nerdexam
Broadcom-VMware

3V0-32.23 · Question #50

A company is currently reviewing all of its security roles and permissions due to an upcoming compliance audit. They must identify tenant-specific and system-wide roles. Which option includes ONLY…

The correct answer is D. XaaS architect, Tenant administrator, Services architect, Approval administrator. Option D is correct because XaaS architect, Tenant administrator, Services architect, and Approval administrator are all roles scoped to a specific tenant - they manage catalog items, blueprints, approvals, and tenant settings without touching the underlying infrastructure that…

Design for security

Question

A company is currently reviewing all of its security roles and permissions due to an upcoming compliance audit. They must identify tenant-specific and system-wide roles. Which option includes ONLY tenant-specific roles?

Options

  • ATenant administrator, Services architect, IaaS administrator, Approval administrator
  • BTenant administrator, IaaS administrator, Fabric administrator, Support user
  • CServices architect, Business user, Approver, IaaS administrator
  • DXaaS architect, Tenant administrator, Services architect, Approval administrator

How the community answered

(60 responses)
  • A
    2% (1)
  • B
    5% (3)
  • C
    2% (1)
  • D
    92% (55)

Explanation

Option D is correct because XaaS architect, Tenant administrator, Services architect, and Approval administrator are all roles scoped to a specific tenant - they manage catalog items, blueprints, approvals, and tenant settings without touching the underlying infrastructure that spans the entire system.

Why the distractors fail:

  • A includes IaaS administrator, which is a system-wide role responsible for managing the underlying infrastructure across all tenants, not within one.
  • B includes both IaaS administrator and Fabric administrator - Fabric administrator manages compute, storage, and network fabric at the system level, making it explicitly system-wide.
  • C also includes IaaS administrator, disqualifying it for the same reason as A and B.

The common trap across all three wrong answers is the inclusion of IaaS administrator (and Fabric administrator in B). These are the two roles exam writers consistently use as distractors because they sound like they could be tenant-scoped, but they operate at the infrastructure/system layer shared across all tenants.

Memory tip: Think of it this way - if a role manages what users consume (services, blueprints, approvals), it's tenant-specific. If it manages what the platform runs on (fabric, IaaS infrastructure), it's system-wide. "Fabric = Foundation = global."

Topics

#RBAC#Tenant isolation#VMware security roles#Permissions

Community Discussion

No community discussion yet for this question.

Full 3V0-32.23 Practice