Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

VMware 2V0-21.23 Exam - Topic 5 Question 64 Discussion

An administrator is tasked with providing users access to objects within an existing VMware vCenter instance. The vCenter inventory has a single data center with one management vSphere cluster and five workload vSphere clusters.The following requirements must be met for assigning the users access:* Users must only be able to view all of the inventory objects associated with the management vSphere cluster.* Users must be able to edit all of the inventory objects associated with the workload vSphere clusters.The administrator creates a custom role to provide the permissions needed to allow users to edit inventory objects.Which series of steps should the administrator complete to assign the custom role and provide the required level of access to users?
D) Apply Global permissions to assign the Read Only role to the root vCenter object and enable propagation. Apply vCenter permissions to assign the custom role to the workload vSphere clusters.
A) Apply Global permissions to assign the Read Only role to the root vCenter object. Apply vCenter permissions to assign the custom role to the workload vSphere clusters and enable propagation.
B) Apply Global permissions to assign the Read Only role to the root vCenter object and enable propagation. Apply vCenter permissions to assign the custom role to the workload vSphere clusters and enable propagation.
C) Apply Global permissions to assign the Read Only role to the root vCenter object. Apply vCenter permissions to assign the custom role to the workload vSphere clusters.

VMware 2V0-21.23 Exam - Topic 5 Question 64 Discussion

Actual exam question for VMware's 2V0-21.23 exam
Question #: 64
Topic #: 5
[All 2V0-21.23 Questions]

An administrator is tasked with providing users access to objects within an existing VMware vCenter instance. The vCenter inventory has a single data center with one management vSphere cluster and five workload vSphere clusters.

The following requirements must be met for assigning the users access:

* Users must only be able to view all of the inventory objects associated with the management vSphere cluster.

* Users must be able to edit all of the inventory objects associated with the workload vSphere clusters.

The administrator creates a custom role to provide the permissions needed to allow users to edit inventory objects.

Which series of steps should the administrator complete to assign the custom role and provide the required level of access to users?

Show Suggested Answer Hide Answer
Suggested Answer: D

Option D is correct because it allows the administrator to apply Global permissions to assign the Read Only role to the root vCenter object and enable propagation, which will apply to all of the inventory objects in vCenter, and then apply vCenter permissions to assign the custom role to the workload vSphere clusters, which will override the Global permissions and allow users to edit all of the inventory objects associated with the workload vSphere clusters. Option A is incorrect because it will not enable propagation for the Global permissions, which will limit the Read Only role to the root vCenter object only. Option B is incorrect because it will enable propagation for both the Global and vCenter permissions, which will create a conflict between the Read Only and custom roles. Option C is incorrect because it will not enable propagation for either the Global or vCenter permissions, which will limit the Read Only role to the root vCenter object only and the custom role to the workload vSphere clusters only. Reference: https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.security.doc/GUID-A2A4371A-B888-404C-B23F-C422A8C40F54.html


Contribute your Thoughts:

0/2000 characters
Carma
3 days ago
I’m leaning towards A. It seems simpler without extra propagation.
upvoted 0 times
...
Vilma
9 days ago
I agree, B makes sense. Propagation is key for access.
upvoted 0 times
...
Luke
14 days ago
I think option B is the best. It covers everything needed.
upvoted 0 times
...
Ira
19 days ago
I’m surprised they didn’t mention the importance of role hierarchy here.
upvoted 0 times
...
Lucia
24 days ago
Totally agree with B, it covers all bases!
upvoted 0 times
...
Beula
29 days ago
Wait, why do we need to apply Global permissions at all?
upvoted 0 times
...
Louisa
1 month ago
I think C is better, no need for propagation on the Read Only role.
upvoted 0 times
...
Dierdre
1 month ago
Option B seems right, gotta enable propagation for both roles.
upvoted 0 times
...
Jaime
1 month ago
I’m not entirely clear on the difference between applying permissions with and without propagation. I feel like I need to double-check that part.
upvoted 0 times
...
Lynsey
2 months ago
This question feels similar to one we practiced where we had to set different permissions for different clusters. I think option B might be the right choice.
upvoted 0 times
...
Tiera
2 months ago
I think we need to apply the custom role to the workload clusters, but I'm confused about whether to enable propagation or not.
upvoted 0 times
...
Tammy
2 months ago
I remember something about using global permissions for read-only access, but I'm not sure if propagation is necessary for that.
upvoted 0 times
...

Save Cancel