PrepAway - Latest Free Exam Questions & Answers

Which role should you assign to each account?

HOTSPOT
You are implementing Azure Role-Based Control (RBAC).
You need to create two new administrator accounts. The accounts must meet the following requirements:
Admin1 must be able to manage only the storage accounts that are used by virtual machines (VMs) and other
resources.
Admin2 must be able to manage and delete resources in the Recovery Services vault.
Which role should you assign to each account? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

PrepAway - Latest Free Exam Questions & Answers

Answer:

Explanation:
Box 1: Storage Account Contributor
A Storage Account Contributor can manage storage accounts, but not access to them.
Incorrect Answers:
Not Data Factory Contributor: Can create and manage data factories, and child resources within them.
Not Virtual Machine Contributor: Can manage virtual machines, but not the virtual network or storage account
to which they are connected.
Box 2: Backup Contributor
A Backup Contributor can manage all backup management actions, except creating Recovery Services vault
and giving access to others.
Incorrect Answers:
Not Automation Operator: Able to start, stop, suspend, and resume jobs.
Not BackupOperator: Can manage backup except removing backup, in Recovery Services vault.
https://docs.microsoft.com/en-us/azure/active-directory/role-based-access-built-in-roles

2 Comments on “Which role should you assign to each account?

  1. Allen says:

    admin1: storage account contributor
    admin2: backup operator

    Backup Contributor Can manage all backup management actions, except creating Recovery Services vault and giving access to others

    Backup Operator Can manage all backup management actions except creating vaults, removing backup and giving access to others




    0



    11
  2. Byronis says:

    Answer Correct
    admin1: storage account contributor
    admin2: backup contributor

    Backup Operator – This role has permissions to everything a contributor does *except* removing backup and managing backup policies. This role is equivalent to contributor except it can’t perform destructive operations such as stop backup with delete data or remove registration of on-premises resources.




    0



    0

Leave a Reply