nerdexam
Novell

050-696 · Question #156

Your company has four regional offices. You are the head Network administrator for the entire organization. Each regional office has its own network administrator. You want to designate each…

The correct answer is F. The Supervisor right to topmost container in their context. G. All rights to the topmost container in their context. Scoped container administrator delegation in Novell eDirectory requires granting elevated rights at the topmost container of each admin's own context rather than at the tree root, which would grant tree-wide authority.

Novell eDirectory Management

Question

Your company has four regional offices. You are the head Network administrator for the entire organization. Each regional office has its own network administrator. You want to designate each regional network administrator as the container administrator for his or her own context in the tree, but not for any other context. Which rights assignment should you make for each container administrator? (Choose 2.)

Options

  • AThe Create right to the root of the tree.
  • BThe Delete right to the root of the tree.
  • CThe Create right to the Security container.
  • DThe Delete right to the Security container.
  • EThe Supervisor right to the root of the tree.
  • FThe Supervisor right to topmost container in their context.
  • GAll rights to the topmost container in their context.

How the community answered

(37 responses)
  • C
    5% (2)
  • D
    3% (1)
  • E
    8% (3)
  • F
    84% (31)

Why each option

Scoped container administrator delegation in Novell eDirectory requires granting elevated rights at the topmost container of each admin's own context rather than at the tree root, which would grant tree-wide authority.

AThe Create right to the root of the tree.

The Create right at the tree root allows the admin to create objects anywhere in the entire tree, violating the requirement to limit authority to their own context.

BThe Delete right to the root of the tree.

The Delete right at the tree root permits deletion of any object in the entire tree, granting far more authority than intended for a regional administrator.

CThe Create right to the Security container.

Granting rights to the Security container gives access to sensitive tree-wide security objects and is unrelated to regional container administration.

DThe Delete right to the Security container.

The Delete right on the Security container could allow destruction of critical authentication and security objects, which is inappropriate and dangerous for a regional admin.

EThe Supervisor right to the root of the tree.

The Supervisor right at the tree root would give every regional admin full authority over the entire directory tree, not just their own regional context.

FThe Supervisor right to topmost container in their context.Correct

Assigning the Supervisor right to the topmost container of each admin's own context grants full administrative control over that subtree and all its objects, while keeping authority bounded to that region because the Supervisor right does not flow up the tree.

GAll rights to the topmost container in their context.Correct

Explicitly assigning all object and property rights to the topmost container in their context achieves equivalent scoped delegation, ensuring each admin manages only their own regional subtree without affecting other contexts.

Concept tested: Delegating scoped container administrator rights in eDirectory

Source: https://www.novell.com/documentation/edir88/pdfdoc/edir_admin/edir_admin.pdf

Topics

#container administrator#Supervisor right#distributed administration#eDirectory rights delegation

Community Discussion

No community discussion yet for this question.

Full 050-696 Practice