nerdexam
Broadcom-VMware

2V0-621 · Question #220

Which three Authorization types are valid in vSphere? (Choose three.)

The correct answer is A. Group Membership in vsphere.local B. Global D. vCenter Server. This question tests knowledge of the three valid authorization scope types in vSphere that control how roles and permissions are assigned to users and groups across the environment.

Section 1 – Configure and Administer vSphere 6.x Security

Question

Which three Authorization types are valid in vSphere? (Choose three.)

Options

  • AGroup Membership in vsphere.local
  • BGlobal
  • CForest
  • DvCenter Server
  • EGroup Membership in system-domain

How the community answered

(56 responses)
  • A
    88% (49)
  • C
    4% (2)
  • E
    9% (5)

Why each option

This question tests knowledge of the three valid authorization scope types in vSphere that control how roles and permissions are assigned to users and groups across the environment.

AGroup Membership in vsphere.localCorrect

Group Membership in vsphere.local is a valid vSphere authorization method - vsphere.local is the built-in vSphere Single Sign-On identity domain, and groups defined within it (such as the Administrators group) can be assigned roles and applied as permissions on vCenter inventory objects.

BGlobalCorrect

Global permissions are a valid vSphere authorization type that apply at the root level across all solutions registered with the Platform Services Controller, including vCenter Server and Site Recovery Manager, and propagate to every object in the entire hierarchy.

CForest

Forest is an Active Directory concept that describes a collection of AD domains sharing a common schema - it is not a recognized authorization type or permission scope within the vSphere security model.

DvCenter ServerCorrect

vCenter Server permissions are a valid authorization type that apply role-based access control to objects within a specific vCenter Server's inventory hierarchy, giving administrators the ability to grant scoped access to individual objects or entire subtrees.

EGroup Membership in system-domain

The correct name for the built-in vSphere SSO identity domain is 'vsphere.local', not 'system-domain' - 'system-domain' is not a valid vSphere identity source or recognized authorization group context.

Concept tested: vSphere valid authorization types - global, vCenter, and SSO group

Source: https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.security.doc/GUID-5372F580-5C23-4E9C-8A4E-EF1B4DD9033E.html

Topics

#authorization types#vsphere.local#vCenter Server permissions#global permissions

Community Discussion

No community discussion yet for this question.

Full 2V0-621 Practice