under a single Microsoft Entra tenant.
The corporate architecture team defines the following requirements:
- A custom Azure RBAC role named 'FinancialAuditor' must be created for the subsidiary's audit team.
- The 'FinancialAuditor' role must only be assignable within the '/providers/Microsoft.Management/managementGroups/Corp-Finance-MG' Management Group hierarchy.
- The subsidiary's subscription must be moved under 'Corp-Finance-MG' and inherit all governance controls.
- To maintain security best practices, direct RBAC assignments to individual user accounts are prohibited.
You need to configure the subscription transition and access controls.
Arrange the steps in the correct logical sequence to meet the requirements.
Drag items to arrange them in the correct order
A retail company plans to reorganize its Azure subscription governance. You are designing a strategy to delegate subscription-level billing and resource group management permissions using a custom Azure RBAC role. The custom role must be applied across multiple new subscriptions that will be grouped under a new management group hierarchy. You need to recommend the correct sequence of steps to implement this strategy while ensuring that administrators have immediate, inherited access to the subscriptions as soon as they are governed by the new hierarchy, and that no invalid scope references are created. Which sequence of actions should you recommend?
Drag items to arrange them in the correct order
Your company is designing a delegated administration model for a team of database administrators (DBAs) who manage resources across multiple Azure subscriptions. The DBAs require temporary, time-bound permissions to manage Azure SQL databases within a specific subset of subscriptions, adhering to the principle of least privilege.
You plan to implement a custom Azure RBAC role and delegate it using Microsoft Entra Privileged Identity Management (PIM) for Groups.
Which sequence of steps should you perform to implement this governance solution?
Drag items to arrange them in the correct order