In a private Azure DevOps project, a project manager needs permission to create custom work item queries for reporting while following the principle of least privilege. To which security group should you add the project manager?
Choose an answer
Tap an option to check your answer.
Correct answer: Contributor.
Why this is the answer
The Contributor group provides the necessary permissions to create and manage custom work item queries, which is essential for reporting, without granting excessive privileges. This aligns with the principle of least privilege. The Reader group has read-only access and cannot create or modify queries. Project Collection Administrators have the highest level of permissions across all projects in the collection, far exceeding what's needed for this task. Project Administrators have broad administrative control over a single project, including managing permissions and project settings, but the Contributor role is sufficient and more aligned with least privilege for query creation.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed