300-620 · Question #228
An engineer must configure a new local user inside a Cisco ACI. The new user must meet these criteria: - Must be provided with complete read-only access to the tenant. - Must be permitted to create an
The correct answer is B. Create a new role with tenant-epg privilege.. tenant-epg privilege Used for managing tenant configurations such as deleting/creating endpoint groups. Used for managing tenant configurations such as deleting/creating endpoint groups, VRFs, and Role: tenant-admin Used for configuring authentication, authorization, accouting an
Question
An engineer must configure a new local user inside a Cisco ACI. The new user must meet these criteria:
- Must be provided with complete read-only access to the tenant.
- Must be permitted to create and delete EPGs within a specific tenant.
- Must not be allowed to modify any other objects within that tenant.
The tenant and security domain association is already in place. Which configuration set configures the new tenant?
Options
- ACreate a new role with tenant-admin privilege.
- BCreate a new role with tenant-epg privilege.
- CCreate a new role with tenant-connectivity privilege.
- DCreate a new role with tenant-security privilege.
How the community answered
(23 responses)- A4% (1)
- B74% (17)
- C17% (4)
- D4% (1)
Explanation
tenant-epg privilege Used for managing tenant configurations such as deleting/creating endpoint groups. Used for managing tenant configurations such as deleting/creating endpoint groups, VRFs, and Role: tenant-admin Used for configuring authentication, authorization, accouting and import/export policies. access-connectivity-l1 Used for Layer 1 configuration under infra. Example: selectors and port Layer 1 policy tenant-connectivity-util Used for atomic counter, diagnostic, and image management policies on leaf switches and spine Used for contract-related configurations for a tenant. Security-Configuration-Guide-401/b_Cisco_APIC_Security_Guide_chapter_01000.html
Topics
Community Discussion
No community discussion yet for this question.