Courseiva
Server Administration →easyMultiple Choice

C100DBA Server Administration Practice Question

A DBA needs to grant a new application service account the ability to read and write data in any database except the admin database on a MongoDB 6.0 replica set. The account should not be able to perform administrative actions such as managing users or shutting down the server. Which built-in role should the DBA assign?

⚠ Common exam trap

The trap here is assuming that any read/write role includes administrative rights, or that dbOwner is needed for full access, when readWriteAnyDatabase is sufficient and safer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

readWriteAnyDatabase

The readWriteAnyDatabase built-in role provides read and write access to all non-system databases without granting administrative privileges. It is the least-privilege role that satisfies the requirement. The other roles either grant excessive privileges, are scoped to a single database, or do not provide the needed access across all application databases.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    root

    Why it's wrong here

    The root role grants full administrative privileges across all databases, including user management and shutdown. This far exceeds the required permissions and violates the principle of least privilege. It would allow the service account to perform administrative actions, which the scenario explicitly forbids.

  • ✗

    dbOwner on each application database

    Why it's wrong here

    The dbOwner role grants administrative privileges on a specific database, including the ability to manage users, roles, and indexes. While it provides read and write access, it also allows actions that the scenario explicitly wants to prevent. Additionally, it must be assigned per database, which is less efficient than a single any-database role.

  • ✓

    readWriteAnyDatabase

    Why this is correct

    The readWriteAnyDatabase role grants read and write privileges on all databases except the admin, local, and config databases. It does not include administrative privileges such as user management or shutdown. This matches the requirement exactly: the service account can read and write application data but cannot perform administrative actions, and it is restricted from the admin database.

  • ✗

    readWrite on the admin database

    Why it's wrong here

    The readWrite role on the admin database only grants read and write access to the admin database, not to other databases. It also does not exclude administrative actions if applied elsewhere. This does not meet the requirement to access all application databases while avoiding admin actions.

About these practice questions

Courseiva writes every C100DBA question from scratch — 222 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official MongoDB exam blueprint

This C100DBA practice question is part of Courseiva's free MongoDB certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the C100DBA exam.