Courseiva
Implement and Manage StorageeasyMultiple ChoiceObjective-mapped

AZ-104 Implement and Manage Storage Practice Question

A help desk engineer must be able to start, stop, and resize only VM-App01. The engineer must not gain access to any other virtual machines or resource groups in the subscription. What scope should you use for the Azure RBAC role assignment?

⚠ Common exam trap

It's easy for candidates to default to resource group scope thinking it is granular enough, but they overlook that resource group scope grants access to all resources within that group, not just the single VM.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Assign the role at the virtual machine scope for VM-App01 only.

Azure RBAC allows you to assign a role at the virtual machine scope, which restricts permissions to that specific resource only. By assigning a role like 'Virtual Machine Contributor' at the scope of VM-App01, the help desk engineer can start, stop, and resize only that VM without gaining access to any other VMs or resource groups in the subscription.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Assign the role at the subscription scope so the engineer can manage any VM in the subscription.

    Why it's wrong here

    Choosing subscription scope means the role assignment cascades to every resource group and all virtual machines within the subscription. The engineer would gain the ability to start, stop, and resize any VM in that subscription, and depending on the assigned role, could also create, delete, or modify other VM settings, which is far broader than the stated requirement of only VM-App01. This violates least privilege and creates a much larger attack surface.

    When this WOULD be correct

    If the requirement were to allow the engineer to manage all virtual machines in the subscription (e.g., for a help desk team responsible for all VMs), assigning the role at the subscription scope would be correct.

  • Assign the role at the virtual machine scope for VM-App01 only.

    Why this is correct

    Assigning the role at the virtual machine scope scopes the permission grant to just VM-App01. This is the narrowest possible scope in Azure RBAC that still covers the resource, so the engineer can start, stop, and resize that VM while receiving no permissions on any other resource. It directly implements least privilege.

  • Assign the role at the resource group scope that contains VM-App01.

    Why it's wrong here

    Scoping the role to the resource group containing VM-App01 would apply the role to all virtual machines in that resource group, not solely to VM-App01. While VM-App01 is included, the engineer would be able to manage any VM in the group, and any VMs added to the group later would automatically inherit the permissions. For a request limited to 'only VM-App01', the resource group scope is too broad.

    When this WOULD be correct

    If the question required the engineer to manage all VMs within the resource group containing VM-App01 (e.g., 'start, stop, and resize all VMs in the resource group'), then assigning the role at the resource group scope would be correct.

  • Assign the role at a management group scope so the team can standardize access.

    Why it's wrong here

    A management group scope sits at the top of the Azure RBAC hierarchy, and permissions assigned there are inherited by every subscription, resource group, and resource within that management group. Applying the role here would give the engineer start/stop/resize control over VMs across an entire portfolio of subscriptions, potentially thousands of machines, rather than just VM-App01. This is drastically over-permissive and unrelated to standardizing access.

    When this WOULD be correct

    A question where the requirement is to grant permissions to manage all virtual machines across multiple subscriptions within a management group, such as 'A team lead needs to start, stop, and resize any VM in all subscriptions under the Contoso management group.'

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

Assign the role at the virtual machine scope for VM-App01 only.Correct answer

Why this is correct

Assigning the role at the virtual machine scope scopes the permission grant to just VM-App01. This is the narrowest possible scope in Azure RBAC that still covers the resource, so the engineer can start, stop, and resize that VM while receiving no permissions on any other resource. It directly implements least privilege.

Assign the role at the subscription scope so the engineer can manage any VM in the subscription.Wrong answer — click to see why

Why this is wrong here

Assigning the role at the subscription scope grants the engineer permissions to manage all virtual machines in the subscription, violating the requirement to restrict access to only VM-App01.

★ When this WOULD be the correct answer

If the requirement were to allow the engineer to manage all virtual machines in the subscription (e.g., for a help desk team responsible for all VMs), assigning the role at the subscription scope would be correct.

Why candidates choose this

Candidates may think subscription scope is necessary for start/stop/resize actions, not realizing that these actions can be scoped to a single VM.

Assign the role at the resource group scope that contains VM-App01.Wrong answer — click to see why

Why this is wrong here

Assigning the role at the resource group scope would grant the engineer permissions to start, stop, and resize all virtual machines within that resource group, not just VM-App01, violating the requirement to restrict access to only VM-App01.

★ When this WOULD be the correct answer

If the question required the engineer to manage all VMs within the resource group containing VM-App01 (e.g., 'start, stop, and resize all VMs in the resource group'), then assigning the role at the resource group scope would be correct.

Why candidates choose this

Candidates may assume that since VM-App01 is in a resource group, assigning the role at that scope is sufficient, overlooking that it grants permissions to all resources in the group, not just the specific VM.

Assign the role at a management group scope so the team can standardize access.Wrong answer — click to see why

Why this is wrong here

Assigning the role at a management group scope would grant permissions to all subscriptions and resources under that management group, far exceeding the requirement to restrict access to only VM-App01.

★ When this WOULD be the correct answer

A question where the requirement is to grant permissions to manage all virtual machines across multiple subscriptions within a management group, such as 'A team lead needs to start, stop, and resize any VM in all subscriptions under the Contoso management group.'

Why candidates choose this

Candidates may think management groups provide a way to standardize access across multiple subscriptions, but they overlook that this scope is too broad for a single VM restriction.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every AZ-104 question from scratch — 1,049 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.