2V0-21.23 exam dumps

2V0-21.23 practice question 233 of 452

VMware Certified Professional - Data Center Virtualization 2024. Associate level, VMware. Free question with the correct answer and a full explanation.

2V0-21.23 Question 233

Single answer

An administrator is tasked with replacing the default Machine SSL certificate on the vCenter Server with a custom certificate issued by their organization's Certificate Authority (CA). After generating the Certificate Signing Request (CSR) and obtaining the signed certificate from the CA, what is the next step to complete the replacement process?

  1. A

    Import the signed certificate into the vSphere Certificate Manager and select the option to replace the Machine SSL certificate.

  2. B

    Manually copy the signed certificate to the vCenter Server and restart the vSphere Client service.

  3. C

    Use the vSphere Web Client to upload the signed certificate and apply it directly to the Machine SSL slot.

  4. D

    Replace the VMCA root certificate with the new signed certificate to ensure all vSphere components use the custom certificate.

Show answer and explanation

Correct answer: A

Explanation

The correct process for replacing the Machine SSL certificate involves using the vSphere Certificate Manager utility. This tool is explicitly designed for managing certificates on vSphere components, including importing signed certificates and replacing default ones. Using other methods, such as manual file manipulation or uploading via the Web Client, are not supported or effective for this task.

  • A. Correct.

    Correct. The vSphere Certificate Manager is the appropriate tool for importing and managing certificates, including replacing the Machine SSL certificate.

  • B. Incorrect.

    Incorrect. Manually copying the signed certificate and restarting services is not the correct approach for replacing the Machine SSL certificate. This process must be done using the vSphere Certificate Manager.

  • C. Incorrect.

    Incorrect. The vSphere Web Client does not provide functionality for directly uploading or applying a signed certificate to the Machine SSL slot.

  • D. Incorrect.

    Incorrect. Replacing the VMCA root certificate is not required for replacing the Machine SSL certificate. The VMCA root certificate is only replaced when you want to change the trusted root authority for all certificates issued by vSphere.

Timed practice exam

Take a 2V0-21.23 practice test under exam conditions

70 questions in 135 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam