Does Assigning AcrPull to ACR-Tasks-Network Meet the Goal?

Provision and manage containers in the Azure portal Manage access to Azure resources
Answer Correct answer: B — Assigning AcrPull to ACR-Tasks-Network does not meet the goal; the role must be granted to the identity that pulls image1 from Registry1.

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have an Azure container registry named Registry1 that contains an image named image1. You receive an error message when you attempt to deploy a container instance by using image1. You need to be able to deploy a container instance by using image1. Solution: You assign the AcrPull role to ACR-Tasks-Network for Registry1. Does this meet the goal?

  1. Yes
  2. No Correct Answer

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests whether you can identify the correct principal for the AcrPull role in an ACR-to-container-instance deployment; the trap is assuming any AcrPull assignment fixes the image pull error.

Deploying an Azure container instance from Registry1 requires AcrPull on the identity that pulls image1. Assigning AcrPull to ACR-Tasks-Network instead does not meet the goal, so the correct answer is B.

Choosing Yes because AcrPull is the required role, without checking that it must be assigned to the deployment identity rather than to ACR-Tasks-Network.

Community Discussion (4 comments)

efla 👍 8 Selected: B
Ans: No AcrPull role assigned to ACR-Tasks-Network does not meet the goal. This role should be assigned to the identity that is performing the container deployment.
[Removed] 👍 1 Selected: B
it´s B You assign the AcrPull role to the identity
Pcservices 👍 2 Selected: B
Answer: B. No Explanation: Assigning the AcrPull role to a service principal or identity is a necessary step to allow pulling container images from an Azure Container Registry (ACR). However, in the scenario described, the role is assigned to ACR-Tasks-Network, which might not be the correct identity involved in deploying the container instance. To deploy a container instance using an image from ACR, the identity or resource attempting the deployment (such as an Azure Container Instance or a user) needs the AcrPull role on the registry (in this case, Registry1). If the correct identity doesn't have this role, you would still encounter a permission issue.
rklai 👍 3
AcrPull role assigned to ACR-Tasks-Network does not meet the goal. This role should be assigned to the identity that is performing the container deployment.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Assigning AcrPull to ACR-Tasks-Network does not grant the container deployment identity permission to pull image1 from Registry1. Azure Container Registry authorizes image pulls based on the identity presenting the request, such as a managed identity, service principal, or user. Because ACR-Tasks-Network is not the principal deploying the container instance, the original authorization error would persist. As efla noted, "This role should be assigned to the identity that is performing the container deployment." Therefore option B, No, is correct.

Why the Other Options Are Wrong

Option A, Yes, is wrong because it assumes the role assignment to ACR-Tasks-Network resolves the pull failure. The question specifically says the error occurs when deploying a container instance, so the identity used by that deployment must have AcrPull on Registry1. Pcservices pointed out that ACR-Tasks-Network "might not be the correct identity involved in deploying the container instance." Without granting AcrPull to the actual deployment principal, the image pull remains unauthorized.

Community Comment Notes

Community responses unanimously select B, with comments emphasizing that AcrPull belongs to the deployment identity. efla and rklai both state that the role "should be assigned to the identity that is performing the container deployment." Another commenter adds that the role is assigned to a principal that may not be involved in the container instance deployment. This consensus aligns with Azure RBAC scoping and the requirement that the image-pulling identity be authorized on the registry.

Official Reference

Exam Strategy

For ACR image-pull errors, identify who is pulling the image before evaluating a role assignment. The presence of the correct role name, AcrPull, is not enough; the role must be assigned to the principal that the container deployment uses.

Frequently Asked Questions

Why doesn't assigning AcrPull to ACR-Tasks-Network meet the goal?

ACR-Tasks-Network is not the identity deploying the container instance; AcrPull must be granted to the principal that actually pulls image1 from Registry1.

Which identity needs AcrPull to deploy a container instance from Registry1?

The identity used by the container instance or deployment process, such as its managed identity or service principal, must have AcrPull on Registry1.

Related Analysis

Practice All AZ-104 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AZ-104 Practice Test →

← Back to AZ-104 Study Guide