To allow User1 to deploy virtual machines and manage virtual networks while following the principle of least privilege, which RBAC role should you assign?
Choose an answer
Tap an option to check your answer.
Correct answer: Contributor.
Why this is the answer
The Contributor role grants full access to manage all resources, but does not allow assigning roles in Azure RBAC, aligning with the principle of least privilege for managing VMs and virtual networks. The Owner role provides full access to manage all resources, including the ability to assign roles, which violates the principle of least privilege if User1 only needs to deploy VMs and manage networks. The Virtual Machine Contributor role is too restrictive as it only allows managing virtual machines, not virtual networks. The Virtual Machine Administrator Login role is specifically for logging into Azure virtual machines as an administrator, not for deploying or managing network resources.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed