Quiz 10 Question 2 of 20

A credit-union vault team needs a custom role that can read blob data inside a storage account but must not change the storage account resource itself. Where should those permission strings be placed in the custom role definition?

Select an answer to reveal the explanation.

Motivation