Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Exhibit

Refer to the exhibit.

```json
{
  "properties": {
    "displayName": "Allow assist setup"
  },
  "roleDefinitionId": "/providers/Microsoft.Authorization/roleDefinitions/...",
  "principalId": "12345678-1234-1234-1234-123456789abc",
  "scope": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/RG1"
}
```

Refer to the exhibit. You are creating a role assignment in Azure. The role definition ID is for the Contributor role. What is the effect of this assignment?

⚠ Common exam trap

Candidates often confuse the Contributor role with the Owner role, mistakenly thinking Contributor can manage access (role assignments), or they overlook the scope and assume the assignment applies to the entire subscription.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The principal can manage all resources in resource group RG1.

The Contributor role in Azure provides full management access to all resources within the assigned scope, but it cannot grant access to other users (role assignments). Since the scope is resource group RG1, the principal can manage all resources in that resource group, including creating, deleting, and modifying them, but cannot manage access to the resource group itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The principal can manage all resources in resource group RG1.

    Why this is correct

    The Contributor role assigned at the resource group scope grants full management permissions over all resources contained in that resource group. This includes creating, deleting, and modifying resources as well as starting or stopping VMs, but it explicitly excludes the ability to grant access to the resource group. Because the assignment is scoped to RG1, these management rights apply only to resources within RG1, not to any other scope.

  • ✗

    The principal can read all resources in resource group RG1.

    Why it's wrong here

    This statement is incomplete because Contributor includes read, write, and delete actions; it is not a read-only role. In Azure RBAC, the Reader role provides read-only visibility, whereas Contributor's wider action set means the principal can change resource configurations and delete resources in RG1. Thus, while the principal can indeed read resources, describing the assignment as merely 'read' understates the actual permissions granted.

  • ✗

    The principal can manage all resources in the subscription.

    Why it's wrong here

    Permissions from a role assignment are applied only to the specified scope and inherited by child scopes, not parent scopes. Since the assignment is scoped to resource group RG1, the principal's Contributor access does not extend to other resource groups or to the subscription itself. To manage all resources in the subscription, the role would need to be assigned at the subscription scope, not at RG1.

  • ✗

    The principal can manage access to resource group RG1.

    Why it's wrong here

    Managing access to resources requires the Microsoft.Authorization/roleAssignments/write permission, which is a capability of the Owner or User Access Administrator roles, not Contributor. Contributor is deliberately restricted from delegating access to prevent privilege escalation; a Contributor cannot grant itself or others more rights within RG1. Therefore, the principal can manage resources but cannot manage access to the resource group.

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.