問題文
A security lead wants operators to be able to watch clusters in the cloud clusters console without being able to create or delete them. Which approach fits?
選択肢
- Give each operator a directory service group entry that grants the read actions and withholds the change actions.
- Give each operator a Nutanix console role that grants the read actions and withholds the change actions.
- Give each operator a provider account permission policy that grants the read actions and withholds the change actions.
- Give each operator a shared resource tag that grants the read actions and withholds the change actions.