Restricting an MDS Role's VSAN Permissions

Answer Correct answer: D — Within the role's VSAN policy, no permit vsan 15-20 removes the permission for the sangroup role to issue commands on those VSANs.

Refer to the exhibit. An engineer must restrict users assigned to the sangroup role on the Cisco MDS 9000 Series Switch from issuing commands on VSANs 15 to 20. Which command must the engineer run to achieve this objective? - image

  1. permit vsan 15-20
  2. no vsan policy deny
  3. vsan policy deny vsan 15-20
  4. no permit vsan 15-20 Correct Answer

Community Votes

D
80%
C
20%

80% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

MDS role-based access uses VSAN policies; removing an existing permit vsan with no permit vsan retracts that role's permission, whereas vsan policy deny sets a default-deny stance.

To stop the MDS sangroup role from issuing commands on VSANs 15-20, enter the role and issue no permit vsan 15-20, which retracts the existing grant.

Using vsan policy deny (sets default deny) instead of no permit (retracts an existing grant), or issuing permit which widens rather than narrows access.

Community Discussion (7 comments)

bizzar7774 👍 1 Selected: D
It's D : cisco.com/c/en/us/td/docs/switches/datacenter/mds9000/sw/8_x/config/security/cisco_mds9000_security_config_guide_8x/configuring_users_and_common_roles.html
PHLTHS 👍 1
It's D:
Rollizo 👍 2 Selected: D
It is D. You have to enter in role name sangroup, after in vsan policy deny and last entre "no permit vsan 15-20"
boyd_05 👍 2 Selected: D
It's D
8d00f64 👍 1 Selected: C
C. vsan policy deny vsan 15-20 This command will deny access to the specified VSANs for the users in the sangroup role
Mr_Myself 👍 3 Selected: D
The following example removes the permission for this role to perform commands for vsan 15 to 20. switch(config-role-vsan)# no permit vsan 15-20
joncursio 👍 1 Selected: C
I think it's C - as you configure it VSAN policy deny..

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

MDS 9000 role-based access uses VSAN policies under the role configuration. If the sangroup role was granted permit vsan 15-20, entering the role and issuing no permit vsan 15-20 removes that permission, so users in sangroup can no longer run commands scoped to VSANs 15 through 20. The vsan policy deny alternative would deny by default and is not how you retract an existing permit.

Why the Other Options Are Wrong

A. permit vsan 15-20 grants the permission; it does the opposite of restricting. B. no vsan policy deny removes a deny policy, which widens access rather than narrowing it. C. vsan policy deny vsan 15-20 sets a default-deny for those VSANs but does not retract the existing explicit permit that the question asks to remove.

Community Comment Notes

Votes D 80 / C 20. Mr_Myself (3 likes) gives the exact example: "switch(config-role-vsan)# no permit vsan 15-20" removes the permission. Rollizo walks through entering the sangroup role then the no permit command. 8d00f64 and joncursio argue C but the task is to remove an existing grant, which is the no permit form.

Official Reference

Related Analysis

← Back to 350-601 Study Guide