Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Your organization uses Microsoft Azure and has a subscription with multiple resource groups. You need to ensure that only users in the Finance department can access storage accounts in the 'Finance' resource group. The solution must use role-based access control (RBAC). What should you assign?

⚠ Common exam trap

Watch out — candidates often confuse management plane roles (like Contributor or Storage Account Contributor) with data plane roles (like Storage Blob Data Reader), mistakenly thinking Contributor grants data access, when in fact it only grants management access unless combined with a data plane role.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign the Storage Blob Data Reader role to the Finance users at the Finance resource group scope

Assigning the Storage Blob Data Reader role at the Finance resource group scope grants Finance users read access to blob data within all storage accounts in that resource group, using RBAC. This meets the requirement of restricting access to only the Finance department while leveraging Azure RBAC's built-in data plane role for storage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Assign the Contributor role to the Finance users at the management group scope

    Why it's wrong here

    Assigning Contributor at a management group level gives Finance users full administrative control over every resource and every subscription within that management group, including the ability to create, modify, or delete any resource and even assign permissions. This dramatically exceeds their need to read blob data and could allow them to change security settings or remove resources unrelated to finance. It is an over-privileged, high-blast-radius assignment that violates least privilege and is therefore incorrect.

  • ✓

    Assign the Storage Blob Data Reader role to the Finance users at the Finance resource group scope

    Why this is correct

    Assigning Storage Blob Data Reader at the Finance resource group scope is correct because it grants exactly the data-plane permission needed to read blobs and containers (Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read) across all storage accounts in that group, without allowing write, delete, or management operations. The resource-group scope is also efficient: one assignment covers existing and future storage accounts in Finance, and it is scoped narrowly enough to avoid exposing other subscriptions or resource groups. This is the least-privileged, maintainable approach.

  • ✗

    Assign the Reader role to the Finance users at the subscription scope

    Why it's wrong here

    The Reader role at subscription scope has two fatal flaws: first, the Reader role only grants control-plane read permissions (such as viewing storage account configuration), not the data-plane ability to read blob contents—reading blobs requires a role like Storage Blob Data Reader; second, a subscription-wide assignment exposes every resource group in that subscription, including non-Finance resources. Even if the Finance users only need blob reads, this scope is far too broad and still fails to provide the required data access.

  • ✗

    Assign the Storage Account Contributor role to the Finance users at each storage account scope

    Why it's wrong here

    Storage Account Contributor is a management-plane role that permits configuring the storage account—such as changing firewall rules or regenerating keys—yet it does not include the blob read action needed to actually access data. Moreover, assigning it at each storage account individually forces you to repeat the process for every account in Finance, multiplying administrative effort and making the configuration fragile as new storage accounts are created. This is both over-privileged for the intended use case and operationally inferior to a single resource-group-scoped data role.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.