Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

VMware 3V0-21.25 Exam - Topic 1 Question 1 Discussion

An administrator is configuring RBAC policies in VMware Cloud Foundation (VCF) Automation to delegate access across multiple clusters. The administrator must ensure that:* Cluster lifecycle operations (e.g., scaling) can only be performed by a designated operations group.* Security policies at the NSX project level remain restricted to network administrators' group.Which two role assignments meet these requirements? (Choose two.)
B) Assign the Security Administrator role in NSX to the network administrators group at the project scope. and E) Assign the Cluster Administrator role in VCF Automation to the operations group at the cluster scope.
A) Assign the Organization Owner role to the network administrators group at the tenant organization level.
C) Assign the Service Viewer role in VCF Automation to the operations group at the cluster scope.
D) Assign the Service User role in VCF Automation to the operations group at the cluster scope.

VMware 3V0-21.25 Exam - Topic 1 Question 1 Discussion

Actual exam question for VMware's 3V0-21.25 exam
Question #: 1
Topic #: 1
[All 3V0-21.25 Questions]

An administrator is configuring RBAC policies in VMware Cloud Foundation (VCF) Automation to delegate access across multiple clusters. The administrator must ensure that:

* Cluster lifecycle operations (e.g., scaling) can only be performed by a designated operations group.

* Security policies at the NSX project level remain restricted to network administrators' group.

Which two role assignments meet these requirements? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: B, E

VCF 9.0 introduces a more granular RBAC model to support complex operational requirements. To meet the first requirement regarding cluster lifecycle management, the administrator must assign the Cluster Administrator role to the operations group. This role provides the specific permissions needed to perform actions such as scaling, patching, and modifying the configuration of Supervisor or TKG clusters. By scoping this at the cluster level (or within the project containing those clusters), the operations group is empowered to maintain the resources without having broad administrative access to other organizational settings. For the second requirement, the Security Administrator role in NSX must be assigned to the network administrators group. By scoping this to the project, the network admins can manage distributed firewall rules, gateway policies, and security profiles specific to that project's VPCs while being prevented from interfering with the compute lifecycle managed by the operations team. This separation of duties is essential for large-scale enterprise deployments to prevent unauthorized security changes or accidental cluster disruptions.


Contribute your Thoughts:

0/2000 characters
Alaine
29 days ago
I disagree, I think A is necessary too.
upvoted 0 times
...
Dannette
1 month ago
B and D seem like the right picks for this.
upvoted 0 times
...
Daniel
2 months ago
I’m leaning towards the Service User role for the operations group, but I’m not entirely confident if that meets the lifecycle operation requirement.
upvoted 0 times
...
Lavelle
2 months ago
I practiced a similar question where we had to restrict access, and I feel like the Cluster Administrator role might be too broad for just scaling operations.
upvoted 0 times
...
Ettie
2 months ago
I think assigning the Security Administrator role to the network admins at the project level makes sense, but I’m a bit confused about the cluster role for the operations group.
upvoted 0 times
...
Rebbecca
2 months ago
I remember that the operations group needs specific roles for lifecycle operations, but I'm not sure if Service User or Service Viewer is the right choice.
upvoted 0 times
...

Save Cancel