2V0-21.23 Question 231
Select 2An organization wants to ensure their virtual machines are running only on trusted hosts within their vSphere environment. They have implemented vSphere Trust Authority. After configuring the Trust Authority Cluster, which of the following steps must be completed to establish a trusted environment?
- A
Attest the workload ESXi hosts using the Trust Authority Cluster.
- B
Assign a Key Provider to the Trusted Cluster.
- C
Enable TPM 2.0 on all ESXi hosts in the Trusted Cluster.
- D
Configure virtual machines to use vTPM devices.
- E
Set up a separate vCenter Server instance for the Trust Authority Cluster.
Show answer and explanation
Correct answers: A, B
Explanation
To establish a trusted environment using vSphere Trust Authority, it is important to attest the workload ESXi hosts and assign a Key Provider to the Trusted Cluster. These steps ensure that the hosts in the environment can be verified and cryptographic operations are managed securely. Other options, while related to security, are either prerequisites or optional configurations that do not directly establish the trust relationship.
- A. Correct.
Correct. Attesting the workload ESXi hosts ensures that these hosts meet the requirements for a trusted environment.
- B. Correct.
Correct. Assigning a Key Provider to the Trusted Cluster is necessary to manage cryptographic operations for the trusted environment.
- C. Incorrect.
Incorrect. While TPM 2.0 is an underlying requirement for attestation, enabling it on the workload cluster hosts is not a specific configuration step after setting up the Trust Authority Cluster.
- D. Incorrect.
Incorrect. Configuring virtual machines to use vTPM devices is optional and not directly related to establishing a trusted environment with vSphere Trust Authority.
- E. Incorrect.
Incorrect. While the Trust Authority Cluster can be managed separately, setting up a separate vCenter is not a required step to establish a trusted environment.