200-155 · Question #184
Which two privilege types can you associate to the role of a Cisco ACI fabric user? (Choose two)
The correct answer is B. read E. write. Cisco ACI fabric user roles define the level of access a user has to the fabric's configurations and operational states. The two fundamental privilege types that can be associated with these roles are 'read' for viewing and 'write' for modifying.
Question
Which two privilege types can you associate to the role of a Cisco ACI fabric user? (Choose two)
Options
- Aadmin
- Bread
- Cenable
- Dfull accesss
- Ewrite
How the community answered
(35 responses)- A3% (1)
- B89% (31)
- C3% (1)
- D6% (2)
Why each option
Cisco ACI fabric user roles define the level of access a user has to the fabric's configurations and operational states. The two fundamental privilege types that can be associated with these roles are 'read' for viewing and 'write' for modifying.
'admin' is typically a predefined role with extensive privileges, rather than a granular privilege type like 'read' or 'write' that can be associated with a custom role.
The 'read' privilege type allows a user to view the configuration, operational state, and performance data within the Cisco ACI fabric without making any changes, which is essential for monitoring and auditing purposes.
'enable' is a command often used for privilege escalation in traditional Cisco IOS devices, not a privilege type directly associated with Cisco ACI user roles.
'full access' is a descriptive term for a high level of permission, but it is not one of the specific, granular privilege types (like 'read' or 'write') defined within Cisco ACI's role-based access control.
The 'write' privilege type grants a user the ability to create, modify, or delete configurations and make changes to the operational state within the Cisco ACI fabric, enabling them to perform administrative tasks that alter the fabric's state or configuration.
Concept tested: Cisco ACI user role privileges
Source: https://www.cisco.com/c/en/us/td/docs/dcn/aci/apic/5x/security/cisco-aci-security-config-guide-52x/m-rbac.html
Topics
Community Discussion
No community discussion yet for this question.