Q: 12
You have an Azure subscription named Sub1 that contains a resource group named RG1. RG1
contains an Azure Cosmos DB database named DB1 and an Azure Kubernetes Service (AKS) cluster
named AKS1. AKS1 uses a managed identity.
You need to ensure that AKS1 can access DB1. The solution must meet the following requirements:
• Ensure that AKS1 uses the managed identity to access DB1.
• Follow the principle of least privilege.
Which role should you assign to the managed identity of AKS1.
Options
Discussion
Probably A, usually see this in practice sets and the official MS docs recommend Data Reader role. Check your study guide for more RBAC scenarios like this.
Be respectful. No spam.