exam questions

Exam 300-620 All Questions

View all questions & answers for the 300-620 exam

Exam 300-620 topic 1 question 8 discussion

Actual exam question from Cisco's 300-620
Question #: 8
Topic #: 1
[All 300-620 Questions]

A RADIUS user resolves its role via the Cisco AV Pair. What object does the Cisco AV Pair resolve to?

  • A. tenant
  • B. security domain
  • C. primary Cisco APIC
  • D. managed object class
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
nikomski
Highly Voted 3 years, 5 months ago
Shouldn't this be B?
upvoted 17 times
...
udo2020
Most Recent 3 weeks, 2 days ago
Selected Answer: D
I agree to D. The Cisco AV Pair (Attribute-Value Pair) is used in RADIUS to communicate attributes about a user. In the context of Cisco ACI, the AV Pair is used to assign roles and permissions to users. When a RADIUS user authenticates, the Cisco AV Pair determines the user's role and permissions. These roles map to specific managed object classes within the Cisco ACI framework, allowing the user to access and interact with the corresponding objects in the APIC.
upvoted 1 times
...
[Removed]
2 months, 2 weeks ago
Selected Answer: D
Took some back and forth to understand what the ask was. The AV Pairs are carrying with them the privileges and roles(grouped privileges). The privileges are managed objects that you can't custom create, however you can regroup them in many ways to create a suitable access level. The key to the answer is understanding what the whole string has. It does somewhat confuse a lot because of the word Security Domains on the beginning of the string, security domains are part of the structure as Tags or tenants etc. https://bestpath.io/cisco-aci-rbac/
upvoted 2 times
...
zelya19
4 months, 2 weeks ago
Selected Answer: B
shell:domains = SecurityDomainA/writeRole1|writeRole2|writeRole3/readRole1|readRole2, SecurityDomainB/writeRole1|writeRole2|writeRole3/readRole1|readRole2
upvoted 1 times
...
Redou2201
9 months, 1 week ago
Selected Answer: D
based on the link in the comment I saw that: Roles and Privileges A privilege controls access to a particular function within the system. The ACI fabric manages access privileges at the managed object (MO) level. so for me it is D
upvoted 2 times
...
Mr_Certifiable
11 months ago
Selected Answer: D
AV Pair on the External Authentication Server The Cisco APIC requires that an administrator configure a Cisco AV Pair on an external authentication server. The Cisco AV pair specifies the APIC required RBAC roles and privileges for the user. The Cisco AV Pair format is the same for RADIUS, LDAP, or TACACS+. https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/4-x/basic-configuration/Cisco-APIC-Basic-Configuration-Guide-42x/Cisco-APIC-Basic-Configuration-Guide-42x_chapter_011.html For each of the defined roles in Cisco APIC, the APIC Roles and Privileges Matrix shows which managed object classes can be written and which can be read. https://www.cisco.com/c/dam/en/us/td/docs/Website/datacenter/apicroles/roles.html https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/2-x/Security_config/b_Cisco_APIC_Security_Configuration_Guide/b_Cisco_APIC_Security_Guide_chapter_01000.html
upvoted 2 times
...
nyanachi
1 year, 8 months ago
The ACI fabric manages access privileges at the managed object (MO) level. Answer is D
upvoted 1 times
...
bizzar777
1 year, 9 months ago
Selected Answer: D
managed object class is an object ; security domain is a tag
upvoted 1 times
...
Alphonza
2 years, 2 months ago
Selected Answer: B
B is the answer Based on the following link https://www.cisco.com/c/en/us/td/docs/dcn/aci/apic/5x/basic-configuration/cisco-apic-basic-configuration-guide-51x/m_aaa.html
upvoted 2 times
...
Smoothey
2 years, 2 months ago
Selected Answer: D
The ACI fabric manages access privileges at the managed object (MO) level. A privilege is an MO that enables or restricts access to a particular function within the system. For example, fabric-equipment is a privilege bit. This bit is set by the Application Policy Infrastructure Controller (APIC) on all objects that correspond to equipment in the physical fabric. A role is a collection of privilege bits. For example, because an “admin” role is configured with privilege bits for “fabric-equipment” and “tenant-security,” the “admin” role has access to all objects that correspond to equipment of the fabric and tenant security.
upvoted 1 times
Smoothey
2 years, 2 months ago
Tricky. AV-Pairs are associated to a security domain/s. Then permissions assigned e.g. read and or write or both as you select the roles. The MO are assigned to various roles. The roles in turn are prescribed in the security domain. Therfore I am leaning more towards security domain for the AV as the SD is where you choose the MO. However with that said it would ideally involve both the SD and the MO as they are linked.
upvoted 3 times
...
...
ciscoaci2022
2 years, 4 months ago
Should be "D" A security domain is a tag associated with a certain subtree in the ACI MIT object hierarchy. For example, the default tenant “common” has a domain tag common. Similarly, the special domain tag all includes the entire MIT object tree. An administrator can assign custom domain tags to the MIT object hierarchy. For example, an administrator could assign the “solar” domain tag to the tenant named solar. Within the MIT, only certain objects can be tagged as security domains. For example, a tenant can be tagged as a security domain but objects within a tenant cannot. https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/4-x/security/b-Cisco-APIC-Security-Configuration-Guide-421/b-Cisco-APIC-Security-Configuration-Guide-421_chapter_011.html
upvoted 2 times
...
Annielover007
2 years, 5 months ago
Selected Answer: B
B is correct
upvoted 2 times
...
jim13c
3 years ago
Agreed, should be B
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago