Management & GovernanceQuestion 85 of 100
Which built-in RBAC role provides view-only access with no ability to make changes?
a.Reader
b.Owner
c.Contributor
d.User Access Administrator
Explanation
The Reader role grants the ability to view resources but not to create, modify, or delete them. It is ideal for auditors or stakeholders who need visibility without change rights. It represents the least-privileged of the common built-in roles.
Practice all 100 questions free — no signup required.
Related questions on this topic
- What does the principle of 'least privilege' mean when assigning RBAC roles?
- Which built-in RBAC role grants full access to manage all resources, including assigning roles to others?
- Which built-in RBAC role lets a user manage resources but NOT grant access to other users?
- What is the main benefit of applying consistent tagging across your Azure resources?
- Which service helps you improve your organization's security posture by providing a security score and recommendations?
- What does an action group in Azure Monitor define?
Last reviewed: · editorial process
PrepPass Editorial Team · Verified against Microsoft Azure Fundamentals (AZ-900) · How we review