Bird
Raised Fist0
Azurecloud~20 mins

Access policies vs RBAC in Azure - Practice Questions

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Challenge - 5 Problems
πŸŽ–οΈ
Access Control Mastery
Get all challenges correct to earn this badge!
Test your skills under time pressure!
🧠 Conceptual
intermediate
2:00remaining
Difference between Access Policies and RBAC in Azure

Which statement correctly describes the main difference between Access Policies and Role-Based Access Control (RBAC) in Azure?

AAccess Policies are specific to individual resources like Key Vaults, while RBAC applies broadly across Azure resources.
BAccess Policies allow assigning roles to users, but RBAC only manages firewall rules.
CRBAC is only used for network security, whereas Access Policies control user permissions on storage accounts.
DRBAC is deprecated and replaced entirely by Access Policies in Azure.
Attempts:
2 left
πŸ’‘ Hint

Think about the scope and resource types each method controls.

❓ Architecture
intermediate
2:00remaining
Choosing Access Control Method for Azure Key Vault

You need to secure an Azure Key Vault so that only specific users can read secrets. Which access control method should you use?

AUse Azure AD Conditional Access policies to restrict secret access.
BUse Azure RBAC to assign the 'Key Vault Secrets User' role to those users.
CCreate Access Policies in the Key Vault to grant secret read permissions to those users.
DConfigure Network Security Groups to restrict access to the Key Vault.
Attempts:
2 left
πŸ’‘ Hint

Consider which method directly controls secret permissions inside Key Vault.

❓ security
advanced
2:00remaining
Impact of RBAC Role Assignment on Azure Storage Account Access

If a user is assigned the 'Storage Blob Data Contributor' role via RBAC on a storage account, what access do they have?

AThey have full administrative control over the storage account and its keys.
BThey can only read blobs but cannot write or delete them.
CThey can manage the storage account settings but cannot access blob data.
DThey can read, write, and delete blobs in the storage account containers.
Attempts:
2 left
πŸ’‘ Hint

Think about what the 'Storage Blob Data Contributor' role allows.

βœ… Best Practice
advanced
2:00remaining
Best Practice for Managing Access to Multiple Azure Resources

Which approach is best to manage user permissions across multiple Azure resources efficiently?

ACreate individual Access Policies for each resource separately for every user.
BUse RBAC role assignments at the resource group level to cover all resources inside it.
CAssign users the Owner role on the subscription to simplify access management.
DUse network security groups to control user access to resources.
Attempts:
2 left
πŸ’‘ Hint

Consider how to reduce repetitive permission assignments.

❓ service_behavior
expert
2:00remaining
Effect of Conflicting Access Policies and RBAC on Azure Key Vault Access

In Azure Key Vault, if a user has an Access Policy denying secret read but is assigned an RBAC role allowing secret read, what is the effective access?

AThe user cannot read secrets because Access Policies deny access regardless of RBAC.
BThe user’s access depends on the order of policy evaluation, which is random.
CThe user can read secrets only if they access via Azure Portal, not via API.
DThe user can read secrets because RBAC permissions override Access Policies.
Attempts:
2 left
πŸ’‘ Hint

Think about which access control method takes precedence in Key Vault.

Practice

(1/5)
1. What is the main difference between Azure Access Policies and RBAC?
easy
A. RBAC controls network traffic; Access Policies manage user passwords.
B. Access Policies grant permissions directly on resources; RBAC assigns roles at scopes.
C. Access Policies are used only for virtual machines; RBAC is for databases.
D. RBAC is a legacy system; Access Policies are the modern replacement.

Solution

  1. Step 1: Understand Access Policies

    Access Policies give permissions directly on specific resources, like a key vault.
  2. Step 2: Understand RBAC

    RBAC assigns roles with permissions at different levels like subscription or resource group.
  3. Final Answer:

    Access Policies grant permissions directly on resources; RBAC assigns roles at scopes. -> Option B
  4. Quick Check:

    Access Policies = direct resource permissions, RBAC = role-based scopes [OK]
Hint: Access Policies = direct, RBAC = role at scope [OK]
Common Mistakes:
  • Confusing Access Policies with RBAC roles
  • Thinking RBAC only applies to virtual machines
  • Assuming Access Policies control network settings
2. Which of the following is the correct way to assign an RBAC role using Azure CLI?
easy
A. az network policy add --role <role> --user <user>
B. az accesspolicy set --user <user> --permission <perm>
C. az vm assign-role --user <user> --role <role>
D. az role assignment create --assignee <user> --role <role> --scope <scope>

Solution

  1. Step 1: Identify correct RBAC command

    The Azure CLI command to assign RBAC roles is 'az role assignment create' with assignee, role, and scope parameters.
  2. Step 2: Verify other options

    Other options mention access policies or unrelated commands which are invalid for RBAC role assignment.
  3. Final Answer:

    az role assignment create --assignee <user> --role <role> --scope <scope> -> Option D
  4. Quick Check:

    RBAC role assignment uses 'az role assignment create' [OK]
Hint: RBAC role assignment uses 'az role assignment create' [OK]
Common Mistakes:
  • Using access policy commands for RBAC
  • Mixing VM or network commands with RBAC
  • Omitting the scope parameter
3. Given this Azure CLI command output snippet for a key vault access policy:
"permissions": {"keys": ["get", "list"], "secrets": ["get"]}
What permissions does this policy grant?
medium
A. Allows only listing keys, no secret access.
B. Allows creating and deleting keys and secrets.
C. Allows getting and listing keys, and getting secrets.
D. Allows full control over keys and secrets.

Solution

  1. Step 1: Read the permissions for keys

    The keys permission includes 'get' and 'list', so it allows reading and listing keys.
  2. Step 2: Read the permissions for secrets

    The secrets permission includes only 'get', so it allows reading secrets but no other actions.
  3. Final Answer:

    Allows getting and listing keys, and getting secrets. -> Option C
  4. Quick Check:

    Permissions match get/list keys and get secrets [OK]
Hint: Check each permission list carefully for allowed actions [OK]
Common Mistakes:
  • Assuming 'get' means create or delete
  • Confusing 'list' with full control
  • Ignoring secret permissions
4. You assigned an RBAC role to a user but they still cannot access a key vault secret. What is the most likely cause?
medium
A. The user lacks an access policy granting secret permissions on the key vault.
B. The RBAC role was assigned at subscription level, which is too broad.
C. The user needs to restart their Azure portal session.
D. RBAC roles do not control access to key vault secrets.

Solution

  1. Step 1: Understand RBAC vs Access Policies for Key Vault

    Key vault secrets require access policies to grant permissions, RBAC alone may not suffice.
  2. Step 2: Analyze the problem

    Even if RBAC role is assigned, without an access policy granting secret permissions, access is denied.
  3. Final Answer:

    The user lacks an access policy granting secret permissions on the key vault. -> Option A
  4. Quick Check:

    Key vault secret access requires access policies [OK]
Hint: Key vault secrets need access policies, not just RBAC [OK]
Common Mistakes:
  • Assuming RBAC alone controls key vault secrets
  • Thinking subscription-level RBAC restricts access
  • Believing portal restart fixes permission issues
5. You want to secure an Azure Key Vault so that only a specific user can read secrets, and a group can manage keys. Which approach follows best practices?
hard
A. Assign specific RBAC roles to the user for secret read (Key Vault Secrets User) and to the group for key management (Key Vault Crypto Officer).
B. Create an access policy granting the user secret read permission; assign an RBAC role to the group for key management.
C. Use access policies for both user and group to grant all permissions.
D. Assign the user an RBAC role for secrets and the group an access policy for keys.

Solution

  1. Step 1: Choose RBAC as best practice

    Azure recommends RBAC for Key Vault. Disable access policies and enable RBAC authorization on the Key Vault.
  2. Step 2: Assign granular roles at Key Vault scope

    Assign 'Key Vault Secrets User' role to user (get/list secrets). Assign 'Key Vault Crypto Officer' role to group (manage keys).
  3. Final Answer:

    Assign specific RBAC roles to the user for secret read (Key Vault Secrets User) and to the group for key management (Key Vault Crypto Officer). -> Option A
  4. Quick Check:

    RBAC Secrets User + Crypto Officer roles [OK]
Hint: RBAC best practice: Secrets User + Crypto Officer roles [OK]
Common Mistakes:
  • Trying to mix Access Policies and RBAC (not possible)
  • Using access policies for everything (legacy method)
  • Assigning overly broad roles or permissions