AZ-305 Practice Question: Design identity, governance, and monitoring solutions
Your organization uses Microsoft Azure and has a subscription with multiple resource groups. You need to ensure that only users in the Finance department can access storage accounts in the 'Finance' resource group. The solution must use role-based access control (RBAC). What should you assign?
⚠ Common exam trap
Watch out — candidates often confuse management plane roles (like Contributor or Storage Account Contributor) with data plane roles (like Storage Blob Data Reader), mistakenly thinking Contributor grants data access, when in fact it only grants management access unless combined with a data plane role.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign the Storage Blob Data Reader role to the Finance users at the Finance resource group scope
Assigning the Storage Blob Data Reader role at the Finance resource group scope grants Finance users read access to blob data within all storage accounts in that resource group, using RBAC. This meets the requirement of restricting access to only the Finance department while leveraging Azure RBAC's built-in data plane role for storage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assign the Contributor role to the Finance users at the management group scope
Why it's wrong here
Assigning Contributor at a management group level gives Finance users full administrative control over every resource and every subscription within that management group, including the ability to create, modify, or delete any resource and even assign permissions. This dramatically exceeds their need to read blob data and could allow them to change security settings or remove resources unrelated to finance. It is an over-privileged, high-blast-radius assignment that violates least privilege and is therefore incorrect.
- ✓
Assign the Storage Blob Data Reader role to the Finance users at the Finance resource group scope
Why this is correct
Assigning Storage Blob Data Reader at the Finance resource group scope is correct because it grants exactly the data-plane permission needed to read blobs and containers (Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read) across all storage accounts in that group, without allowing write, delete, or management operations. The resource-group scope is also efficient: one assignment covers existing and future storage accounts in Finance, and it is scoped narrowly enough to avoid exposing other subscriptions or resource groups. This is the least-privileged, maintainable approach.
- ✗
Assign the Reader role to the Finance users at the subscription scope
Why it's wrong here
The Reader role at subscription scope has two fatal flaws: first, the Reader role only grants control-plane read permissions (such as viewing storage account configuration), not the data-plane ability to read blob contents—reading blobs requires a role like Storage Blob Data Reader; second, a subscription-wide assignment exposes every resource group in that subscription, including non-Finance resources. Even if the Finance users only need blob reads, this scope is far too broad and still fails to provide the required data access.
- ✗
Assign the Storage Account Contributor role to the Finance users at each storage account scope
Why it's wrong here
Storage Account Contributor is a management-plane role that permits configuring the storage account—such as changing firewall rules or regenerating keys—yet it does not include the blob read action needed to actually access data. Moreover, assigning it at each storage account individually forces you to repeat the process for every account in Finance, multiplying administrative effort and making the configuration fragile as new storage accounts are created. This is both over-privileged for the intended use case and operationally inferior to a single resource-group-scoped data role.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.