nerdexam
Broadcom-VMware

2V0-622 · Question #214

Review the Exhibit. An administrator has configured permissions for a group called VMGroup and a user named VMUser. A new Role has been created called PowerVM. The group and role have these…

The correct answer is A. The VMUser permission overrides the VMGroup permission. In vSphere, a direct user permission on an object always takes precedence over a group-inherited permission on the same object, so VMUser's No Access assignment blocks all access despite group membership.

Section 1 – Configure and Administer vSphere 6.5 Security

Question

Review the Exhibit. An administrator has configured permissions for a group called VMGroup and a user named VMUser. A new Role has been created called PowerVM. The group and role have these charecteristics:

-PowerVM role can power on VMs -VMGroup granted PowerVM role on VMFolder -VMUser is a member of VMGroup -VMUser granted No Access on VMFolder Based on the exhibit, which statement best explains why VMUser is denied access to the VMFolder?

Exhibit

2V0-622 question #214 exhibit

Options

  • AThe VMUser permission overrides the VMGroup permission.
  • BThe No Access role overrides the PowerVM role.
  • CThe VMGroup permission overrides the VMUser permission.
  • DThe PowerVM role overrides the No Access role.

How the community answered

(33 responses)
  • A
    82% (27)
  • B
    9% (3)
  • C
    6% (2)
  • D
    3% (1)

Why each option

In vSphere, a direct user permission on an object always takes precedence over a group-inherited permission on the same object, so VMUser's No Access assignment blocks all access despite group membership.

AThe VMUser permission overrides the VMGroup permission.Correct

In vSphere's permission model, when a user has both a direct permission and an inherited group permission on the same inventory object, the user-specific permission always takes precedence. VMUser has No Access assigned directly on VMFolder, which overrides the PowerVM role that VMGroup grants on the same object. This is a fundamental vSphere permission hierarchy rule - user-level permissions win over group-level permissions at the same scope.

BThe No Access role overrides the PowerVM role.

The No Access role does not generically override other roles by its type; it is the user-level assignment that wins over the group assignment, not the role name itself.

CThe VMGroup permission overrides the VMUser permission.

This reverses the actual vSphere permission precedence rule; group permissions do not override user-specific permissions on the same object - user permissions take priority.

DThe PowerVM role overrides the No Access role.

The PowerVM role does not override No Access; vSphere prioritizes the directly assigned user permission regardless of which specific roles are involved.

Concept tested: vSphere user vs group permission precedence on same object

Source: https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-5372F580-5C23-4E9C-8A4E-EF1B4DD9033E.html

Topics

#permissions#No Access role#user vs group precedence#role inheritance

Community Discussion

No community discussion yet for this question.

Full 2V0-622 Practice