ETExamTower
Q19Network

A company operates two Cisco Nexus 7706 Series Switches within a data center segment. All network engineers have limited read-write access to the core switches. A network engineer needs to add a new FCoE VLAN to permit traffic from servers to FCoE storage. Which actions must be performed to satisfy these requirements?

← → navigate · a answer
Community votes
C
100% (5)
A
0% (0)
B
0% (0)
D
0% (0)
Discussion · 8
10
it has to be C
4
I´d pick C. Too. User roles include rules that define the operations allowed for the user assigned to the role. Each user role can contain multiple rules and each user can have multiple roles. For example, if role1 allows access only to configuration operations, and role2 allows access only to debug operations, then users who belong to both role1 and role2 can access configuration and debug operations. You can also limit access to specific VLANs, virtual routing and forwarding instances (VRFs), and interfaces. The Cisco NX-OS software provides four default user roles: •network-admin—Complete read-and-write access to the entire NX-OS device (only available in the default VDC) •network-operator—Complete read access to the entire NX-OS device (only available in the default VDC) •vdc-admin—Read-and-write access limited to a VDC •vdc-operator—Read access limited to a VDC Note You cannot change the default user roles. https://www.cisco.com/c/en/us/td/docs/switches/datacenter/sw/4_1/nx-os/security/configuration/guide/sec_nx-os-cfg/sec_rbac.html#wp1431408
C 1
Selected Answer: C Define the role, add priv e.g. role name User-role-A rule 3 permit read-write feature l2nac rule 2 permit read-write feature dot1x rule 1 deny command clear *
C 1
Selected Answer: C C is the answer
C 1
Selected Answer: C C is right.
1
user needs vdc-admin for FCoE VDC sooo I don't know. C ?
1
I was mistaken. you assign vlans for FCoE VDC from the default VDC, which means you need network-admin role. A is correct
C 1
Selected Answer: C Option C is the most fitting because it lets you customize privileges while keeping security intact by not giving overly permissive roles. The other options either point to roles that may have too many privileges or do not stress creating a specific user-defined role.