Azure Resource Locks for RG Protection

Describe features and tools in Azure for governance and compliance
Answer Correct answer: B — Apply a read-only lock to RG1 to prevent all modifications and deletions.

You have an Azure subscription that contains a resource group named RG1. Users must NOT be able to perform the following operations: • Delete RG1. • Modify resources in RG1. • Delete resources from RG1. What should you do?

  1. Apply a delete lock to RG1.
  2. Apply a read-only lock to RG1. Correct Answer
  3. Grant role-based access control (RBAC) permissions to RG1.
  4. Add a tag to RG1.

Community Votes

B
75%
A
25%

75% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The trap lies in confusing 'Delete' locks with 'Read-Only' locks; while Delete prevents deletion, it allows modification, whereas Read-Only prevents both.

This question tests the correct Azure resource lock type to prevent both modifications and deletions of a resource group. Applying a read-only lock is the definitive solution to restrict users from performing write or delete operations on RG1.

Many learners choose A (Delete lock) because they focus only on preventing deletion, failing to realize that this option still permits modifying resources within the group.

Community Discussion (5 comments)

RjayC 👍 1 Selected: B
The correct answer is B. Apply a read-only lock to RG1. ### Explanation: A read-only lock prevents users from making any modifications to resources within the resource group, including adding, updating, or deleting resources. It also ensures that the resource group itself cannot be deleted. This meets all the requirements stated in the scenario. ### Why not the other options? - A. Apply a delete lock to RG1: A delete lock would prevent users from deleting RG1 but does not restrict modifications to resources within RG1. - C. Grant role-based access control (RBAC) permissions to RG1: RBAC permissions provide access control but require detailed configuration and may not completely restrict all the specified actions. - D. Add a tag to RG1: Tags are used for organizing resources and do not control access or prevent actions.
Dmarcetic 👍 1 Selected: B
ReadOnly: Prevents both modifications and deletion of the resource
Dmarcetic 👍 1 Selected: B
Read-only: This lock type prevents users from modifying or deleting the resource group and its resources. CanNotDelete: This lock type prevents users from deleting the resource group but allows modifications.
Lili97 👍 1 Selected: A
I think we should get a : - delete lock on RG1 =====> Answer A - read only lock on RG1 resources only ====> Not mentioned in the possible choices Additionally, I understand there is no inheritance on a RG and its resources. So it should be answer A. Am I wrong ?
zswap 👍 2
B. Apply a read-only lock to RG1. A read-only lock will prevent users from making any modifications or deletions to the resource group and its resources. This lock type ensures that all resources within RG1 can only be read, not modified or deleted

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Applying a read-only lock (Option B) to RG1 ensures that users can only view the resources but cannot perform any write or delete operations. This perfectly satisfies the requirement to block both modification and deletion of resources and the resource group itself.

Why the Other Options Are Wrong

A delete lock (Option A) only prevents deletion, allowing users to modify resources, which violates the prompt. RBAC (Option C) requires complex role assignments rather than a simple blanket restriction, and tags (Option D) are metadata only and have no enforcement capabilities.

Community Comment Notes

While the majority voted for B, some learners like Lili97 questioned if inheritance applies to resource groups, noting that locks on a RG do not automatically apply to its child resources. However, since the question specifies operations on 'RG1' and 'resources in RG1', applying the lock directly to RG1 is the standard administrative approach to achieve the stated goal without managing every individual resource.

Official Reference

Exam Strategy

When securing resources against accidental changes, always distinguish between the two lock types: 'CanNotDelete' for preventing removal only, and 'ReadOnly' for preventing all changes including deletion.

Frequently Asked Questions

Does a lock applied to a Resource Group inherit to its resources?

No, locks must be explicitly applied to each resource. However, applying them to the RG is often used as a management shortcut in exam scenarios.

Why is RBAC not the best answer here?

RBAC allows granular permissions but does not provide a single, immediate 'block all writes' action like a lock does for this specific scenario.

Related Analysis

Practice All AZ-900 Questions

Access 90 questions with complete answers and detailed explanations.

View Full AZ-900 Practice Test →

← Back to AZ-900 Study Guide