Courseiva

AZ-305 Design data storage solutions Practice Question

Exhibit

Refer to the exhibit.

```json
{
  "roleName": "CustomStorageRole",
  "permissions": [{
    "actions": [
      "Microsoft.Storage/storageAccounts/blobServices/containers/read",
      "Microsoft.Storage/storageAccounts/blobServices/containers/write"
    ],
    "notActions": [],
    "dataActions": [
      "Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read",
      "Microsoft.Storage/storageAccounts/blobServices/containers/blobs/write"
    ],
    "notDataActions": []
  }]
}
```

Refer to the exhibit. A custom Azure RBAC role is defined as shown. A user assigned this role is unable to delete blobs in a container. What is the most likely reason?

⚠ Common exam trap

The trap here is that candidates see 'delete' in the Actions list and assume it covers blob deletion, missing the critical distinction between control plane and data plane permissions in Azure RBAC.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The role does not include delete permission on blobs

The custom RBAC role definition shown in the exhibit includes 'Microsoft.Storage/storageAccounts/blobServices/containers/blobs/delete' under the 'Actions' section, but this permission is a control plane action, not a data plane action. To delete blobs, the role must include the corresponding data action 'Microsoft.Storage/storageAccounts/blobServices/containers/blobs/delete/action' under 'DataActions'. Without it, the user lacks the necessary data plane permission to perform blob deletion, even though the control plane permission is present.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The role is scoped to the storage account but not to the container

    Why it's wrong here

    This statement is incorrect because Azure RBAC roles can be assigned at any scope, including the container (blob) level, not just the storage account. While the custom role is defined with actions applicable to the storage account, nothing restricts assignment to that scope; you can assign it directly to a specific blob container or even a management group. Therefore, the fact that the role is not scoped to the container is not the reason for any access failure—the role is fully assignable at container scope.

  • ✗

    The role does not include read permission on blobs

    Why it's wrong here

    This assertion is false because the role's DataActions explicitly include the read permission for blobs: Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read. With this action present, any user assigned the role can read blob data, such as listing blobs or downloading blob content. The absence of read permission is not the issue here; the role does provide read access.

  • ✗

    The role does not include any dataActions

    Why it's wrong here

    This claim is incorrect because the role definition contains a DataActions array that includes both read and write operations on blobs, specifically Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read and .../write. Since DataActions are present and grant data-plane access, the role does include data actions. The real problem is not a lack of DataActions but a missing delete action.

  • ✓

    The role does not include delete permission on blobs

    Why this is correct

    This is correct: the custom role's DataActions list only includes read and write permissions for blobs, notably omitting Microsoft.Storage/storageAccounts/blobServices/containers/blobs/delete. Without the delete action, a user assigned this role cannot delete blobs or containers. Therefore, any attempt to delete blob data will be denied, making the missing delete permission the precise reason why the role is insufficient for deletion tasks.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.