Question 148 of 239 from exam AZ-300: Microsoft Azure Architect Technologies

Question 148 of 239 from exam AZ-300: Microsoft Azure Architect Technologies

Question

SIMULATION -

Click to expand each objective. To connect to the Azure portal, type https://portal.azure.com in the browser address bar.

When you are finished performing all the tasks, click the "Next' button.

Note that you cannot return to the lab once you click the "Next' button. Scoring occur in the background while you complete the rest of the exam.

Overview -

The following section of the exam is a lab. In this section, you will perform a set of tasks in a live environment. While most functionality will be available to you as it would be in a live environment, some functionality (e.g., copy and paste, ability to navigate to external websites) will not be possible by design.

Scoring is based on the outcome of performing the tasks stated in the lab. In other words, it doesn't matter how you accomplish the task, if you successfully perform it, you will earn credit for that task.

Labs are not timed separately, and this exam may have more than one lab that you must complete. You can use as much time as you would like to complete each lab. But, you should manage your time appropriately to ensure that you are able to complete the lab(s) and all other sections of the exam in the time provided.

Please note that once you submit your work by clicking the Next button within a lab, you will NOT be able to return to the lab.

To start the lab -

You may start the lab by clicking the Next button.

You plan to grant the members of a new Azure AD group named corp8548987 the rights to delegate administrative access to any resource in the resource group named corp8548987.

You need to create the Azure AD group, and then to assign the correct role to the group. The solution must use the principle of least privilege and minimize the number of role assignments.

What should you do from the Azure portal?

Explanations

See explanation below.

Step 1:

Click Resource groups from the menu of services to access the Resource Groups blade

Step 2:

Click Add (+) to create a new resource group. The Create Resource Group blade appears. Enter corp8548987 as the Resource group name, and click the Create button.

Step 3:

Select Create.

Your group is created and ready for you to add members.

Now we need to assign a role to this resource group scope.

Step 4:

Choose the newly created Resource group, and Access control (IAM) to see the current list of role assignments at the resource group scope. Click +Add to open the Add permissions pane.

Step 5:

In the Role drop-down list, select a role Delegate administration, and select Assign access to: resource group corp8548987

https://docs.microsoft.com/en-us/azure/role-based-access-control/role-assignments-portal https://www.juniper.net/documentation/en_US/vsrx/topics/task/multi-task/security-vsrx-azure-marketplace-resource-group.html