nerdexam
Cisco

210-060 · Question #293

A system administrator needs to grant additional privileges to a single Cisco Unified Communications Manager user. How should the administrator accomplish this task?

The correct answer is C. assign an access control group to a new role. In Cisco Unified Communications Manager, administrative privileges flow through Roles assigned to Access Control Groups (ACGs), not directly to individual users.

Users, Mobility, and Presence

Question

A system administrator needs to grant additional privileges to a single Cisco Unified Communications Manager user. How should the administrator accomplish this task?

Options

  • Aassign a new role to the user
  • Badd the user to a new role
  • Cassign an access control group to a new role
  • Dadd the user to a new access control group

How the community answered

(26 responses)
  • A
    15% (4)
  • B
    8% (2)
  • C
    73% (19)
  • D
    4% (1)

Why each option

In Cisco Unified Communications Manager, administrative privileges flow through Roles assigned to Access Control Groups (ACGs), not directly to individual users.

Aassign a new role to the user

CUCM does not permit roles to be directly assigned to individual user accounts; privilege escalation must occur through Access Control Group membership.

Badd the user to a new role

In CUCM, users are not added to roles; roles are assigned to Access Control Groups, and users gain privileges through their ACG membership.

Cassign an access control group to a new roleCorrect

CUCM enforces a role-based access model where Roles - containing specific resource and privilege definitions - are assigned to Access Control Groups; assigning an ACG to a new role links those privileges to all users who are members of that ACG, which is the architecturally correct method for extending privileges. This ACG-to-role binding is the required mechanism in CUCM because the platform does not support direct role assignment to individual user accounts.

Dadd the user to a new access control group

Adding a user to a new, empty Access Control Group confers no additional privileges unless that ACG already has appropriate roles assigned to it.

Concept tested: CUCM role-based access control via Access Control Groups

Source: https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/14/adminGuide/cucm_b_cisco-unified-communications-manager-administration-guide-14.html

Topics

#CUCM user privileges#access control group#roles#user administration

Community Discussion

No community discussion yet for this question.

Full 210-060 Practice