2V0-21.23 exam dumps

2V0-21.23 practice question 188 of 452

VMware Certified Professional - Data Center Virtualization 2024. Associate level, VMware. Free question with the correct answer and a full explanation.

2V0-21.23 Question 188

Select 3

An administrator is tasked with configuring LDAP integration for a vCenter Server environment to enable centralized user authentication. The organization's LDAP directory is hosted on Active Directory, and the security policy requires encrypted communication. Which of the following steps should the administrator perform to properly configure and secure the LDAP integration?

  1. A

    Use the Active Directory domain name as the LDAP server address.

  2. B

    Enable LDAPS and configure the vCenter Server to use port 636 for LDAP communication.

  3. C

    Generate and upload a trusted SSL certificate to the vCenter Server to secure LDAP communication.

  4. D

    Set the Base DN to the root of the Active Directory domain for user and group searches.

  5. E

    Test the LDAP connection using the administrator's domain credentials.

Show answer and explanation

Correct answers: B, C, D

Explanation

To configure LDAP integration with vCenter Server and meet the security policy requirements, the administrator must enable LDAPS (port 636) for encrypted communication, upload a trusted SSL certificate to secure the connection, and set the Base DN to the root of the Active Directory domain to ensure proper user and group searches. These steps ensure secure and functional LDAP integration. Using the Active Directory domain name for the LDAP server address and testing the connection are not sufficient or necessary for this specific configuration.

  • A. Incorrect.

    Using the Active Directory domain name as the LDAP server address is incorrect because the LDAP server address should point to the specific domain controller or load-balanced VIP of the domain controllers.

  • B. Correct.

    Enabling LDAPS and using port 636 is necessary for secure LDAP communication, as it encrypts the traffic between the vCenter Server and the Active Directory.

  • C. Correct.

    Uploading a trusted SSL certificate ensures that vCenter Server can securely communicate with the LDAP server using LDAPS, protecting the credentials and data exchanged.

  • D. Correct.

    Setting the Base DN to the root of the Active Directory domain allows vCenter Server to locate users and groups within the directory hierarchy. This is a critical configuration step for LDAP integration.

  • E. Incorrect.

    Testing the LDAP connection using the administrator's domain credentials is not a required step for configuration. It is a good practice to test the connection, but it is not a mandatory part of the configuration process.

Timed practice exam

Take a 2V0-21.23 practice test under exam conditions

70 questions in 135 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam