nerdexam
Microsoft

70-243 · Question #174

You have a System Center 2012 R2 Configuration Manager Service Pack 1 (SP1) stand-alone primary site. You have an administrator named Admin1. You discover that Admin1 can create collections that…

The correct answer is A. Security Scopes for Admin1. Security Scopes in SCCM's role-based administration control which objects an administrator can see and interact with, so scoping Admin1 to only desktop objects restricts the collections they can populate.

security management

Question

You have a System Center 2012 R2 Configuration Manager Service Pack 1 (SP1) stand-alone primary site. You have an administrator named Admin1. You discover that Admin1 can create collections that contains servers, laptops, and desktop computers. You create a collection named Collection1. Collection1 contains only desktop computers on the network. You need to ensure that Admin1 can create only collections that contain desktop computers. Which settings should you modify?

Options

  • ASecurity Scopes for Admin1
  • BMembership Rules for Collection1
  • CSecurity Roles for Admin1
  • DSecurity for Collection1

How the community answered

(35 responses)
  • A
    77% (27)
  • B
    3% (1)
  • C
    14% (5)
  • D
    6% (2)

Why each option

Security Scopes in SCCM's role-based administration control which objects an administrator can see and interact with, so scoping Admin1 to only desktop objects restricts the collections they can populate.

ASecurity Scopes for Admin1Correct

Security Scopes define which instances of objects (computers, collections, packages, etc.) an administrative user can view and select. By assigning Admin1 a security scope that includes only desktop computer objects, the administrator will be unable to browse or select server or laptop objects when defining collection membership rules. This restricts collection creation to desktop-only collections without changing the overall permissions granted by Admin1's security role.

BMembership Rules for Collection1

Membership Rules define the criteria that determine which resources belong to an existing collection; they do not govern what objects Admin1 is permitted to target when creating new collections.

CSecurity Roles for Admin1

Security Roles define what operations (create, delete, modify, deploy) an administrator is authorized to perform, not which specific object instances they are allowed to act upon.

DSecurity for Collection1

Security settings on Collection1 control access to that single existing collection, and have no effect on what Admin1 can include when creating new collections in the future.

Concept tested: SCCM role-based administration security scopes for object restriction

Source: https://learn.microsoft.com/en-us/mem/configmgr/core/understand/fundamentals-of-role-based-administration

Topics

#security scopes#RBAC#collections#administrative permissions

Community Discussion

No community discussion yet for this question.

Full 70-243 Practice