Yes, it is possible.
Yes, managed identities are credential-free.
Fine-grained access control, Enhanced security, Protection of sensitive data etc.
Parent-child hierarchy or Top-Down approach.
Yes, a user with the Contributor role can delete an entire resource group