Courseiva
Manage Azure Identities and GovernancemediumMultiple ChoiceObjective-mapped

AZ-104 Manage Azure Identities and Governance Practice Question

Exhibit

Shared resource group layout
Resource group: rg-platform
Resources:
- VNet-vm
- VM-web01
- VM-db01
- stlogs
Requirement: A network engineer must create and modify subnets and network settings only for VNet-vm. They must not be able to change either VM or the storage account in the resource group.

Based on the exhibit, where should the Network Contributor role be assigned so the engineer can manage only VNet-vm and its subnets, but not other resources in rg-platform?

⚠ Common exam trap

Candidates often assume assigning a role at the resource group scope is sufficient to limit access to a specific resource, but they overlook that resource group scope grants permissions to all resources of that type within the group, not just the intended one.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Assign Network Contributor at the VNet-vm resource scope.

Assigning the Network Contributor role at the VNet-vm resource scope grants the engineer permissions to manage only that specific virtual network and its subnets, while preventing any access to other resources within the rg-platform resource group. This follows the principle of least privilege by scoping the role assignment to the exact resource that needs to be managed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Assign Network Contributor at the management group scope.

    Why it's wrong here

    A management group sits above one or more subscriptions, so assigning Network Contributor at this scope cascades the role down to every subscription and resource group within the management group hierarchy. This gives the principal full network-management rights across entire departments or environments, potentially spanning multiple Azure subscriptions and enabling changes that could affect network-wide connectivity, compliance, and cost. This is the most over-permissive option and clearly exceeds the requirement to secure only the VNet-vm resource.

    When this WOULD be correct

    If the question required granting the engineer the ability to manage all networking resources across multiple subscriptions within a management group (e.g., for a global network administrator), then assigning at the management group scope would be correct.

  • Assign Network Contributor at the subscription scope.

    Why it's wrong here

    Assigning Network Contributor at the subscription scope grants the principal permission to manage every network resource across all resource groups in the subscription, including VNets, NSGs, load balancers, VPN gateways, and user-defined routes. This scope is far broader than a single VNet and would allow the user to alter or delete network resources in unrelated workloads, introducing an unacceptable security risk and violating the principle of least privilege.

    When this WOULD be correct

    This option would be correct if the question required the engineer to manage all virtual networks and subnets within the entire subscription, without any restriction to a specific resource group or virtual network.

  • Assign Network Contributor at the resource group scope for rg-platform.

    Why it's wrong here

    Even though VNet-vm resides in rg-platform, a resource-group-scoped assignment applies Network Contributor to every network resource in that resource group, not just the target VNet. The principal could modify or delete other VNets, subnets, network interfaces, and NSGs in the same group, and because network interfaces are attached to VMs, these changes can indirectly disrupt virtualized workloads. This scope still violates least privilege because it grants broader network permissions than the single-resource scope allows.

    When this WOULD be correct

    This option would be correct if the question required the engineer to manage all networking resources within the rg-platform resource group, such as multiple virtual networks and subnets, without needing access to resources in other resource groups.

  • Assign Network Contributor at the VNet-vm resource scope.

    Why this is correct

    Assigning the role at the specific VNet-vm resource scope confines permissions to that virtual network and its child subnets. The principal can manage subnet address prefixes, DNS servers, peering, and delegation without affecting other VNets, NSGs, or resources in rg-platform. This is the narrowest, least-privilege assignment that still provides full Network Contributor capabilities for the target integration.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

Assign Network Contributor at the VNet-vm resource scope.Correct answer

Why this is correct

Assigning the role at the specific VNet-vm resource scope confines permissions to that virtual network and its child subnets. The principal can manage subnet address prefixes, DNS servers, peering, and delegation without affecting other VNets, NSGs, or resources in rg-platform. This is the narrowest, least-privilege assignment that still provides full Network Contributor capabilities for the target integration.

Assign Network Contributor at the management group scope.Wrong answer — click to see why

Why this is wrong here

Assigning Network Contributor at the management group scope would grant permissions to manage all virtual networks and subnets across all subscriptions under that management group, not just VNet-vm in rg-platform.

★ When this WOULD be the correct answer

If the question required granting the engineer the ability to manage all networking resources across multiple subscriptions within a management group (e.g., for a global network administrator), then assigning at the management group scope would be correct.

Why candidates choose this

Candidates may think that assigning at a higher scope (management group) is more efficient or covers the needed resource, but they overlook that it grants excessive permissions beyond the intended scope.

Assign Network Contributor at the subscription scope.Wrong answer — click to see why

Why this is wrong here

Assigning Network Contributor at the subscription scope would grant the engineer permissions to manage all virtual networks and subnets across all resource groups in the subscription, including resources outside rg-platform, which violates the requirement to restrict management to only VNet-vm and its subnets.

★ When this WOULD be the correct answer

This option would be correct if the question required the engineer to manage all virtual networks and subnets within the entire subscription, without any restriction to a specific resource group or virtual network.

Why candidates choose this

Candidates may think that assigning at the subscription scope is a convenient way to grant network permissions broadly, overlooking the need for least privilege and the specific constraint to limit access to only one VNet.

Assign Network Contributor at the resource group scope for rg-platform.Wrong answer — click to see why

Why this is wrong here

Assigning Network Contributor at the resource group scope for rg-platform would grant the engineer permissions to manage all networking resources within rg-platform, not just VNet-vm and its subnets, violating the requirement to restrict access to only VNet-vm.

★ When this WOULD be the correct answer

This option would be correct if the question required the engineer to manage all networking resources within the rg-platform resource group, such as multiple virtual networks and subnets, without needing access to resources in other resource groups.

Why candidates choose this

Candidates may mistakenly think that assigning the role at the resource group level is sufficient to limit access to only the resources within that group, overlooking that it still grants permissions to all networking resources in the group, not just the specified VNet.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every AZ-104 question from scratch — 1,049 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.