AZ-104 Implement and Manage Storage Practice Question
A help desk engineer must be able to start, stop, and resize only VM-App01. The engineer must not gain access to any other virtual machines or resource groups in the subscription. What scope should you use for the Azure RBAC role assignment?
⚠ Common exam trap
It's easy for candidates to default to resource group scope thinking it is granular enough, but they overlook that resource group scope grants access to all resources within that group, not just the single VM.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign the role at the virtual machine scope for VM-App01 only.
Azure RBAC allows you to assign a role at the virtual machine scope, which restricts permissions to that specific resource only. By assigning a role like 'Virtual Machine Contributor' at the scope of VM-App01, the help desk engineer can start, stop, and resize only that VM without gaining access to any other VMs or resource groups in the subscription.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assign the role at the subscription scope so the engineer can manage any VM in the subscription.
Why it's wrong here
Choosing subscription scope means the role assignment cascades to every resource group and all virtual machines within the subscription. The engineer would gain the ability to start, stop, and resize any VM in that subscription, and depending on the assigned role, could also create, delete, or modify other VM settings, which is far broader than the stated requirement of only VM-App01. This violates least privilege and creates a much larger attack surface.
When this WOULD be correct
If the requirement were to allow the engineer to manage all virtual machines in the subscription (e.g., for a help desk team responsible for all VMs), assigning the role at the subscription scope would be correct.
- ✓
Assign the role at the virtual machine scope for VM-App01 only.
Why this is correct
Assigning the role at the virtual machine scope scopes the permission grant to just VM-App01. This is the narrowest possible scope in Azure RBAC that still covers the resource, so the engineer can start, stop, and resize that VM while receiving no permissions on any other resource. It directly implements least privilege.
- ✗
Assign the role at the resource group scope that contains VM-App01.
Why it's wrong here
Scoping the role to the resource group containing VM-App01 would apply the role to all virtual machines in that resource group, not solely to VM-App01. While VM-App01 is included, the engineer would be able to manage any VM in the group, and any VMs added to the group later would automatically inherit the permissions. For a request limited to 'only VM-App01', the resource group scope is too broad.
When this WOULD be correct
If the question required the engineer to manage all VMs within the resource group containing VM-App01 (e.g., 'start, stop, and resize all VMs in the resource group'), then assigning the role at the resource group scope would be correct.
- ✗
Assign the role at a management group scope so the team can standardize access.
Why it's wrong here
A management group scope sits at the top of the Azure RBAC hierarchy, and permissions assigned there are inherited by every subscription, resource group, and resource within that management group. Applying the role here would give the engineer start/stop/resize control over VMs across an entire portfolio of subscriptions, potentially thousands of machines, rather than just VM-App01. This is drastically over-permissive and unrelated to standardizing access.
When this WOULD be correct
A question where the requirement is to grant permissions to manage all virtual machines across multiple subscriptions within a management group, such as 'A team lead needs to start, stop, and resize any VM in all subscriptions under the Contoso management group.'
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓Assign the role at the virtual machine scope for VM-App01 only.Correct answer▾
Why this is correct
Assigning the role at the virtual machine scope scopes the permission grant to just VM-App01. This is the narrowest possible scope in Azure RBAC that still covers the resource, so the engineer can start, stop, and resize that VM while receiving no permissions on any other resource. It directly implements least privilege.
✗Assign the role at the subscription scope so the engineer can manage any VM in the subscription.Wrong answer — click to see why▾
Why this is wrong here
Assigning the role at the subscription scope grants the engineer permissions to manage all virtual machines in the subscription, violating the requirement to restrict access to only VM-App01.
★ When this WOULD be the correct answer
If the requirement were to allow the engineer to manage all virtual machines in the subscription (e.g., for a help desk team responsible for all VMs), assigning the role at the subscription scope would be correct.
Why candidates choose this
Candidates may think subscription scope is necessary for start/stop/resize actions, not realizing that these actions can be scoped to a single VM.
✗Assign the role at the resource group scope that contains VM-App01.Wrong answer — click to see why▾
Why this is wrong here
Assigning the role at the resource group scope would grant the engineer permissions to start, stop, and resize all virtual machines within that resource group, not just VM-App01, violating the requirement to restrict access to only VM-App01.
★ When this WOULD be the correct answer
If the question required the engineer to manage all VMs within the resource group containing VM-App01 (e.g., 'start, stop, and resize all VMs in the resource group'), then assigning the role at the resource group scope would be correct.
Why candidates choose this
Candidates may assume that since VM-App01 is in a resource group, assigning the role at that scope is sufficient, overlooking that it grants permissions to all resources in the group, not just the specific VM.
✗Assign the role at a management group scope so the team can standardize access.Wrong answer — click to see why▾
Why this is wrong here
Assigning the role at a management group scope would grant permissions to all subscriptions and resources under that management group, far exceeding the requirement to restrict access to only VM-App01.
★ When this WOULD be the correct answer
A question where the requirement is to grant permissions to manage all virtual machines across multiple subscriptions within a management group, such as 'A team lead needs to start, stop, and resize any VM in all subscriptions under the Contoso management group.'
Why candidates choose this
Candidates may think management groups provide a way to standardize access across multiple subscriptions, but they overlook that this scope is too broad for a single VM restriction.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Dynamic Membership Groups
Key term
Subscription
A subscription is a payment model where you pay a recurring fee to access a product or service instead of buying it once and owning it forever.
Key term
Role assignment
Role assignment is the process of granting a specific set of permissions to a user, group, or service principal so they can perform certain actions within a system.
About these practice questions
Courseiva writes every AZ-104 question from scratch — 1,049 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.