nerdexam
Broadcom-VMware

5V0-35.21 · Question #15

Within a large enterprise IT department, a member of the monitoring team has moved to another role within the operations team. The administrator's user account was initially assigned the…

The correct answer is A. The administrator will now be able to complete tasks associated with remediation actions. Option A is correct because role permissions are additive in RBAC systems - when the PowerUser role was added alongside PowerUserMinusRemediation, the user now holds the union of both roles' permissions. The PowerUser role includes remediation actions that were deliberately…

Administering and Operating vRealize Operations

Question

Within a large enterprise IT department, a member of the monitoring team has moved to another role within the operations team. The administrator's user account was initially assigned the PowerUserMinusRemediation role, but the PowerUser role has now been added by the helpdesk team following the job change. Which statement accurately describes the nature of this change?

Options

  • AThe administrator will now be able to complete tasks associated with remediation actions.
  • BThe administrator will now be able to perform cluster management tasks but unable to complete
  • CThe administrator will now be able to perform user management tasks and remediation actions.
  • DThe administrator will remain unable to complete tasks associated with remediation actions.

How the community answered

(32 responses)
  • A
    75% (24)
  • B
    3% (1)
  • C
    16% (5)
  • D
    6% (2)

Explanation

Option A is correct because role permissions are additive in RBAC systems - when the PowerUser role was added alongside PowerUserMinusRemediation, the user now holds the union of both roles' permissions. The PowerUser role includes remediation actions that were deliberately excluded from PowerUserMinusRemediation, so adding it effectively restores that capability.

Option B is wrong because cluster management is not the distinguishing capability being introduced here - the meaningful change between these two roles is specifically around remediation permissions, not cluster management.

Option C is wrong because user management is an administrative privilege typically reserved for higher-privileged roles (like an Administrator role), not granted by PowerUser; the remediation part is correct, but the user management claim is not supported.

Option D is wrong because it assumes the original restrictive role "blocks" remediation even after a broader role is added - in additive RBAC, you cannot have a less-privileged role cancel out permissions granted by a more-privileged role assigned to the same account.

Memory tip: Treat role names literally - "PowerUserMinusRemediation" is just PowerUser with remediation subtracted. Adding PowerUser back in is like adding back the subtracted piece: (PowerUser − Remediation) + PowerUser = PowerUser with full remediation restored.

Topics

#RBAC#vRealize Operations Roles#Privilege Management#Remediation Actions

Community Discussion

No community discussion yet for this question.

Full 5V0-35.21 Practice