2V0-41.24 Question 220
Single answerYour organization has recently deployed NSX-T Data Center, and you have been tasked with configuring Role-Based Access Control (RBAC) for the networking team. The team requires the ability to create and manage Tier-1 Gateways but should not have permissions to modify Tier-0 Gateways. Which role should you assign to the networking team to meet this requirement?
- A
Enterprise Administrator
- B
Network Engineer
- C
NSX Administrator
- D
Network Operator
Show answer and explanation
Correct answer: B
Explanation
Role-Based Access Control (RBAC) in NSX-T allows administrators to assign specific permissions based on user roles. The 'Network Engineer' role is designed for users who need to create and manage Tier-1 Gateways but should not have permissions to modify Tier-0 Gateways. This role aligns with the organization's requirement of restricting access to Tier-0 Gateways while enabling the management of Tier-1 Gateways.
- A. Incorrect.
Enterprise Administrator has the highest level of permissions and can manage all aspects of NSX-T, including Tier-0 Gateways. This role does not meet the requirement of restricting access to Tier-0 Gateways.
- B. Correct.
Network Engineer is the correct role because it provides permissions to create and manage Tier-1 Gateways while restricting access to Tier-0 Gateway configurations.
- C. Incorrect.
NSX Administrator has full administrative access to NSX-T, including Tier-0 Gateways. Assigning this role would give the networking team more permissions than required.
- D. Incorrect.
Network Operator is a read-only role for monitoring and does not allow the creation or management of Tier-1 Gateways. This role does not meet the requirement.