AZ-305 Practice Question: Design identity, governance, and monitoring solutions
You need to provide a team of developers with access to create and manage Azure resources in a specific resource group. The developers should not be able to modify access policies for other users. Which built-in role should you assign?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Contributor
The Contributor role allows full management of resources but cannot manage access (role assignments). Owner can manage access. Reader is read-only. User Access Administrator only manages access, not resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Contributor
Why this is correct
Contributor is the correct choice because it grants full management rights over all resource types within the assigned scope, allowing developers to create, modify, and delete resources as needed. However, it explicitly excludes the ability to assign roles or manage access, which is not required for the team's task. By using Contributor, you adhere to the principle of least privilege, giving developers the capabilities they need without exposing access-control functions.
- ✗
Owner
Why it's wrong here
Owner is wrong for this scenario because, in addition to all the management capabilities of Contributor, it also includes the ability to manage access, assign roles, and grant permissions to other users. This broad scope introduces an unnecessary security risk; developers would be able to elevate their own or others' privileges, which is beyond the requirement of simply creating resources. Custom RBAC roles or Contributor would provide the needed access without these dangerous permissions.
- ✗
Reader
Why it's wrong here
Reader is inadequate because it provides only read-only access to resources, allowing developers to view resource properties and settings but not create, delete, or modify anything. Since the team's explicit need is to create resources, this role would block all creation and management operations, making it impossible for them to perform their work. Reader could be useful for visibility, but it cannot satisfy the requirement in this question.
- ✗
User Access Administrator
Why it's wrong here
User Access Administrator is a common misselected option, but it is wrong because it focuses exclusively on managing access to Azure resources, such as assigning roles and managing permissions, rather than creating or managing the resources themselves. A developer assigned this role would be able to grant other users access to resources but would lack the Contributor action 'Microsoft.Resources/subscriptions/resourceGroups/write' needed to actually create anything. This role is for identity governance, not hands-on development work.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.