Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

F5 Networks F5CAB4 Exam - Topic 4 Question 15 Discussion

A local user account (Users) on the BIG-IP device is assigned the User Manager role. User1 attempts to modify the properties of another account (User2), but the action fails. The BIG-IP Administrator can successfully modify the User2 account. Assuming the principle of least privilege, what is the correct way to allow User1 to modify User2 properties?
D) Modify the partition access for User1
A) Move User2 to the same partition as User1
B) Grant User administrator privileges
C) Move User1 to the same partition as User2

F5 Networks F5CAB4 Exam - Topic 4 Question 15 Discussion

Actual exam question for F5 Networks's F5CAB4 exam
Question #: 15
Topic #: 4
[All F5CAB4 Questions]

A local user account (Users) on the BIG-IP device is assigned the User Manager role. User1 attempts to modify the properties of another account (User2), but the action fails. The BIG-IP Administrator can successfully modify the User2 account. Assuming the principle of least privilege, what is the correct way to allow User1 to modify User2 properties?

Show Suggested Answer Hide Answer
Suggested Answer: D

In F5 TMOS, administrative roles and user permissions are partition-specific. The User Manager role allows an account to manage other user accounts, but this authority is restricted to the administrative partitions to which the User Manager has been granted access.

Partition Awareness: If User1 (the User Manager) attempts to modify User2 and fails, while the full Administrator succeeds, it indicates that User2 resides in a partition where User1 does not have management rights.

Principle of Least Privilege: This principle dictates that a user should be given only the minimum level of access necessary to perform their job functions.

Procedural Solution: Granting 'Administrator' privileges (Option B) would violate least privilege by giving User1 full control over all system settings and all partitions. Moving users between partitions (Options A and C) might disrupt the organizational security structure. The correct and most secure administrative action is to modify the partition access for User1 to include the partition where User2 is located. This enables User1 to manage User2's properties while maintaining their restricted role as a User Manager.


Contribute your Thoughts:

0/2000 characters
Mozell
2 hours ago
I remember something about partition access being crucial for user permissions, so maybe D is the right choice?
upvoted 0 times
...

Save Cancel