Courseiva
Deploy and Manage Azure ComputehardMultiple SelectObjective-mapped

AZ-104 Deploy and Manage Azure Compute Practice Question

A developer has the Contributor role on a resource group. A Bicep deployment that creates a VM with a public IP fails with a policy denial, but the same template succeeds after the public IP resource is removed. Which two statements are true? Select two.

⚠ Common exam trap

A common mix-up: candidates confuse Azure Policy denials with Azure role-based access control (RBAC) or resource locks, leading candidates to incorrectly assume that a higher-privileged role like Owner can override a policy denial, or that a CanNotDelete lock blocks resource creation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The Contributor role allows deployments in the resource group, but it cannot override a deny policy inherited from a higher scope.

The Contributor role grants full management access to resources within the resource group, but it cannot override Azure Policy effects such as 'deny'. Policy inheritance flows from higher scopes (management group, subscription) down to the resource group, and even a Contributor cannot bypass a deny policy assigned at a higher scope. The Bicep deployment fails specifically because the public IP resource violates a policy rule, not because of a lack of permissions on the role itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The Contributor role allows deployments in the resource group, but it cannot override a deny policy inherited from a higher scope.

    Why this is correct

    Contributor grants broad management rights within its scope, but Azure Policy enforcement is separate from RBAC. A deny effect blocks the resource creation even when the user has sufficient permissions. The fact that the deployment succeeds once the public IP is removed strongly indicates a policy rule, not a permissions issue.

  • The policy assignment can apply to the resource group because policy inheritance flows from management group to subscription to resource group.

    Why this is correct

    Azure Policy assignments at a management group or subscription can affect child scopes automatically. That inheritance explains why a resource group deployment can be denied even when the user has access at the resource-group scope. The template change works because it stops violating the inherited policy condition.

  • A CanNotDelete lock is the reason the public IP resource cannot be created.

    Why it's wrong here

    A CanNotDelete lock only prevents deletion of locked resources. It does not stop creating a new VM, NIC, or public IP, and it does not explain a policy denial message. This distractor confuses resource protection with compliance enforcement.

    When this WOULD be correct

    A question where a resource cannot be deleted and the error message indicates a lock is in place, or where a deployment fails because it tries to delete a locked resource.

  • Assigning Owner on the resource group would automatically bypass the policy denial and allow the template to deploy unchanged.

    Why it's wrong here

    Owner provides full RBAC permissions at the assigned scope, but Azure Policy still evaluates independently. A deny policy remains effective even for highly privileged users unless the policy definition or assignment changes. RBAC elevation does not override policy compliance rules.

    When this WOULD be correct

    This option would be correct if the question stated that the deployment failed due to a resource lock (e.g., CanNotDelete) instead of a policy denial. In that case, assigning Owner would allow the user to remove or override the lock.

  • Moving the VM to another subnet in the same virtual network would remove the inherited policy effect.

    Why it's wrong here

    Policy scope is tied to Azure hierarchy, not to whether a VM uses one subnet or another. Changing the subnet may affect networking, but it does not remove a policy inherited from the management group or subscription. The denial would remain until the policy condition is no longer met.

    When this WOULD be correct

    If the question described a network security group (NSG) rule blocking traffic, and moving the VM to a different subnet with a different NSG resolved the issue, then this option would be correct.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.

The Contributor role allows deployments in the resource group, but it cannot override a deny policy inherited from a higher scope.Correct answer

Why this is correct

Contributor grants broad management rights within its scope, but Azure Policy enforcement is separate from RBAC. A deny effect blocks the resource creation even when the user has sufficient permissions. The fact that the deployment succeeds once the public IP is removed strongly indicates a policy rule, not a permissions issue.

A CanNotDelete lock is the reason the public IP resource cannot be created.Wrong answer — click to see why

Why this is wrong here

A CanNotDelete lock prevents deletion of existing resources, not creation of new ones. The failure is due to a policy denial, not a lock.

★ When this WOULD be the correct answer

A question where a resource cannot be deleted and the error message indicates a lock is in place, or where a deployment fails because it tries to delete a locked resource.

Why candidates choose this

Candidates may confuse locks with policies, or think that a 'deny' effect is equivalent to a lock, leading them to incorrectly attribute the failure to a CanNotDelete lock.

Assigning Owner on the resource group would automatically bypass the policy denial and allow the template to deploy unchanged.Wrong answer — click to see why

Why this is wrong here

Assigning the Owner role on the resource group does not automatically bypass Azure Policy denials. Policies are enforced at the Azure Resource Manager level and override any role permissions, including Owner.

★ When this WOULD be the correct answer

This option would be correct if the question stated that the deployment failed due to a resource lock (e.g., CanNotDelete) instead of a policy denial. In that case, assigning Owner would allow the user to remove or override the lock.

Why candidates choose this

Candidates may assume that higher privileges like Owner can override any restriction, confusing Azure Policy (which is an explicit deny) with role-based access control or resource locks.

Moving the VM to another subnet in the same virtual network would remove the inherited policy effect.Wrong answer — click to see why

Why this is wrong here

Moving a VM to another subnet does not affect policy inheritance; policies are assigned to scopes (management group, subscription, resource group) and apply to all resources within that scope regardless of subnet.

★ When this WOULD be the correct answer

If the question described a network security group (NSG) rule blocking traffic, and moving the VM to a different subnet with a different NSG resolved the issue, then this option would be correct.

Why candidates choose this

Candidates may confuse policy inheritance with network-level restrictions, thinking that changing subnets can alter policy applicability.

Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 1,049 original AZ-104 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.