AZ-305 Design data storage solutions Practice Question
Exhibit
Refer to the exhibit.
```json
{
"roleName": "CustomStorageRole",
"permissions": [{
"actions": [
"Microsoft.Storage/storageAccounts/blobServices/containers/read",
"Microsoft.Storage/storageAccounts/blobServices/containers/write"
],
"notActions": [],
"dataActions": [
"Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read",
"Microsoft.Storage/storageAccounts/blobServices/containers/blobs/write"
],
"notDataActions": []
}]
}
```Refer to the exhibit. A custom Azure RBAC role is defined as shown. A user assigned this role is unable to delete blobs in a container. What is the most likely reason?
⚠ Common exam trap
The trap here is that candidates see 'delete' in the Actions list and assume it covers blob deletion, missing the critical distinction between control plane and data plane permissions in Azure RBAC.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The role does not include delete permission on blobs
The custom RBAC role definition shown in the exhibit includes 'Microsoft.Storage/storageAccounts/blobServices/containers/blobs/delete' under the 'Actions' section, but this permission is a control plane action, not a data plane action. To delete blobs, the role must include the corresponding data action 'Microsoft.Storage/storageAccounts/blobServices/containers/blobs/delete/action' under 'DataActions'. Without it, the user lacks the necessary data plane permission to perform blob deletion, even though the control plane permission is present.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The role is scoped to the storage account but not to the container
Why it's wrong here
This statement is incorrect because Azure RBAC roles can be assigned at any scope, including the container (blob) level, not just the storage account. While the custom role is defined with actions applicable to the storage account, nothing restricts assignment to that scope; you can assign it directly to a specific blob container or even a management group. Therefore, the fact that the role is not scoped to the container is not the reason for any access failure—the role is fully assignable at container scope.
- ✗
The role does not include read permission on blobs
Why it's wrong here
This assertion is false because the role's DataActions explicitly include the read permission for blobs: Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read. With this action present, any user assigned the role can read blob data, such as listing blobs or downloading blob content. The absence of read permission is not the issue here; the role does provide read access.
- ✗
The role does not include any dataActions
Why it's wrong here
This claim is incorrect because the role definition contains a DataActions array that includes both read and write operations on blobs, specifically Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read and .../write. Since DataActions are present and grant data-plane access, the role does include data actions. The real problem is not a lack of DataActions but a missing delete action.
- ✓
The role does not include delete permission on blobs
Why this is correct
This is correct: the custom role's DataActions list only includes read and write permissions for blobs, notably omitting Microsoft.Storage/storageAccounts/blobServices/containers/blobs/delete. Without the delete action, a user assigned this role cannot delete blobs or containers. Therefore, any attempt to delete blob data will be denied, making the missing delete permission the precise reason why the role is insufficient for deletion tasks.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.