VMware vSphere 8.x Professional — Question 66
An administrator is tasked with providing users access to objects within an existing VMware vCenter instance. The vCenter inventory has a single data center with one management vSphere cluster and five workload vSphere clusters.
The following requirements must be met for assigning the users access:
Users must only be able to view all of the inventory objects associated with the management vSphere cluster.
Users must be able to edit all of the inventory objects associated with the workload vSphere clusters.
The administrator creates a custom role to provide the permissions needed to allow users to edit inventory objects.
Which series of steps should the administrator complete to assign the custom role and provide the required level of access to users?
Answer options
- A. Apply Global permissions to assign the Read Only role to the root vCenter object. Apply vCenter permissions to assign the custom role to the workload vSphere clusters and enable propagation.
- B. Apply Global permissions to assign the Read Only role to the root vCenter object and enable propagation. Apply vCenter permissions to assign the custom role to the workload vSphere clusters and enable propagation.
- C. Apply Global permissions to assign the Read Only role to the root vCenter object. Apply vCenter permissions to assign the custom role to the workload vSphere clusters.
- D. Apply Global permissions to assign the Read Only role to the root vCenter object and enable propagation. Apply vCenter permissions to assign the custom role to the workload vSphere clusters.
Correct answer: B
Explanation
The correct answer is B because it allows users to have the necessary permissions at both the global and vCenter levels, enabling them to view the management vSphere cluster while editing the workload vSphere clusters. Option A does not mention enabling propagation for the Read Only role, which is essential for proper access. Option C does not enable propagation for the custom role, and option D omits enabling propagation for the custom role as well, which is critical for the desired access levels.