AZ-305 Design business continuity solutions Practice Question
Exhibit
{
"properties": {
"provisioningState": "Succeeded",
"roleDefinitionId": "/subscriptions/.../providers/Microsoft.Authorization/roleDefinitions/...",
"principalId": "...",
"scope": "/subscriptions/...",
"condition": "((!(ActionMatches{'Microsoft.Storage/storageAccounts/blobServices/containers/blobs/delete'})) OR (@Resource[Microsoft.Storage/storageAccounts/blobServices/containers/blobs] Tag Matches 'Project' 'ProjectA'))",
"conditionVersion": "2.0"
},
"id": "/subscriptions/.../providers/Microsoft.Authorization/roleAssignments/...",
"type": "Microsoft.Authorization/roleAssignments",
"name": "..."
}Refer to the exhibit. A role assignment has a condition that controls blob deletion. A user assigned this role tries to delete a blob with tag 'Project' set to 'ProjectB'. What will happen?
⚠ Common exam trap
The trap is that candidates may focus on the action type or condition version, but the key is the tag value mismatch. The condition requires a specific tag value, and the blob has a different one, leading to denial.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The deletion is denied because the blob does not have the required tag
The role assignment condition likely requires the blob to have the tag 'Project' set to a specific value (e.g., 'ProjectA'). Since the blob in question has the tag 'Project' set to 'ProjectB', the condition is not satisfied, and the deletion is denied. Option C correctly identifies this mismatch.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The deletion is allowed because the condition only applies to write operations
Why it's wrong here
The condition's action set governs delete operations, so a delete request is evaluated against it; the tag mismatch denies rather than allows. It is tempting because conditions scoped only to write actions do exist, and that reasoning would hold if the exhibit listed write and not delete.
- ✗
The deletion is allowed because the condition does not affect blob deletion
Why it's wrong here
The condition explicitly targets blob deletion, so it does affect delete operations and cannot be bypassed. It is tempting because conditions scoped to other actions, such as read or write, genuinely leave deletion unaffected, which would make this answer right if the exhibit listed those actions.
- ✓
The deletion is denied because the blob does not have the required tag
Why this is correct
The role assignment condition permits blob deletion only when the blob carries the required tag value. Because the blob's 'Project' tag is set to 'ProjectB' rather than the value the condition expects, the condition evaluates false and the delete operation is blocked.
- ✗
The deletion is denied because the condition version is 2.0 and not supported
Why it's wrong here
Condition version 2.0 is fully supported by Microsoft Entra ID role assignments; version mismatch is not the cause of denial here. It is tempting because version-related failures do occur with older condition syntax, so it would be the correct explanation if the exhibit showed an unsupported version.
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.