VCP-CMA 2024 Question 173
Select 2An organization is using VMware Aria Automation to manage their cloud infrastructure. They want to ensure that specific team members have access to certain projects but not to others, and they also need to control what actions these team members can perform. Which steps should the administrator take to configure Identity and Access Management in VMware Aria Automation to meet this requirement?
- A
Create custom roles in VMware Aria Automation and assign them to users or groups.
- B
Add users to VMware Aria Automation and assign them to default global roles.
- C
Create projects in VMware Aria Automation and assign users or groups to the projects with specific roles.
- D
Use VMware Workspace ONE Access to define granular permissions within VMware Aria Automation.
- E
Enable Identity Federation in VMware Aria Automation and use external identity providers to assign roles.
Show answer and explanation
Correct answers: A, C
Explanation
To meet the organization's requirements, the administrator must leverage VMware Aria Automation's Identity and Access Management capabilities. This involves creating custom roles to define specific permissions and assigning those roles to users or groups. Additionally, using projects in VMware Aria Automation allows the administrator to group resources and assign users or groups with specific roles to control access and actions. Simply relying on default global roles or identity federation does not provide the necessary granularity for this scenario.
- A. Correct.
Correct. Creating custom roles allows the administrator to define specific permissions and assign them to users or groups, ensuring that team members have appropriate access and control.
- B. Incorrect.
Incorrect. While assigning default global roles can provide basic access, it does not enable fine-grained control over specific projects or permissions.
- C. Correct.
Correct. Projects in VMware Aria Automation let you group resources and assign specific users or groups to those projects with roles that define their level of access and actions they can perform.
- D. Incorrect.
Incorrect. VMware Workspace ONE Access is used for identity federation and SSO purposes but does not manage granular permissions directly within VMware Aria Automation.
- E. Incorrect.
Incorrect. While enabling identity federation allows integration with external identity providers, it does not inherently manage or assign permissions within VMware Aria Automation.