350-601 · Question #266
A company is running a pair of cisco Nexus 7706 series switches as part of a data center segment. All network engineers have restricted read-Write access to the core switches. A network engineer…
The correct answer is A. 1. Create a user-defined role and add the required privileges. Since all engineers have restricted (not full) read-write access, the correct approach under Cisco NX-OS RBAC is to create a user-defined (custom) role and grant it only the specific privileges needed - such as VLAN and FCoE configuration - without elevating the user to a fully…
Question
A company is running a pair of cisco Nexus 7706 series switches as part of a data center segment. All network engineers have restricted read-Write access to the core switches. A network engineer must a new FCoE VLAN to allow traffic from services toward FCoE storage. Which set of actions must be taken to meet these requirements?
Options
- A
- Create a user-defined role and add the required privileges.
- B
- Add the required privilege to the VDC-admin role.
- C
- Modify a network-operator role and add the required privileges.
- D
- Assign the network-admin role to a user.
How the community answered
(28 responses)- A71% (20)
- B14% (4)
- C11% (3)
- D4% (1)
Explanation
Since all engineers have restricted (not full) read-write access, the correct approach under Cisco NX-OS RBAC is to create a user-defined (custom) role and grant it only the specific privileges needed - such as VLAN and FCoE configuration - without elevating the user to a fully privileged role. Option D (assigning network-admin) would grant unrestricted access, violating the restricted access policy. Option B (modifying VDC-admin) modifies a built-in role, which is not best practice and may affect other users. Option C (modifying network-operator) modifies a read-only built-in role. Creating a tailored custom role follows the principle of least privilege and meets the stated requirement.
Topics
Community Discussion
No community discussion yet for this question.