Cisco MDS 9000 RBAC: Default Role Override of Conflicting Rules
Refer to the exhibit. A Cisco MDS 9000 Series Switch is configured with RBAC. The default role applies to all users. User A is also assigned to the role Custom-Role-B. Which set of features will user A be authorized to configure? - 
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
MDS RBAC conflict resolution: same rule type applies both; different rule type means the default role's rule applies and overrides the configured role. So a user's effective permission for a contested feature is determined by the default role, not the custom role.
In MDS RBAC, when the default role and a user's configured role have different rule types for the same feature, the default role's rule overrides the configured role. User A (default + Custom-Role-B) is therefore authorized only for features where the default role permits — here, SSH.
Assuming the custom role adds its permissions on top of the default. It does only when rule types match; when they differ, the default wins. Hence User A gets only what the default role grants (SSH), not NTP/DPVM/hardware from Custom-Role-B.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.