2V0-41.24 Question 400
Single answerAn administrator is configuring user roles in an NSX-T environment. The organization requires that a specific user should be able to read and modify firewall rules but must not have the ability to create or delete network segments. Which role should the administrator assign to this user to meet the requirements?
- A
Enterprise Administrator
- B
Network Engineer
- C
Security Engineer
- D
Auditor
Show answer and explanation
Correct answer: C
Explanation
The Security Engineer role perfectly aligns with the requirement to modify firewall rules without granting permissions to create or delete network segments. This role is specifically designed for security-focused tasks, ensuring the user has the necessary access without exceeding the scope of their responsibilities.
- A. Incorrect.
The Enterprise Administrator role has the highest level of privileges, including the ability to create and delete network segments, which does not meet the requirement of restricting such permissions.
- B. Incorrect.
The Network Engineer role includes permissions to create and manage network infrastructure, including segments, which exceeds the user's required scope of responsibilities.
- C. Correct.
The Security Engineer role is tailored for managing and modifying security configurations, such as firewall rules, without permissions to create or delete network segments, making it the correct choice.
- D. Incorrect.
The Auditor role is a read-only role and does not allow for modifying firewall rules, which is required in this scenario.