2V0-621 · Question #222
In which two vsphere.local groups should an administrator avoid adding members? (Choose two.)
The correct answer is A. SolutionUsers B. Administrators. SolutionUsers and Administrators are vsphere.local built-in groups that VMware explicitly warns against populating with additional members due to security and service-integrity risks.
Question
In which two vsphere.local groups should an administrator avoid adding members? (Choose two.)
Options
- ASolutionUsers
- BAdministrators
- CDCAdmins
- DExternalPDUsers
How the community answered
(52 responses)- A87% (45)
- C10% (5)
- D4% (2)
Why each option
SolutionUsers and Administrators are vsphere.local built-in groups that VMware explicitly warns against populating with additional members due to security and service-integrity risks.
SolutionUsers is a reserved vsphere.local group automatically populated by vSphere solution components (such as vCenter services) for machine-to-machine certificate-based authentication. Adding human user accounts to this group can disrupt inter-service trust and violates the intended use of the group.
The vsphere.local Administrators group grants the highest level of SSO domain and vCenter privileges across the environment. VMware guidance recommends against assigning users here for day-to-day operations, favoring least-privilege custom roles to limit the blast radius of a compromised account.
DCAdmins is not a built-in vsphere.local group referenced in VMware security guidance as off-limits for membership; it is not one of the groups VMware warns administrators to leave unpopulated.
ExternalPDUsers is a vsphere.local group used to sync users from external platform domains and is not flagged in VMware documentation as a group that administrators should avoid adding members to.
Concept tested: vsphere.local built-in group membership restrictions
Source: https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.security.doc/GUID-3B78EEB3-23E2-4CEB-9FBD-E432B606011D.html
Topics
Community Discussion
No community discussion yet for this question.