ServerAdmins must be allowed to create virtual machines only in resource group RG1 and to connect those VMs to existing virtual networks only in resource group RG2. Using least privilege, which two RBAC role assignments satisfy these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: A custom RBAC role scoped to RG2, Virtual Machine Contributor role for RG1.
Why this is the answer
The Virtual Machine Contributor role for RG1 allows ServerAdmins to create and manage virtual machines within RG1, satisfying the first requirement. This role adheres to the principle of least privilege by limiting VM creation to the specified resource group. A custom RBAC role scoped to RG2 is necessary because the built-in Network Contributor role would grant broader permissions than needed, potentially allowing network modifications beyond just connecting VMs. A custom role can be crafted to specifically allow connecting VMs to existing virtual networks within RG2, fulfilling the second requirement with least privilege. The Contributor role at the subscription scope is too permissive, granting unnecessary access across the entire subscription. The Network Contributor role for RG1 is incorrect as network connections are restricted to RG2.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed