A customer would like to remove the output_file capability from users with the default user role to stop them from filling up the disk on the search head with lookup files. What is the best way to remove this capability from users?
A.
Create a new role without the output_file capability that inherits the default user role and assign it to the users.
B.
Create a new role with the output_file capability that inherits the default user role and assign it to the users.
C.
Edit the default user role and remove the output_file capability.
D.
Clone the default user role, remove the output_file capability, and assign it to the users.
D is correct. If new role will inherit user role, user role will have the capabilities from user role, you cannot remove it from new role but if you clone it, it would be possible.
I get it, answer is D. However, I thought users inherited the most restrictive capabilities from their roles. So if we create a new role, 'no_output_file', and assign it to the user, why wouldn't it take effect?
Ref: CI Notes p.116
Roles cannot remove capabilities when they inherit them from another role!
"C" is a possible option which will work, but it's not a best practice. Page 118 states "One quick fix is to adjust the default “user” role to take away the *** setting", but that's a quick and dirty fix, which will remove this capability globally from all users...
The best option is "D", but it's better to set the output_file capability to "disabled" rather than removing it.
I'm not sure what the default behavior will be like when the capability is removed and not set to disabled.
I agree to never edit a default role but the answer is D. If a role inherits another role, it gets its capabilities as well, which in this case we do not desire.
I think the answer is A because if you upgrade Splunk, they will make some modifications to the original role. So, it's better to create a new role with inherits properties from the original one and make your customs modifications.
but answer A inherits the default user role, hence it will still have the output_file capability. With D you are Cloning the role, then editing the new role you created. I think the answer is D.
upvoted 2 times
...
...
...
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
v12
Highly Voted 3 years, 11 months agomarinatedcohort
Most Recent 2 weeks, 2 days agobobixaka
7 months agoRedtonyeah
2 years, 7 months agoGiodada
3 years, 11 months agonoysherer
3 years, 6 months agochuchoneitor
3 years, 3 months agopbandj12
3 years, 3 months ago