New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

VMware 2V0-33.22 Exam - Topic 7 Question 59 Discussion

Actual exam question for VMware's 2V0-33.22 exam
Question #: 59
Topic #: 7
[All 2V0-33.22 Questions]

A cloud administrator wants to restrict Junior administrators to creating, deleting, and managing virtual machines in the Development folder In the VMware Cloud on AWS vCenter Server instance.

Which type of access should be granted to these junior administrators?

Show Suggested Answer Hide Answer
Suggested Answer: B

This role is designed to give administrators access to manage virtual machines, networks, and other settings within the folder. The CloudAdmin role will also give the junior administrators access to all global permissions that are associated with the Development folder.

'The CloudAdmin role is designed to give administrators access to manage a single folder. This role grants access to manage virtual machines, networks, and other settings within the folder. Additionally, this role grants access to all global permissions that are associated with the folder. For example, if the folder has global permissions that allow users to create or delete virtual machines, the CloudAdmin role will grant access to those permissions within the folder.'

The CloudAdmin user can grant other users or groups read-only access to VMware Cloud on AWS vCenter management objects such as the Mgmt-ResourcePool, Management VMs folder, Discovered Virtual Machines folder, vmc-hostswitch, and vsanDatastore. Because this read-only access does not propagate to management objects, you cannot grant it as a Global Permission and instead must explicitly grant it for each management object. VMware Cloud on AWS runs a script once a day that updates any newly-created management objects (such as objects in a new cluster) so that the CloudAdmin user and CloudAdminGroup SSO group have the updated role applied. The script itself does not grant additional access to any user or group, so you'll need to wait until it completes before the CloudAdmin can use this workflow to grant read-only access to those objects.


https://docs.vmware.com/en/VMware-Cloud-on-AWS/services/com.vmware.vsphere.vmc-aws-manage-data-center-vms.doc/GUID-06B8A15B-4BE9-4236-8BEA-3F4F7C55D87A.html

Contribute your Thoughts:

0/2000 characters
Teri
9 hours ago
B is the right choice for limited access.
upvoted 0 times
...
Vernice
6 days ago
B is the clear winner. Wouldn't want those junior admins messing up the whole vCenter Server instance!
upvoted 0 times
...
An
11 days ago
Haha, I bet the cloud admin is regretting not just giving them the "God Mode" role. B is the way to go though.
upvoted 0 times
...
Vi
16 days ago
I'd go with B as well. Gives them the access they need without going overboard.
upvoted 0 times
...
Theola
21 days ago
Definitely B. Restricting junior admins to just the Development folder is the way to go.
upvoted 0 times
...
An
26 days ago
B) CloudAdmin role on the Development folder seems like the right choice here.
upvoted 0 times
...
Andra
1 month ago
I thought the CloudAdmin role was specifically designed for cloud tasks, but I’m not 100% confident about the folder restrictions.
upvoted 0 times
...
Launa
1 month ago
I practiced a similar question, and I feel like the Administrator role might give too much power.
upvoted 0 times
...
Linn
1 month ago
I'm not entirely sure, but I remember something about global permissions being too broad for junior admins.
upvoted 0 times
...
Brynn
2 months ago
I think the CloudAdmin role on the Development folder might be the right choice since it sounds like it limits access to just that area.
upvoted 0 times
...
Reena
2 months ago
I'm leaning towards B as well. Giving the junior admins the CloudAdmin role on the Development folder seems like the most targeted and secure approach here.
upvoted 0 times
...
Alline
2 months ago
Okay, let me make sure I understand this correctly. The question is asking about the appropriate access level for the junior admins, not the overall cloud admin. I think B is the way to go, but I'll double-check the details.
upvoted 0 times
...
Chaya
2 months ago
I think B is the best choice. It limits access to just the Development folder.
upvoted 0 times
...
Keneth
3 months ago
Wait, can they really manage everything in that folder?
upvoted 0 times
...
Chaya
3 months ago
Option B looks like the best choice to me. Restricting the junior admins to just the Development folder makes sense, and the CloudAdmin role should give them the necessary permissions.
upvoted 0 times
...
Danica
3 months ago
I'm a bit confused here. Do the junior admins need full Administrator access, or is the CloudAdmin role sufficient? I'll have to think this through carefully.
upvoted 0 times
...
Salena
3 months ago
Hmm, this seems straightforward. I'd go with option B - the CloudAdmin role on the Development folder.
upvoted 0 times
Gwenn
2 months ago
Yeah, it limits their access properly.
upvoted 0 times
...
Roselle
2 months ago
I agree, option B makes the most sense.
upvoted 0 times
...
...

Save Cancel