2V0-21.23 exam dumps

2V0-21.23 practice question 234 of 452

VMware Certified Professional - Data Center Virtualization 2024. Associate level, VMware. Free question with the correct answer and a full explanation.

2V0-21.23 Question 234

Select 2

An organization is deploying a new vSphere environment and wants to secure communications between vCenter Server and ESXi hosts using certificates. The organization decides to replace the default VMware Certificate Authority (VMCA) signed certificates with custom certificates issued by their internal Certificate Authority (CA). What must the administrator do to successfully complete this configuration?

  1. A

    Generate a Certificate Signing Request (CSR) from each ESXi host and submit it to the internal CA.

  2. B

    Replace the VMCA root certificate with the certificate from the internal CA.

  3. C

    Manually replace the default certificates on each ESXi host with the custom certificates issued by the internal CA.

  4. D

    Configure vCenter Server to use the custom CA-signed certificates by importing the new root certificate into the vSphere Certificate Store.

  5. E

    Restart the ESXi hosts after applying the custom certificates to ensure proper functionality.

Show answer and explanation

Correct answers: A, D

Explanation

To replace default VMware certificates with custom certificates issued by an internal CA, the administrator must generate a CSR from each ESXi host and submit it to the internal CA to obtain the custom certificate. Additionally, vCenter Server must be configured to trust the custom CA by importing its root certificate into the vSphere Certificate Store. These steps ensure secure communication between vSphere components while leveraging certificates issued by the organization's internal CA.

  • A. Correct.

    Correct: A Certificate Signing Request (CSR) must be generated from each ESXi host and submitted to the internal CA to retrieve the custom certificate.

  • B. Incorrect.

    Incorrect: Replacing the VMCA root certificate with an internal CA certificate is not required in this scenario. The VMCA can still manage certificates while allowing custom CA-signed certificates for individual components.

  • C. Incorrect.

    Incorrect: Manually replacing certificates on each ESXi host is not necessary as the certificate management process in vSphere provides automation for applying custom certificates.

  • D. Correct.

    Correct: vCenter Server must be configured to trust the custom CA-signed certificates by importing the root certificate into the vSphere Certificate Store.

  • E. Incorrect.

    Incorrect: While restarting the ESXi hosts may be necessary in some cases, applying certificates alone does not mandate a restart. This is not a required step in the process.

Timed practice exam

Take a 2V0-21.23 practice test under exam conditions

70 questions in 135 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam