nerdexam
Broadcom-VMware

2V0-621 · Question #3

An administrator with global administrator privileges creates a custom role but fails to assign any privileges to it. Which two privileges would the custom role have? (Choose two.)

The correct answer is A. System.View B. System.Anonymous. vCenter Server automatically assigns System.Anonymous and System.View to every role, including custom roles with no explicitly granted privileges.

Section 1 – Configure and Administer vSphere 6.x Security

Question

An administrator with global administrator privileges creates a custom role but fails to assign any privileges to it. Which two privileges would the custom role have? (Choose two.)

Options

  • ASystem.View
  • BSystem.Anonymous
  • CSystem.User
  • DSystem.ReadOnly

How the community answered

(19 responses)
  • A
    95% (18)
  • C
    5% (1)

Why each option

vCenter Server automatically assigns System.Anonymous and System.View to every role, including custom roles with no explicitly granted privileges.

ASystem.ViewCorrect

System.View is automatically granted to all roles in vCenter and allows the role to view the objects that other assigned privileges apply to; it cannot be removed from any role.

BSystem.AnonymousCorrect

System.Anonymous is the most basic system privilege, automatically present on every role, allowing minimal unauthenticated awareness of the vCenter environment without exposing any managed objects.

CSystem.User

System.User is not automatically assigned to empty custom roles; it is a privilege associated with logged-in user sessions and is not a default privilege on new custom roles.

DSystem.ReadOnly

System.ReadOnly is not automatically granted to custom roles with no privileges; the Read-Only role holds this privilege, but it is not inherited by new custom roles automatically.

Concept tested: vCenter default system privileges on custom roles

Source: https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-ED56F3C4-77D0-49E3-88B6-B99B8B437B62.html

Topics

#custom roles#system privileges#System.View#System.Anonymous

Community Discussion

No community discussion yet for this question.

Full 2V0-621 Practice