mediummultiple choiceObjective-mapped

Exhibit

Shared resource group layout
Resource group: rg-platform
Resources:
- VNet-vm
- VM-web01
- VM-db01
- stlogs
Requirement: A network engineer must create and modify subnets and network settings only for VNet-vm. They must not be able to change either VM or the storage account in the resource group.

Based on the exhibit, where should the Network Contributor role be assigned so the engineer can manage only VNet-vm and its subnets, but not other resources in rg-platform?

Question 1mediummultiple choice
Full question →

Based on the exhibit, where should the Network Contributor role be assigned so the engineer can manage only VNet-vm and its subnets, but not other resources in rg-platform?

Answer choices

Why each option matters

Good practice is not just finding the correct option. The wrong answers often show the exact trap the exam wants you to fall into.

A

Distractor review

Assign Network Contributor at the management group scope.

This would grant access too broadly and far beyond a single virtual network.

B

Distractor review

Assign Network Contributor at the subscription scope.

Subscription scope still includes all resources in the subscription and is broader than the requirement.

C

Distractor review

Assign Network Contributor at the resource group scope for rg-platform.

Resource group scope would include the VMs and storage account as well, which violates least privilege.

D

Best answer

Assign Network Contributor at the VNet-vm resource scope.

Assigning the role directly to the virtual network limits access to that specific network object and its child subnets while excluding unrelated resources in the same resource group.

Common exam trap

Common exam trap: usable hosts are not the same as total addresses

Subnetting questions often tempt you into counting all addresses. In normal IPv4 subnets, the network and broadcast addresses are not usable host addresses.

Technical deep dive

How to think about this question

Subnetting questions test whether you can identify the network, broadcast address, usable range, mask and correct subnet. Slow down enough to calculate the block size correctly.

KKey Concepts to Remember

  • CIDR notation defines the prefix length.
  • Block size helps identify subnet boundaries.
  • Network and broadcast addresses are not usable hosts in normal IPv4 subnets.
  • The required host count determines the smallest suitable subnet.

TExam Day Tips

  • Write the block size before choosing the subnet.
  • Check whether the question asks for hosts, subnets or a specific address range.
  • Do not confuse /24, /25, /26 and /27 host counts.

Related practice questions

Related AZ-104 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

More questions from this exam

Keep practising from the same exam bank, or move into a focused topic page if this question exposed a weak area.

FAQ

Questions learners often ask

What does this AZ-104 question test?

CIDR notation defines the prefix length.

What is the correct answer to this question?

The correct answer is: Assign Network Contributor at the VNet-vm resource scope. — The narrowest scope that satisfies the requirement is the VNet-vm resource itself. Azure RBAC inherited permissions would make resource group or subscription scope too broad because the engineer would also gain rights over the VMs and storage account. By assigning Network Contributor at the virtual network scope, the administrator gives subnet and network configuration control only where it is needed. Why others are wrong: Management group and subscription scopes are both too broad for a task limited to one virtual network. Resource group scope is also too broad because it covers every resource in rg-platform, including the VMs and storage account. The scenario specifically asks for the smallest scope that still permits network administration on only VNet-vm and its subnets.

What should I do if I get this AZ-104 question wrong?

Then try more questions from the same exam bank and focus on understanding why the wrong options are tempting.

Discussion

Loading comments…

Sign in to join the discussion.