nerdexam
Cisco

300-625 · Question #9

Refer to the exhibit. The san-user must configure FSPF on the VSAN 500, but fails. An operator with network administrative rights must authorize the san-user to perform this work. Which…

The correct answer is D. MDS-A(config)# role name sangroup. Note: The answer choices in this question appear to have a display/rendering issue - all four options show only the first line (MDS-A(config)# role name sangroup) without the critical sub-commands that distinguish them. The exhibit is also missing. The explanation below is…

Management and Monitoring

Question

Refer to the exhibit. The san-user must configure FSPF on the VSAN 500, but fails. An operator with network administrative rights must authorize the san-user to perform this work. Which configuration must the operator apply?

Exhibit

300-625 question #9 exhibit

Options

  • AMDS-A(config)# role name sangroup
  • BMDS-A(config)# role name sangroup
  • CMDS-A(config)# role name sangroup
  • DMDS-A(config)# role name sangroup

How the community answered

(34 responses)
  • A
    12% (4)
  • B
    3% (1)
  • C
    3% (1)
  • D
    82% (28)

Explanation

Note: The answer choices in this question appear to have a display/rendering issue - all four options show only the first line (MDS-A(config)# role name sangroup) without the critical sub-commands that distinguish them. The exhibit is also missing. The explanation below is based on the underlying Cisco MDS RBAC concept being tested.


Option D is correct because it contains the complete role configuration that both permits the FSPF-related commands and scopes that permission to VSAN 500 specifically - the combination needed to authorize san-user without granting broader network access. On Cisco MDS switches, RBAC roles require explicit rule statements defining permitted commands; simply creating a role name grants nothing by itself.

The distractors (A, B, C) are wrong because they likely each omit or misconfigure one element: A probably grants the permission but without VSAN scope, B may use incorrect command syntax or the wrong rule action (e.g., deny instead of permit), and C likely scopes to the wrong VSAN or grants read-only access when read-write is required for configuration tasks.

Memory tip: Think of Cisco MDS RBAC as needing three things to work - a role name, a rule with permit + the right command scope, and a VSAN policy if the task is VSAN-specific. Missing any one of these three elements means the user can't do the job. "Name, Rule, VSAN - all three or none."

Topics

#RBAC#FSPF Configuration#MDS Authorization#Role Management

Community Discussion

No community discussion yet for this question.

Full 300-625 Practice