Which two login-class permissions could permit a user to view the system hierarchy of the active
configuration? (Choose two.)
A.
system permission
B.
view-configuration permission
C.
network permission
D.
super-user permission
Explanation:
Which two login-class permissions could permit a user to view the system hierarchy of the active
configuration? (Choose two.)
Which two login-class permissions could permit a user to view the system hierarchy of the active
configuration? (Choose two.)
A.
system permission
B.
view-configuration permission
C.
network permission
D.
super-user permission
Explanation:
A – system permission: allows the viewing of system configuration
B – view-configuration permission: allows the viewing of all configuration (not including secrets)
Chapter 4, page 5
example
root@vSRX_R2# run show cli authorization
Current user: ‘root ‘ class ‘super-user’
Permissions:
admin — Can view user accounts
admin-control– Can modify user accounts
clear — Can clear learned network info
control — Can modify any config
edit — Can edit full files
field — Can use field debug commands
floppy — Can read and write the floppy
interface — Can view interface configuration
interface-control– Can modify interface configuration
network — Can access the network
reset — Can reset/restart interfaces and daemons
routing — Can view routing configuration
routing-control– Can modify routing configuration
shell — Can start a local shell
snmp — Can view SNMP configuration
snmp-control– Can modify SNMP configuration
system — Can view system configuration
system-control– Can modify system configuration
trace — Can view trace file settings
trace-control– Can modify trace file settings
view — Can view current values and statistics
maintenance — Can become the super-user
firewall — Can view firewall configuration
firewall-control– Can modify firewall configuration
secret — Can view secret statements
secret-control– Can modify secret statements
rollback — Can rollback to previous configurations
security — Can view security configuration
security-control– Can modify security configuration
access — Can view access configuration
access-control– Can modify access configuration
view-configuration– Can view all configuration (not including secrets)
flow-tap — Can view flow-tap configuration
flow-tap-control– Can modify flow-tap configuration
idp-profiler-operation– Can Profiler data
pgcp-session-mirroring– Can view pgcp session mirroring configuration
pgcp-session-mirroring-control– Can modify pgcp session mirroring configura ion
storage — Can view fibre channel storage protocol configuration
storage-control– Can modify fibre channel storage protocol configuration
all-control — Can modify any configuration
Individual command authorization:
Allow regular expression: none
Deny regular expression: none
Allow configuration regular expression: none
Deny configuration regular expression: none
[edit interfaces ge-0/0/0 unit 0]
root@vSRX_R2#