An administrator needs to restrict access to the SmartConsole so that only members of the 'Audit_Team' AD group can perform read-only tasks. How should this be implemented?
Trap 1: Create a local administrator account for each user and assign the…
Creating local accounts is inefficient and does not leverage existing enterprise authentication infrastructure. It leads to management overhead and potential password synchronization issues, failing to utilize the centralized user management capabilities provided by integration with Active Directory through LDAP or Identity Awareness.
Trap 2: Add the 'Audit_Team' group to the 'All_Users' network object group.
Adding a group to a network object group does not influence administrative access to SmartConsole. Administrative permissions are handled via the Permissions Profile section in the Manage Administrators area, not through network object groups which are used primarily for security policy rules and traffic control.
Trap 3: Enable the 'ReadOnly' global flag in the Global Properties section.
The 'ReadOnly' flag in Global Properties is a global setting that affects all administrators, not specific groups. This approach lacks the granularity required to permit specific users while denying others, and it would inadvertently lock out all administrators from making necessary policy changes.
- A
Create a local administrator account for each user and assign the Auditor role.
Why it fails: Creating local accounts is inefficient and does not leverage existing enterprise authentication infrastructure. It leads to management overhead and potential password synchronization issues, failing to utilize the centralized user management capabilities provided by integration with Active Directory through LDAP or Identity Awareness.
- B
Add the 'Audit_Team' group to the 'All_Users' network object group.
Why it fails: Adding a group to a network object group does not influence administrative access to SmartConsole. Administrative permissions are handled via the Permissions Profile section in the Manage Administrators area, not through network object groups which are used primarily for security policy rules and traffic control.
- C
Create an External Administrator group in SmartConsole and map it to the AD 'Audit_Team' group with an Auditor profile.
Mapping an external group to an administrative profile allows centralized management of permissions. By linking the AD group to the Auditor profile, you ensure that anyone in that group automatically receives the correct set of read-only permissions without needing individual account configuration in the local database.
- D
Enable the 'ReadOnly' global flag in the Global Properties section.
Why it fails: The 'ReadOnly' flag in Global Properties is a global setting that affects all administrators, not specific groups. This approach lacks the granularity required to permit specific users while denying others, and it would inadvertently lock out all administrators from making necessary policy changes.