050-696 · Question #156
Your company has four regional offices. You are the head Network administrator for the entire organization. Each regional office has its own network administrator. You want to designate each…
The correct answer is F. The Supervisor right to topmost container in their context. G. All rights to the topmost container in their context. Scoped container administrator delegation in Novell eDirectory requires granting elevated rights at the topmost container of each admin's own context rather than at the tree root, which would grant tree-wide authority.
Question
Options
- AThe Create right to the root of the tree.
- BThe Delete right to the root of the tree.
- CThe Create right to the Security container.
- DThe Delete right to the Security container.
- EThe Supervisor right to the root of the tree.
- FThe Supervisor right to topmost container in their context.
- GAll rights to the topmost container in their context.
How the community answered
(37 responses)- C5% (2)
- D3% (1)
- E8% (3)
- F84% (31)
Why each option
Scoped container administrator delegation in Novell eDirectory requires granting elevated rights at the topmost container of each admin's own context rather than at the tree root, which would grant tree-wide authority.
The Create right at the tree root allows the admin to create objects anywhere in the entire tree, violating the requirement to limit authority to their own context.
The Delete right at the tree root permits deletion of any object in the entire tree, granting far more authority than intended for a regional administrator.
Granting rights to the Security container gives access to sensitive tree-wide security objects and is unrelated to regional container administration.
The Delete right on the Security container could allow destruction of critical authentication and security objects, which is inappropriate and dangerous for a regional admin.
The Supervisor right at the tree root would give every regional admin full authority over the entire directory tree, not just their own regional context.
Assigning the Supervisor right to the topmost container of each admin's own context grants full administrative control over that subtree and all its objects, while keeping authority bounded to that region because the Supervisor right does not flow up the tree.
Explicitly assigning all object and property rights to the topmost container in their context achieves equivalent scoped delegation, ensuring each admin manages only their own regional subtree without affecting other contexts.
Concept tested: Delegating scoped container administrator rights in eDirectory
Source: https://www.novell.com/documentation/edir88/pdfdoc/edir_admin/edir_admin.pdf
Topics
Community Discussion
No community discussion yet for this question.