MongoDB provides db.grantRolesToUser() specifically for assigning one or more additional roles to an existing user. The method takes the username as its first argument and an array of roles as its second argument, so db.grantRolesToUser( " user1 " , [ " customRole1 " ]) is the correct choice. A role can be supplied as a simple string when it belongs to the current database or as an explicit document such as { role: " customRole1 " , db: " admin " } when the database context must be specified. Option B uses db.createUser(), which is used to create a new user rather than modify the role membership of an account that already exists. Options A and C use method names that are not the documented mongosh interfaces for this operation. Administrators should also distinguish grantRolesToUser() from grantRolesToRole(): the latter makes a user-defined role inherit other roles, whereas the former directly changes a user ' s assigned roles. Least-privilege practice requires granting only roles necessary for the user ' s responsibilities. For the requested update to the existing user, option D is correct.
Study Guide reference/topic:Security, Networking, and Encryption - user administration, role assignment, RBAC, and grantRolesToUser().
===========
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit