nerdexam
Cisco

350-601 · Question #325

A customer undergoes an IT security review assessment. The auditor must have read-only access to the Cisco Nexus 9000 Series Switch to perform the configuration review. The customer implements this…

The correct answer is D. deny command configure terminal. deny configure terminal Before you begin If you want to distribute the user role configuration, enable user role configuration distribution on all Cisco NX-OS devices to which you want the configuration distributed. configure terminal role name role-name rule number {deny |…

Security

Question

A customer undergoes an IT security review assessment. The auditor must have read-only access to the Cisco Nexus 9000 Series Switch to perform the configuration review. The customer implements this security role for the auditor:

role name audit rule 1 permit command * rule 2 - Output omitted - username auditor password C4SAFF0B96EB0045$c0 role audit Which configuration snippet must complete the configuration?

Options

  • Adeny command write*
  • Bpermit command enable
  • Cpermit command show *
  • Ddeny command configure terminal

How the community answered

(49 responses)
  • A
    8% (4)
  • B
    14% (7)
  • C
    2% (1)
  • D
    76% (37)

Explanation

deny configure terminal Before you begin If you want to distribute the user role configuration, enable user role configuration distribution on all Cisco NX-OS devices to which you want the configuration distributed. configure terminal role name role-name rule number {deny | permit} command command-string rule number {deny | permit} {read | read-write} rule number {deny | permit} {read | read-write} feature feature-name rule number {deny | permit} {read | read-write} feature-group group-name rule number {deny | permit} {read | read-write} oid snmp_oid_name (Optional) description text

Topics

#Cisco Nexus RBAC#Network Security#Command Authorization#Access Control

Community Discussion

No community discussion yet for this question.

Full 350-601 Practice