nerdexam
Cisco

350-601 · Question #266

A company is running a pair of cisco Nexus 7706 series switches as part of a data center segment. All network engineers have restricted read-Write access to the core switches. A network engineer…

The correct answer is A. 1. Create a user-defined role and add the required privileges. Since all engineers have restricted (not full) read-write access, the correct approach under Cisco NX-OS RBAC is to create a user-defined (custom) role and grant it only the specific privileges needed - such as VLAN and FCoE configuration - without elevating the user to a fully…

Security

Question

A company is running a pair of cisco Nexus 7706 series switches as part of a data center segment. All network engineers have restricted read-Write access to the core switches. A network engineer must a new FCoE VLAN to allow traffic from services toward FCoE storage. Which set of actions must be taken to meet these requirements?

Options

  • A
    1. Create a user-defined role and add the required privileges.
  • B
    1. Add the required privilege to the VDC-admin role.
  • C
    1. Modify a network-operator role and add the required privileges.
  • D
    1. Assign the network-admin role to a user.

How the community answered

(28 responses)
  • A
    71% (20)
  • B
    14% (4)
  • C
    11% (3)
  • D
    4% (1)

Explanation

Since all engineers have restricted (not full) read-write access, the correct approach under Cisco NX-OS RBAC is to create a user-defined (custom) role and grant it only the specific privileges needed - such as VLAN and FCoE configuration - without elevating the user to a fully privileged role. Option D (assigning network-admin) would grant unrestricted access, violating the restricted access policy. Option B (modifying VDC-admin) modifies a built-in role, which is not best practice and may affect other users. Option C (modifying network-operator) modifies a read-only built-in role. Creating a tailored custom role follows the principle of least privilege and meets the stated requirement.

Topics

#Cisco Nexus RBAC#Access Control#Privilege Management#FCoE

Community Discussion

No community discussion yet for this question.

Full 350-601 Practice