exam questions

Exam 300-620 All Questions

View all questions & answers for the 300-620 exam

Exam 300-620 topic 1 question 241 discussion

Actual exam question from Cisco's 300-620
Question #: 241
Topic #: 1
[All 300-620 Questions]

An engineer is configuring a new user account in Cisco ACI. The new user will be assigned the role of fabric administrator. The fabric has only one tenant, so the engineer associated the new user account with a security domain for the tenant, as well as the security domain for the management tenant. Which configuration permits the new user with admin access to the fabric?

  • A. Associate the new user with the security domain all.
  • B. Grant the new user R/W access to the user and management tenant.
  • C. Add the DN uni/fabric under explicit rules.
  • D. Bind the security domain infra to the new user account.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
prospio971
5 days, 21 hours ago
Selected Answer: A
To provide the new user fabric administrator access to the Cisco ACI fabric, the engineer must ensure that the user has the correct role and security domain associations.
upvoted 1 times
...
Rollizo
1 month ago
Selected Answer: A
Doesn't exist security domain infra. You would need to create it
upvoted 2 times
...
mdriraa
4 months, 1 week ago
Selected Answer: A
https://www.cisco.com/c/en/us/td/docs/dcn/aci/apic/6x/security-configuration/cisco-apic-security-configuration-guide-61x/access-authentication-and-accounting-61x.htmlCreating a user and assigning a role to that user does not enable access rights. It is necessary to also assign the user to one or more security domains. By default, the ACI fabric includes the following special pre-created domains: All—allows access to the entire MIT Common—allows access to fabric common objects/subtrees Mgmt—allows access to fabric management objects/subtrees
upvoted 2 times
...
zelya19
9 months, 1 week ago
Selected Answer: A
By default, the ACI fabric includes the following special pre-created domains: All—allows access to the entire MIT Common—allows access to fabric common objects/subtrees Mgmt—allows access to fabric management objects/subtrees https://www.cisco.com/c/en/us/td/docs/dcn/aci/apic/6x/security-configuration/cisco-apic-security-configuration-guide-60x/access-authentication-and-accounting-60x.html
upvoted 2 times
...
sailorsoul
10 months, 2 weeks ago
Selected Answer: D
Creating a user and assigning a role to that user does not enable access rights. It is necessary to also assign the user to one or more security domains. By default, the ACI fabric includes two special pre-created domains: All—allows access to the entire MIT Infra— allows access to fabric infrastructure objects/subtrees, such as fabric access policies https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/5-x/security/cisco-apic-security-configuration-guide-50x/m_access_authentication_and_accounting.html#concept_A5EAE4EC5E164965B42AD0364B55E9CB
upvoted 1 times
...
Mr_Certifiable
1 year, 3 months ago
Selected Answer: D
Access Rights Workflow Dependencies The Cisco Application Centric Infrastructure (ACI) RBAC rules enable or restrict access to some or all of the fabric. For example, in order to configure a leaf switch for bare metal server access, the logged in administrator must have rights to the infra domain. By default, a tenant administrator does not have rights to the infra domain. In this case, a tenant administrator who plans to use a bare metal server connected to a leaf switch could not complete all the necessary steps to do so. The tenant administrator would have to coordinate with a fabric administrator who has rights to the infra domain. The fabric administrator would set up the switch configuration policies that the tenant administrator would use to deploy an application policy that uses the bare metal server attached to an ACI leaf switch. https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/5-x/security/cisco-apic-security-configuration-guide-50x/m_access_authentication_and_accounting.html
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago