Start here! Get your feet wet with the Microsoft cloud and begin your journey to earning your Microsoft Certified: Azure Fundamentals certification!
Prepare and test your skills

Prepare and test your skills

Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An IT administrator needs to grant a developer permission to manage all cloud resources located inside a specific resource group named App-Dev-RG. The developer must not have access to any other resource groups or services across the Azure subscription.
Which core component of an Azure Role-Based Access Control (Azure RBAC) role assignment defines the boundary of resources to which the assigned permissions apply?
In Azure Role-Based Access Control (Azure RBAC), a scope represents the specific resource, or set of resources, that an identity is permitted to access. It defines the boundary where permissions take effect within the Azure resource hierarchy.
By setting the scope of the role assignment directly to the App-Dev-RG resource group, the administrator ensures that the assigned permissions apply only to the resources inside that container. Access will not spill over to other sibling resource groups within the same subscription.
The scope is the only fundamental RBAC component designed specifically to establish resource boundaries. Configuring the scope correctly ensures that security policies adhere to the principle of least privilege.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.