Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceEasy
A security auditor needs read-only access to all resources within a specific Azure subscription. They should be able to view all resource configurations, logs, and security settings, but must not be able to make any changes or manage user access. Which built-in Azure role should be assigned to the security auditor at the subscription scope?
- AOwner
- BReader
- CContributor
- DSecurity Reader
Show answer & explanationAnswer & explanation
Correct answer: B. Reader
The 'Reader' role provides read-only access to all resources within its scope, including resource configurations, logs, and security settings, without allowing any modifications. This aligns perfectly with the auditor's requirement.
Why the other options are wrong
- A. Owner has full access to manage all resources and assign roles, which is too permissive for an auditor.
- C. Contributor can manage all resources but cannot assign roles, which goes beyond read-only.
- D. Security Reader provides read-only access to security-related aspects, but 'Reader' provides broader read-only access to all resources and configurations.
Azure RBAC Reader Role
The Azure built-in 'Reader' role grants read-only access to all resources within its assigned scope, allowing users to view configurations and settings without making changes.
- Provides comprehensive read access.
- Does not allow any write, delete, or role assignment actions.
- Ideal for monitoring, auditing, and reporting purposes.
Memory trick: Just looking? Be a Reader, not a doer.