UIAAAV1 · Question #50
Scenario: A Citrix Administrator needs to create local user accounts for other administrators with limited privileges. The other administrators will need only: - Read-only access - The ability to…
The correct answer is C. Operator. Operator is correct because it maps precisely to the two requirements: read-only access to the system configuration plus the ability to enable and disable services and servers - no more, no less. This makes it the least-privilege fit for the described role. Read-Only (B) is…
Question
Scenario: A Citrix Administrator needs to create local user accounts for other administrators with limited privileges. The other administrators will need only:
- Read-only access
- The ability to enable and disable services and servers
Which built-in Command Policy permission level can the administrator use?
Options
- ANetwork
- BRead-Only
- COperator
- DSysadmin
How the community answered
(36 responses)- A17% (6)
- B6% (2)
- C75% (27)
- D3% (1)
Explanation
Operator is correct because it maps precisely to the two requirements: read-only access to the system configuration plus the ability to enable and disable services and servers - no more, no less. This makes it the least-privilege fit for the described role.
Read-Only (B) is wrong because it covers the first requirement but lacks the enable/disable capability, making it insufficient for the task. Network (A) is a Command Policy scoped to network-related commands and does not align with the described administrative needs. Sysadmin (D) grants full administrative rights, which violates the "limited privileges" requirement - it's the highest built-in level, not a restricted one.
Memory tip: Think of the four levels as a ladder - Read-Only < Operator < Network < Sysadmin. "Operator" suggests someone who operates services (turning them on/off) but doesn't own the whole system, which maps perfectly to the scenario.
Topics
Community Discussion
No community discussion yet for this question.