Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

You need to provide a team of developers with access to create and manage Azure resources in a specific resource group. The developers should not be able to modify access policies for other users. Which built-in role should you assign?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Contributor

The Contributor role allows full management of resources but cannot manage access (role assignments). Owner can manage access. Reader is read-only. User Access Administrator only manages access, not resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Contributor

    Why this is correct

    Contributor is the correct choice because it grants full management rights over all resource types within the assigned scope, allowing developers to create, modify, and delete resources as needed. However, it explicitly excludes the ability to assign roles or manage access, which is not required for the team's task. By using Contributor, you adhere to the principle of least privilege, giving developers the capabilities they need without exposing access-control functions.

  • ✗

    Owner

    Why it's wrong here

    Owner is wrong for this scenario because, in addition to all the management capabilities of Contributor, it also includes the ability to manage access, assign roles, and grant permissions to other users. This broad scope introduces an unnecessary security risk; developers would be able to elevate their own or others' privileges, which is beyond the requirement of simply creating resources. Custom RBAC roles or Contributor would provide the needed access without these dangerous permissions.

  • ✗

    Reader

    Why it's wrong here

    Reader is inadequate because it provides only read-only access to resources, allowing developers to view resource properties and settings but not create, delete, or modify anything. Since the team's explicit need is to create resources, this role would block all creation and management operations, making it impossible for them to perform their work. Reader could be useful for visibility, but it cannot satisfy the requirement in this question.

  • ✗

    User Access Administrator

    Why it's wrong here

    User Access Administrator is a common misselected option, but it is wrong because it focuses exclusively on managing access to Azure resources, such as assigning roles and managing permissions, rather than creating or managing the resources themselves. A developer assigned this role would be able to grant other users access to resources but would lack the Contributor action 'Microsoft.Resources/subscriptions/resourceGroups/write' needed to actually create anything. This role is for identity governance, not hands-on development work.

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.