nerdexam
Broadcom-VMware

5V0-35.21 · Question #134

A user finds a cluster is not visible when attempting to navigate to it in the Environment navigation panel. Global settings within vRealize Operations has disabled all vCenter the account…

The correct answer is A. vCenter user privileges B. User role. When vCenter account authentication is globally disabled in vRealize Operations, the system no longer uses vCenter SSO to filter object visibility, so two distinct layers must be inspected: the vCenter service account privileges (A) and the vROps user role (B). If the adapter…

Administering and Operating vRealize Operations

Question

A user finds a cluster is not visible when attempting to navigate to it in the Environment navigation panel. Global settings within vRealize Operations has disabled all vCenter the account authentication. Which two items should be administratively checked within vRealize Operations to ensure that desired object is visible? (Choose two.)

Options

  • AvCenter user privileges
  • BUser role
  • COutbound settings
  • DPolicy assignment
  • EUser object access assignment

How the community answered

(48 responses)
  • A
    75% (36)
  • C
    8% (4)
  • D
    13% (6)
  • E
    4% (2)

Explanation

When vCenter account authentication is globally disabled in vRealize Operations, the system no longer uses vCenter SSO to filter object visibility, so two distinct layers must be inspected: the vCenter service account privileges (A) and the vROps user role (B). If the adapter service account used to communicate with vCenter lacks sufficient privileges on the cluster object, that object will never be imported into vROps inventory in the first place - making it invisible to everyone. Separately, even if the object is discovered, the user's assigned role in vROps must grant permissions to view environment objects; without it, the user is locked out of seeing the cluster regardless of discovery status.

Why the distractors are wrong:

  • C (Outbound settings): These govern external notification channels (SMTP, webhooks) - unrelated to object visibility.
  • D (Policy assignment): Policies control how data is collected (metrics, thresholds), not who can see which objects.
  • E (User object access assignment): While object-level access exists in vROps, the role (B) is the primary gating mechanism; object access is typically a sub-configuration of the role assignment, making B the correct answer over E.

Memory tip: Think "Who can see it?" = Role (B), "Can vROps even find it?" = vCenter privileges (A). The adapter must discover the object before any user can view it.

Topics

#vCenter authentication#User roles and RBAC#Object visibility#Access control

Community Discussion

No community discussion yet for this question.

Full 5V0-35.21 Practice