mediummultiple choiceObjective-mapped

An enterprise uses one management group to contain five subscriptions for a business unit. A compliance auditor in an Entra ID group needs read-only access to every current and future resource in all five subscriptions, but must not see resources in other business units. What is the best scope for the Reader role assignment?

Question 1mediummultiple choice
Full question →

An enterprise uses one management group to contain five subscriptions for a business unit. A compliance auditor in an Entra ID group needs read-only access to every current and future resource in all five subscriptions, but must not see resources in other business units. What is the best scope for the Reader role assignment?

Answer choices

Why each option matters

Good practice is not just finding the correct option. The wrong answers often show the exact trap the exam wants you to fall into.

A

Best answer

Assign Reader at the management group that contains the five subscriptions.

This scope lets the role flow downward to all subscriptions, resource groups, and resources under that management group. It is the narrowest place that still covers every current and future subscription in that business unit. The auditor gets consistent read-only visibility without requiring separate assignments for each subscription, and access stays isolated from other management groups.

B

Distractor review

Assign Reader separately at each subscription in the business unit.

This would provide the needed access, but only after creating and maintaining multiple assignments. It does not take advantage of inheritance from the parent container, so future subscriptions would require manual work. The requirement asks for the best scope, not just a workable one.

C

Distractor review

Assign Reader at a single resource group within one subscription.

A resource group scope is too narrow because it only covers resources inside that one group. The auditor would miss resources in other resource groups and other subscriptions. This does not satisfy the need for organization-wide visibility across the business unit.

D

Distractor review

Assign Reader directly to each resource that the auditor should see.

Per-resource assignments are operationally expensive and easy to miss. They do not scale to all current and future resources in five subscriptions. This approach also creates unnecessary administrative overhead compared with inheritance from the management group.

Common exam trap

Common exam trap: answer the scenario, not the keyword

Many certification questions include familiar terms but test a specific constraint. Read the exact wording before choosing an answer that is generally true but wrong for this case.

Technical deep dive

How to think about this question

This question should be treated as a scenario, not a definition check. Identify the problem, the constraint and the best action. Then compare each option against those facts.

KKey Concepts to Remember

  • Read the scenario before looking for a memorised answer.
  • Find the constraint that changes the correct option.
  • Eliminate answers that are true in general but not in this case.
  • Use explanations to understand the rule behind the answer.

TExam Day Tips

  • Underline the problem statement mentally.
  • Watch for words such as best, first, most likely and least administrative effort.
  • Review why wrong options are wrong, not only why the correct option is correct.

Related practice questions

Related AZ-104 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

More questions from this exam

Keep practising from the same exam bank, or move into a focused topic page if this question exposed a weak area.

FAQ

Questions learners often ask

What does this AZ-104 question test?

Read the scenario before looking for a memorised answer.

What is the correct answer to this question?

The correct answer is: Assign Reader at the management group that contains the five subscriptions. — RBAC assignments inherit downward through the Azure hierarchy, from management group to subscription, resource group, and resource. Assigning Reader at the management group that contains the five subscriptions gives the auditor read-only access to everything in that branch, including resources created later. It also keeps access limited to that business unit instead of granting visibility across unrelated subscriptions. Why others are wrong: Subscription-level assignments would work only if repeated across all five subscriptions and updated for every future one. A resource group or resource-level assignment is far too narrow and would miss many assets. The management group is the correct scope because it is the first place that covers all five subscriptions through inheritance.

What should I do if I get this AZ-104 question wrong?

Then try more questions from the same exam bank and focus on understanding why the wrong options are tempting.

Discussion

Loading comments…

Sign in to join the discussion.