Question 1
Q1A storage administrator is provisioning a service account on a PowerProtect Data Domain system running DD OS. The account will be used by an automated management utility to create snapshots on MTrees, manage virtual tape movement within a Virtual Tape Library (VTL), and wait for replication synchronization. The account must NOT have permissions to delete MTrees, modify network configurations, or alter global system settings. Which built-in DD OS role fulfills these requirements while adhering to the principle of least privilege?
Show answer & explanation
Correct answer: A
The backup-operator role grants user-level monitoring permissions along with the specific ability to create snapshots on MTrees, import, export, and move tapes within a VTL, copy tapes between pools, manage SSH keys for passwordless script execution, and monitor/wait for replication synchronization. It cannot delete MTrees or change network settings, making it the least-privilege choice. The limited-admin role has broader configuration rights; user is strictly read-only; tenant-admin applies only to Secure Multitenancy tenant units.