Courseiva
Secure identity and access →mediumMultiple Choice

AZ-500 Secure identity and access Practice Question

Exhibit

Refer to the exhibit.
```json
{
  "roleName": "Custom Role - Read Only",
  "roleType": "CustomRole",
  "assignableScopes": ["/subscriptions/12345678-1234-1234-1234-123456789012"],
  "permissions": [
    {
      "actions": ["Microsoft.Storage/storageAccounts/read"],
      "notActions": [],
      "dataActions": [],
      "notDataActions": []
    }
  ]
}
```

Refer to the exhibit. You are creating a custom Azure RBAC role for a security analyst. The role as shown allows read access to storage accounts. The analyst reports that they cannot read the contents of a blob container in a storage account. Why is this?

⚠ Common exam trap

Many candidates assume that 'read' access to a storage account automatically grants read access to its data, but Azure RBAC requires explicit dataActions for data plane operations, a distinction that is frequently tested on the AZ-500 exam.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The role does not include dataActions to read blob data.

The custom RBAC role only includes read permissions for the storage account's control plane (e.g., listing keys, reading properties) but lacks the necessary dataActions to read blob data. To read blob container contents, the role must include 'Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read' under dataActions, which governs access to the data plane. Without this, the analyst can see the storage account but cannot access the blobs within it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The role is not assigned to the analyst's user account.

    Why it's wrong here

    Whether the custom role is assigned to the analyst's user account is not the root cause of the failure shown in the exhibit; the exhibit depicts a role definition that contains only management-plane Actions. Even if the analyst has a valid assignment at subscription scope, without corresponding dataActions the role cannot authorize requests to read blob content. Therefore, this statement would not explain the inability to access the blob.

  • ✓

    The role does not include dataActions to read blob data.

    Why this is correct

    The custom role's 'Actions' list includes only control-plane operations such as Microsoft.Storage/storageAccounts/read, which govern resource management actions but not blob reads. Reading blob data is a data-plane operation and must be granted via the 'dataActions' property, for example Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read. Because no dataActions exist in the role definition, the analyst is denied blob read access despite having a valid role assignment.

  • ✗

    The assignable scope is incorrect; it should be at the resource group level.

    Why it's wrong here

    Assignable scope is not the issue; setting assignableScopes to the subscription is legitimate and allows the role to be assigned anywhere within that subscription, including resource groups and storage accounts. If the analyst's assignment were on a specific storage account, a subscription-level assignable scope on the definition would still be valid. Narrowing assignable scope to a resource group would only restrict where the role can be assigned, not add the missing data-plane permissions.

  • ✗

    The storage account does not exist in the specified subscription.

    Why it's wrong here

    The storage account's existence is irrelevant because Azure RBAC authorization checks fail before the storage service processes the request. The scenario indicates the storage account is present in the subscription; the failure is an authorization failure caused by the role lacking dataActions. If the storage account did not exist, the error would be a resource-not-found message, not an access-denied condition.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.