nerdexam
Broadcom-VMware

2V0-622 · Question #223

An administrator has configured three vCenter Servers and vRealize Orchestrator within a Platform Services Controller domain, and needs to grant a user privileges that span all environments. Which…

The correct answer is A. Assign a Global Permission to the user. Global Permissions are the only permission type in vSphere that apply across all vCenter Servers and solutions tied to the same Platform Services Controller SSO domain.

Section 1 – Configure and Administer vSphere 6.5 Security

Question

An administrator has configured three vCenter Servers and vRealize Orchestrator within a Platform Services Controller domain, and needs to grant a user privileges that span all environments. Which statement best describes how the administrator would accomplish this?

Options

  • AAssign a Global Permission to the user.
  • BAssign a vCenter Permission to the user.
  • CAssign vsphere.local membership to the user.
  • DAssign an ESXi Permission to the user.

How the community answered

(35 responses)
  • A
    71% (25)
  • B
    3% (1)
  • C
    17% (6)
  • D
    9% (3)

Why each option

Global Permissions are the only permission type in vSphere that apply across all vCenter Servers and solutions tied to the same Platform Services Controller SSO domain.

AAssign a Global Permission to the user.Correct

A Global Permission is assigned at the global root object in the vSphere inventory hierarchy, causing it to propagate down to all vCenter Server instances and solutions such as vRealize Orchestrator that are registered with the same Platform Services Controller domain. This makes it the single correct mechanism for granting a user consistent privileges spanning all environments in one assignment.

BAssign a vCenter Permission to the user.

A vCenter Permission is scoped to a single vCenter Server inventory and its objects, so it cannot span additional vCenter Servers or vRealize Orchestrator.

CAssign vsphere.local membership to the user.

vsphere.local group membership controls SSO domain authentication, not authorization - it does not grant inventory-level permissions across vCenter or vRealize Orchestrator environments.

DAssign an ESXi Permission to the user.

An ESXi Permission applies only to that individual host and its local objects, with no ability to extend to vCenter Server or vRealize Orchestrator.

Concept tested: vSphere Global Permissions spanning multiple vCenter instances

Source: https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.security.doc/GUID-74F53189-EF41-4AC1-A78E-D25621855800.html

Topics

#global permissions#Platform Services Controller#SSO domain#multi-vCenter

Community Discussion

No community discussion yet for this question.

Full 2V0-622 Practice