1Y0-253 · Question #70
Scenario: An administrator configured an LDAP authentication policy and bound it globally. The only system group configured on the Netscaler is NS_Admins. After reviewing the security logs, the…
The correct answer is C. Specify (!(memberOf="CN=External_Contractors, CN=Groups, CN=example, CN=com")) as a filter. See the full explanation below for the reasoning.
Question
Scenario: An administrator configured an LDAP authentication policy and bound it globally. The only system group configured on the Netscaler is NS_Admins. After reviewing the security logs, the administrator notices that users in the External_Contractors LDAP group are able to log on to NetScaler using SSH; however, members of the External_Contractors group are NOT authorized to run any commands. Which action could the administrator take to prevent the members of the External_Contractors LDAP Group from logging on to NetScaler using SSH without affecting other users?
Options
- AConfigure an authorization policy that allows logon only by members of the "External_Contractors"
- BSpecify (memberOf="CN=External_Contractors, CN=Groups, CN=example, CN=com") as a filter
- CSpecify (!(memberOf="CN=External_Contractors, CN=Groups, CN=example, CN=com")) as a filter
- DCreate a new command policy with a DENY action. Create a System Group named "External_Contractors"
How the community answered
(43 responses)- A5% (2)
- B12% (5)
- C79% (34)
- D5% (2)
Community Discussion
No community discussion yet for this question.