2V0-622 · Question #214
Review the Exhibit. An administrator has configured permissions for a group called VMGroup and a user named VMUser. A new Role has been created called PowerVM. The group and role have these…
The correct answer is A. The VMUser permission overrides the VMGroup permission. In vSphere, a direct user permission on an object always takes precedence over a group-inherited permission on the same object, so VMUser's No Access assignment blocks all access despite group membership.
Question
Review the Exhibit. An administrator has configured permissions for a group called VMGroup and a user named VMUser. A new Role has been created called PowerVM. The group and role have these charecteristics:
-PowerVM role can power on VMs -VMGroup granted PowerVM role on VMFolder -VMUser is a member of VMGroup -VMUser granted No Access on VMFolder Based on the exhibit, which statement best explains why VMUser is denied access to the VMFolder?
Exhibit
Options
- AThe VMUser permission overrides the VMGroup permission.
- BThe No Access role overrides the PowerVM role.
- CThe VMGroup permission overrides the VMUser permission.
- DThe PowerVM role overrides the No Access role.
How the community answered
(33 responses)- A82% (27)
- B9% (3)
- C6% (2)
- D3% (1)
Why each option
In vSphere, a direct user permission on an object always takes precedence over a group-inherited permission on the same object, so VMUser's No Access assignment blocks all access despite group membership.
In vSphere's permission model, when a user has both a direct permission and an inherited group permission on the same inventory object, the user-specific permission always takes precedence. VMUser has No Access assigned directly on VMFolder, which overrides the PowerVM role that VMGroup grants on the same object. This is a fundamental vSphere permission hierarchy rule - user-level permissions win over group-level permissions at the same scope.
The No Access role does not generically override other roles by its type; it is the user-level assignment that wins over the group assignment, not the role name itself.
This reverses the actual vSphere permission precedence rule; group permissions do not override user-specific permissions on the same object - user permissions take priority.
The PowerVM role does not override No Access; vSphere prioritizes the directly assigned user permission regardless of which specific roles are involved.
Concept tested: vSphere user vs group permission precedence on same object
Source: https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-5372F580-5C23-4E9C-8A4E-EF1B4DD9033E.html
Topics
Community Discussion
No community discussion yet for this question.
