nerdexam
Broadcom-VMware

2V0-621 · Question #221

Which three components should an administrator select when configuring vSphere permissions? (Choose three.)

The correct answer is A. Inventory Object B. Role C. User/Group. vSphere permissions are constructed from three components: an inventory object (the scope), a role (the set of privileges), and a user or group (the principal) - combining all three defines who can do what on which object.

Section 1 – Configure and Administer vSphere 6.x Security

Question

Which three components should an administrator select when configuring vSphere permissions? (Choose three.)

Options

  • AInventory Object
  • BRole
  • CUser/Group
  • DPrivilege
  • EPassword

How the community answered

(45 responses)
  • A
    96% (43)
  • D
    2% (1)
  • E
    2% (1)

Why each option

vSphere permissions are constructed from three components: an inventory object (the scope), a role (the set of privileges), and a user or group (the principal) - combining all three defines who can do what on which object.

AInventory ObjectCorrect

The Inventory Object specifies the target in the vSphere hierarchy to which the permission applies, such as a datacenter, cluster, host, or virtual machine. Without selecting an inventory object there is no scope for the permission to be enforced.

BRoleCorrect

The Role is a named collection of privileges defining what operations are permitted on the selected object. Roles can be built-in (such as Administrator or Read-Only) or custom, and must be paired with a user/group and an inventory object to form a complete permission.

CUser/GroupCorrect

The User/Group identifies the principal - either an individual user or a group from a connected identity source or vsphere.local - that receives the assigned role. Selecting a user or group completes the three-part permission definition along with the inventory object and role.

DPrivilege

Privileges are the individual action rights that compose a role and are not selected directly during permission assignment - the role (which bundles privileges) is what gets assigned.

EPassword

Password is an authentication credential used during login and plays no part in defining or assigning a vSphere permission.

Concept tested: vSphere permissions three-component model

Source: https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.security.doc/GUID-41E5E52E-A95B-4E81-9724-6AD6800BEF78.html

Topics

#vSphere permissions#roles#inventory objects#user/group assignment

Community Discussion

No community discussion yet for this question.

Full 2V0-621 Practice