C100DBA Server Administration Practice Question
A DBA needs to grant a new application service account the ability to read and write data in any database except the admin database on a MongoDB 6.0 replica set. The account should not be able to perform administrative actions such as managing users or shutting down the server. Which built-in role should the DBA assign?
⚠ Common exam trap
The trap here is assuming that any read/write role includes administrative rights, or that dbOwner is needed for full access, when readWriteAnyDatabase is sufficient and safer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
readWriteAnyDatabase
The readWriteAnyDatabase built-in role provides read and write access to all non-system databases without granting administrative privileges. It is the least-privilege role that satisfies the requirement. The other roles either grant excessive privileges, are scoped to a single database, or do not provide the needed access across all application databases.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
root
Why it's wrong here
The root role grants full administrative privileges across all databases, including user management and shutdown. This far exceeds the required permissions and violates the principle of least privilege. It would allow the service account to perform administrative actions, which the scenario explicitly forbids.
- ✗
dbOwner on each application database
Why it's wrong here
The dbOwner role grants administrative privileges on a specific database, including the ability to manage users, roles, and indexes. While it provides read and write access, it also allows actions that the scenario explicitly wants to prevent. Additionally, it must be assigned per database, which is less efficient than a single any-database role.
- ✓
readWriteAnyDatabase
Why this is correct
The readWriteAnyDatabase role grants read and write privileges on all databases except the admin, local, and config databases. It does not include administrative privileges such as user management or shutdown. This matches the requirement exactly: the service account can read and write application data but cannot perform administrative actions, and it is restricted from the admin database.
- ✗
readWrite on the admin database
Why it's wrong here
The readWrite role on the admin database only grants read and write access to the admin database, not to other databases. It also does not exclude administrative actions if applied elsewhere. This does not meet the requirement to access all application databases while avoiding admin actions.
About these practice questions
Courseiva writes every C100DBA question from scratch — 222 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official MongoDB exam blueprint
This C100DBA practice question is part of Courseiva's free MongoDB certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the C100DBA exam.