300-615 · Question #259
A Cisco ACI fabric consists of three tenants. User1 must have permission to manage only the PROD tenant. These configurations have already been completed: - The security domain TENANT has been…
The correct answer is B. Associate security domain TENANT to tenant PROD. The issue is that User1 has access to all tenants because the security domain configuration is incomplete. To restrict User1's access to only the PROD tenant, the security domain TENANT must be associated specifically with the PROD tenant. This association ensures that User1's…
Question
A Cisco ACI fabric consists of three tenants. User1 must have permission to manage only the PROD tenant. These configurations have already been completed:
- The security domain TENANT has been created.
- User1 has been created with the "write" privilege level.
- User1 has access to all leaf nodes.
The configuration was deployed, but User1 still has access to all the other tenants. Which action resolves the issue?
Options
- AAttach local user User1 to security domain all.
- BAssociate security domain TENANT to tenant PROD.
- CAdd local user User1 to the RBAC node rule.
- DEnable the restricted domain under security domain TENANT.
How the community answered
(20 responses)- A5% (1)
- B80% (16)
- C10% (2)
- D5% (1)
Explanation
The issue is that User1 has access to all tenants because the security domain configuration is incomplete. To restrict User1's access to only the PROD tenant, the security domain TENANT must be associated specifically with the PROD tenant. This association ensures that User1's access is limited to managing only the PROD tenant and no others.
Topics
Community Discussion
No community discussion yet for this question.