nerdexam
Cisco

300-620 · Question #379

An engineer configures two Cisco ACI objects: - Security domain Dom_1 - Local user called User1 Which role privilege must be assigned to security domains so that User1 can access only policies for int

The correct answer is B. access-connectivity-util. The fabric-connectivity-l1 privilege allows a user to view and modify interface-level policies (such as interface selectors) without granting broader fabric or tenant permissions. This is the required privilege for limiting User1 to interface selector policies within the assigned

ACI Management and Operations

Question

An engineer configures two Cisco ACI objects:

  • Security domain Dom_1
  • Local user called User1

Which role privilege must be assigned to security domains so that User1 can access only policies for interface selectors?

Options

  • Afabric-connectivity-l1
  • Baccess-connectivity-util
  • Cnw-svc-devshare
  • Dout-of-band bridge domain

How the community answered

(63 responses)
  • A
    24% (15)
  • B
    59% (37)
  • C
    11% (7)
  • D
    6% (4)

Explanation

The fabric-connectivity-l1 privilege allows a user to view and modify interface-level policies (such as interface selectors) without granting broader fabric or tenant permissions. This is the required privilege for limiting User1 to interface selector policies within the assigned security domain.

Topics

#RBAC#security domains#role privileges#interface selectors

Community Discussion

No community discussion yet for this question.

Full 300-620 Practice