2V0-621 · Question #3
An administrator with global administrator privileges creates a custom role but fails to assign any privileges to it. Which two privileges would the custom role have? (Choose two.)
The correct answer is A. System.View B. System.Anonymous. vCenter Server automatically assigns System.Anonymous and System.View to every role, including custom roles with no explicitly granted privileges.
Question
An administrator with global administrator privileges creates a custom role but fails to assign any privileges to it. Which two privileges would the custom role have? (Choose two.)
Options
- ASystem.View
- BSystem.Anonymous
- CSystem.User
- DSystem.ReadOnly
How the community answered
(19 responses)- A95% (18)
- C5% (1)
Why each option
vCenter Server automatically assigns System.Anonymous and System.View to every role, including custom roles with no explicitly granted privileges.
System.View is automatically granted to all roles in vCenter and allows the role to view the objects that other assigned privileges apply to; it cannot be removed from any role.
System.Anonymous is the most basic system privilege, automatically present on every role, allowing minimal unauthenticated awareness of the vCenter environment without exposing any managed objects.
System.User is not automatically assigned to empty custom roles; it is a privilege associated with logged-in user sessions and is not a default privilege on new custom roles.
System.ReadOnly is not automatically granted to custom roles with no privileges; the Read-Only role holds this privilege, but it is not inherited by new custom roles automatically.
Concept tested: vCenter default system privileges on custom roles
Source: https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-ED56F3C4-77D0-49E3-88B6-B99B8B437B62.html
Topics
Community Discussion
No community discussion yet for this question.