nerdexam
Broadcom-VMware

5V0-35.21 · Question #58

An administrator defines the role-based access control mechanisms for new vRealize Operations Manager implementation using LDAP authentication method. Which statement accurately describes these users?

The correct answer is C. They can access vSphere and other objects including third-party objects. When LDAP users are configured in vRealize Operations Manager, their accounts are federated from the external directory - meaning they authenticate via LDAP but still receive role-based access to vSphere objects, third-party objects, and any other resources their assigned roles…

Administering and Operating vRealize Operations

Question

An administrator defines the role-based access control mechanisms for new vRealize Operations Manager implementation using LDAP authentication method. Which statement accurately describes these users?

Options

  • ACredentials for these accounts are stored in its central Postgres database.
  • BThey are not allowed to perform any actions in vRealize Operations.
  • CThey can access vSphere and other objects including third-party objects.
  • DThe LDAP user password policy is set to expire every 45 days in vRealize Operations.

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    13% (4)
  • C
    77% (23)
  • D
    7% (2)

Explanation

When LDAP users are configured in vRealize Operations Manager, their accounts are federated from the external directory - meaning they authenticate via LDAP but still receive role-based access to vSphere objects, third-party objects, and any other resources their assigned roles permit, making C correct.

Why the distractors are wrong:

  • A is incorrect because LDAP credentials are stored and managed in the external LDAP/Active Directory server, not in vROps' internal Postgres database (local accounts use Postgres, not LDAP accounts).
  • B is incorrect because LDAP users are fully functional once assigned roles - they absolutely can perform actions; they're just authenticated externally.
  • D is incorrect because vROps does not control or enforce the LDAP password expiration policy - that policy lives on the LDAP/AD server itself, not within vROps.

Memory tip: Think of LDAP users as "guests with a keycard" - vROps doesn't own their identity (no local password storage, no local password policy), but once they're inside, their RBAC role grants them the same broad access as any other user, including third-party integrated objects.

Topics

#LDAP Authentication#Role-Based Access Control#User Management#External Authentication

Community Discussion

No community discussion yet for this question.

Full 5V0-35.21 Practice