Azure Resource Locks for RG Protection
You have an Azure subscription that contains a resource group named RG1. Users must NOT be able to perform the following operations: • Delete RG1. • Modify resources in RG1. • Delete resources from RG1. What should you do?
Community Votes
75% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The trap lies in confusing 'Delete' locks with 'Read-Only' locks; while Delete prevents deletion, it allows modification, whereas Read-Only prevents both.
This question tests the correct Azure resource lock type to prevent both modifications and deletions of a resource group. Applying a read-only lock is the definitive solution to restrict users from performing write or delete operations on RG1.
Many learners choose A (Delete lock) because they focus only on preventing deletion, failing to realize that this option still permits modifying resources within the group.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Applying a read-only lock (Option B) to RG1 ensures that users can only view the resources but cannot perform any write or delete operations. This perfectly satisfies the requirement to block both modification and deletion of resources and the resource group itself.Why the Other Options Are Wrong
A delete lock (Option A) only prevents deletion, allowing users to modify resources, which violates the prompt. RBAC (Option C) requires complex role assignments rather than a simple blanket restriction, and tags (Option D) are metadata only and have no enforcement capabilities.Community Comment Notes
While the majority voted for B, some learners like Lili97 questioned if inheritance applies to resource groups, noting that locks on a RG do not automatically apply to its child resources. However, since the question specifies operations on 'RG1' and 'resources in RG1', applying the lock directly to RG1 is the standard administrative approach to achieve the stated goal without managing every individual resource.Official Reference
Exam Strategy
When securing resources against accidental changes, always distinguish between the two lock types: 'CanNotDelete' for preventing removal only, and 'ReadOnly' for preventing all changes including deletion.
Frequently Asked Questions
Does a lock applied to a Resource Group inherit to its resources?
No, locks must be explicitly applied to each resource. However, applying them to the RG is often used as a management shortcut in exam scenarios.
Why is RBAC not the best answer here?
RBAC allows granular permissions but does not provide a single, immediate 'block all writes' action like a lock does for this specific scenario.
Related Analysis
Practice All AZ-900 Questions
Access 90 questions with complete answers and detailed explanations.
View Full AZ-900 Practice Test →