300-625 · Question #9
Refer to the exhibit. The san-user must configure FSPF on the VSAN 500, but fails. An operator with network administrative rights must authorize the san-user to perform this work. Which…
The correct answer is D. MDS-A(config)# role name sangroup. Note: The answer choices in this question appear to have a display/rendering issue - all four options show only the first line (MDS-A(config)# role name sangroup) without the critical sub-commands that distinguish them. The exhibit is also missing. The explanation below is…
Question
Refer to the exhibit. The san-user must configure FSPF on the VSAN 500, but fails. An operator with network administrative rights must authorize the san-user to perform this work. Which configuration must the operator apply?
Exhibit
Options
- AMDS-A(config)# role name sangroup
- BMDS-A(config)# role name sangroup
- CMDS-A(config)# role name sangroup
- DMDS-A(config)# role name sangroup
How the community answered
(34 responses)- A12% (4)
- B3% (1)
- C3% (1)
- D82% (28)
Explanation
Note: The answer choices in this question appear to have a display/rendering issue - all four options show only the first line (MDS-A(config)# role name sangroup) without the critical sub-commands that distinguish them. The exhibit is also missing. The explanation below is based on the underlying Cisco MDS RBAC concept being tested.
Option D is correct because it contains the complete role configuration that both permits the FSPF-related commands and scopes that permission to VSAN 500 specifically - the combination needed to authorize san-user without granting broader network access. On Cisco MDS switches, RBAC roles require explicit rule statements defining permitted commands; simply creating a role name grants nothing by itself.
The distractors (A, B, C) are wrong because they likely each omit or misconfigure one element: A probably grants the permission but without VSAN scope, B may use incorrect command syntax or the wrong rule action (e.g., deny instead of permit), and C likely scopes to the wrong VSAN or grants read-only access when read-write is required for configuration tasks.
Memory tip: Think of Cisco MDS RBAC as needing three things to work - a role name, a rule with permit + the right command scope, and a VSAN policy if the task is VSAN-specific. Missing any one of these three elements means the user can't do the job. "Name, Rule, VSAN - all three or none."
Topics
Community Discussion
No community discussion yet for this question.
