Independence Day Deal! Unlock 25% OFF Today – Limited-Time Offer - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft Exam DP-420 Topic 7 Question 33 Discussion

Actual exam question for Microsoft's DP-420 exam
Question #: 33
Topic #: 7
[All DP-420 Questions]

You have a container named container1 in an Azure Cosmos DB Core (SQL) API account.

You need to provide a user named User1 with the ability to insert items into container1 by using role-based access control (RBAC). The solution must use the principle of least privilege.

Which roles should you assign to User1?

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

An
2 months ago
Option A seems a bit overkill. The CosmosDB Operator role has way more permissions than what's required here. I'd stick with option D for this scenario.
upvoted 0 times
Bonita
3 days ago
I think option D is the most appropriate choice for assigning roles to User1 in this scenario.
upvoted 0 times
...
Margarett
4 days ago
Yeah, option A does seem like too much. Option D is definitely the way to go for least privilege.
upvoted 0 times
...
Audrie
21 days ago
I agree, option D is the best choice for providing User1 with the ability to insert items into container1.
upvoted 0 times
...
...
Felicia
2 months ago
Hmm, I'm not sure about that. Wouldn't the DocumentDB Account Contributor role be needed to manage the Cosmos DB account as well? I might go with option B just to be safe.
upvoted 0 times
Catalina
16 days ago
That makes sense, let's go with option B then.
upvoted 0 times
...
Royal
20 days ago
I see your point, it's better to be safe and go with option B to cover both managing the account and inserting items.
upvoted 0 times
...
Adaline
21 days ago
But the question specifically mentions inserting items into container1, so maybe Cosmos DB Built-in Data Contributor is enough.
upvoted 0 times
...
Rashida
28 days ago
I think you're right, DocumentDB Account Contributor role is needed for managing the Cosmos DB account.
upvoted 0 times
...
...
Eveline
2 months ago
I think option D is the correct answer. The Cosmos DB Built-in Data Contributor role provides the necessary permissions to insert items into the container, which aligns with the principle of least privilege.
upvoted 0 times
Margret
2 months ago
Yes, option D aligns with the principle of least privilege.
upvoted 0 times
...
Thea
2 months ago
I agree, option D is the correct answer.
upvoted 0 times
...
...
Ricarda
2 months ago
But wouldn't that give User1 more permissions than necessary? I think least privilege is important.
upvoted 0 times
...
Frederica
3 months ago
I disagree, I believe assigning CosmosDB Operator only would be sufficient for User1.
upvoted 0 times
...
Ricarda
3 months ago
I think we should assign DocumentDB Account Contributor and Cosmos DB Built-in Data Contributor to User1.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77