Which two are true concerning the role-based access control specifics of a Cisco Unified Computing System?

Which two are true concerning the role-based access control specifics of a Cisco Unified
Computing System? (Choose two.)

Which two are true concerning the role-based access control specifics of a Cisco Unified
Computing System? (Choose two.)

A.
Disabled local user accounts are deleted from the database.

B.
A locally authenticated user account is any user account that is authenticated through LDAP,
RADIUS, or TACACS+.

C.
If a user maintains a local user account and a remote user account simultaneously, the roles
that are defined in the local user account override those that are maintained in the remote user
account.

D.
By default, user accounts expire after 90 days; a warning message will be generated 10 days
prior to expiration.

E.
A user that is assigned one or more roles will be allowed the privileges that are consistent
across all of the assigned roles.

F.
All roles include read access to all configuration settings in the Cisco Unified Computing System
domain.



Leave a Reply 3

Your email address will not be published. Required fields are marked *


ossi

ossi

I think E and F are the correct answers

Michael Churchill

Michael Churchill

A locally authenticated user account is authenticated directly through the fabric interconnect and can be enabled or disabled by anyone with admin or aaa privileges.

A remotely authenticated user account is any user account that is authenticated through LDAP, RADIUS, or TACACS+.

If a user maintains a local user account and a remote user account simultaneously, the roles defined in the local user account override those maintained in the remote user account. so C is right

User roles contain one or more privileges that define the operations that are allowed for a user. One or more roles can be assigned to each user. Users with multiple roles have the combined privileges of all assigned roles not those that are consistent across roles For example, if Role1 has storage-related privileges, and Role2 has server-related privileges, users with Role1 and Role2 have both storage-related and server-related privileges. so E is wrong as this mention consistent roles

All roles include read access to all configuration settings in the Cisco UCS domain. Users with read-only roles cannot modify the system state. – so F is right

So as JoJo say C and F I would say for this answer