You are building a Java app that uses Cassandra (via the Cassandra API) on a new Azure Cosmos DB resource. You create an Azure AD group named Cosmos DB Creators to allow provisioning of Cosmos DB accounts, databases, and containers, but members must not be able to access the database keys. Which RBAC role should you assign to restrict the group's access appropriately?
Choose an answer
Tap an option to check your answer.
Correct answer: Cosmos DB Operator.
Why this is the answer
The Cosmos DB Operator role is correct because it allows members to provision Azure Cosmos DB accounts, databases, and containers, which aligns with the requirement for the Cosmos DB Creators group. Critically, this role does not grant access to the database keys or data, thus preventing members from accessing the database keys. The DocumentDB Accounts Contributor role provides full access to manage Cosmos DB accounts, including keys, which violates the "must not be able to access the database keys" requirement. Cosmos Backup Operator is for backup and restore operations, not provisioning. Cosmos DB Account Reader only allows viewing account properties, not creating resources.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed