Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam 2V0-21.23 topic 1 question 55 discussion

Actual exam question from VMware's 2V0-21.23
Question #: 55
Topic #: 1
[All 2V0-21.23 Questions]

An administrator is tasked with providing users access to objects within an existing VMware vCenter instance. The vCenter inventory has a single data center with one management vSphere cluster and five workload vSphere clusters.
The following requirements must be met for assigning the users access:
Users must only be able to view all of the inventory objects associated with the management vSphere cluster.
Users must be able to edit all of the inventory objects associated with the workload vSphere clusters.
The administrator creates a custom role to provide the permissions needed to allow users to edit inventory objects.
Which series of steps should the administrator complete to assign the custom role and provide the required level of access to users?

  • A. Apply Global permissions to assign the Read Only role to the root vCenter object.
    Apply vCenter permissions to assign the custom role to the workload vSphere clusters and enable propagation.
  • B. Apply Global permissions to assign the Read Only role to the root vCenter object and enable propagation.
    Apply vCenter permissions to assign the custom role to the workload vSphere clusters and enable propagation.
  • C. Apply Global permissions to assign the Read Only role to the root vCenter object.
    Apply vCenter permissions to assign the custom role to the workload vSphere clusters.
  • D. Apply Global permissions to assign the Read Only role to the root vCenter object and enable propagation.
    Apply vCenter permissions to assign the custom role to the workload vSphere clusters.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
dredlinee
2 weeks, 2 days ago
Selected Answer: B
When you assign a permission to an object, you can choose whether the permission propagates down the object hierarchy. You set propagation for each permission. Propagation is not universally applied. Permissions defined for a child object always override the permissions that are propagated from parent objects.
upvoted 1 times
...
dennis314159
2 weeks, 5 days ago
Selected Answer: B
Table 2-1. Differences Between vCenter Server Permissions and Global Permissions Permission Type Description vCenter Server vCenter Server permissions apply to specific objects in the inventory hierarchy, such as hosts, virtual machines, datastores, and so on. When you assign vCenter Server permissions, you specify that a user or group has a role (set of privileges) on the object. Global Global permissions give a user or group privileges to view or manage all objects in each of the inventory hierarchies in your deployment. Global permissions also apply to global objects such as tags and content libraries. See vCenter Server Permissions on Tag Objects. If you assign a global permission and do not select Propagate, the users or groups associated with this permission do not have access to the objects in the hierarchy. They only have access to some global functionality such as creating roles. Therefore, propagation at Global level is required. Answer B.
upvoted 1 times
...
WOODENPC
1 month ago
Selected Answer: D
tested: propagation at global permission is sufficient
upvoted 1 times
...
DizzzyD
4 months, 2 weeks ago
Selected Answer: B
This was my answer, passed with 452
upvoted 2 times
...
Achab
4 months, 3 weeks ago
Why not A ? If you apply global permissions read permission on vcenter root object AND enable propagation, read permissions will propagate to ALL of the clusters. all of the inventory objects associated with the management vSphere cluster
upvoted 1 times
...
mr00va
7 months ago
Selected Answer: B
"Users must be able to edit ALL OF THE INVENTORY OBJECTS associated with the workload vSphere clusters."
upvoted 2 times
...
[Removed]
8 months ago
Selected Answer: D
Virtual Machine Edit Inventory Privileges You can set this privilege at different levels in the hierarchy. For example, if you set a privilege at the folder level, you can propagate the privilege to one or more objects within the folder. Read page 453 in https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-esxi-vcenter-801-security-guide.pdf
upvoted 1 times
...
Bert_77
8 months ago
Selected Answer: B
B is the correct answer, tested in lab envoronment. Propagation is required, if not you will only set the permissions on the level where you configure it, not on the objects below.
upvoted 1 times
...
SeeWish
8 months ago
Selected Answer: B
Tested in lab. Answer is B Propagation is needed for both
upvoted 1 times
...
kijken
8 months, 1 week ago
Selected Answer: D
only first line needs propagation
upvoted 1 times
...
VMwareGuy123
9 months, 1 week ago
Selected Answer: B
I also opt for option B. What is the point of setting the permission only on the cluster object without propagation? There can be many objects under a cluster (resource pools, hosts, VMs), etc. I don't want to have to set permissions on them separately. Definitely B!
upvoted 1 times
...
VMwareGuy123
9 months, 2 weeks ago
Can someone explain: Why not B?
upvoted 1 times
...
pepi_5121
9 months, 2 weeks ago
Selected Answer: D
https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-esxi-vcenter-801-security-guide.pdf
upvoted 1 times
...
Klklejda
9 months, 4 weeks ago
Yes propagation is needed, but for global permissions only, and then it propagates to vcenter permissions. So I think is D https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-esxi-vcenter-801-security-guide.pdf
upvoted 1 times
...
JesterVS
10 months, 1 week ago
Selected Answer: B
Propagation is needed
upvoted 2 times
...
atinivelli
10 months, 2 weeks ago
Selected Answer: B
i'd say B
upvoted 2 times
...
Ilmace86
10 months, 2 weeks ago
Selected Answer: B
I think I'll go for B. Without propagation on workload clusters, you'll get custom roles only at the root level where you apply permission
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...