2V0-21.23 exam dumps

2V0-21.23 practice question 237 of 452

VMware Certified Professional - Data Center Virtualization 2024. Associate level, VMware. Free question with the correct answer and a full explanation.

2V0-21.23 Question 237

Select 3

An organization is deploying vSphere in a secure environment and wants to ensure that all SSL communication between its vCenter Server, ESXi hosts, and clients uses certificates signed by its internal Enterprise PKI. What role does the Enterprise PKI play in this setup, and what must the administrator do to properly integrate the PKI with vSphere?

  1. A

    The Enterprise PKI issues certificates to vSphere components, ensuring trust between them.

  2. B

    The administrator must manually replace default VMware self-signed certificates with certificates signed by the Enterprise PKI.

  3. C

    The Enterprise PKI serves as an intermediary Certificate Authority (CA) for VMware's built-in CA.

  4. D

    The administrator must configure vSphere Certificate Manager to use the Enterprise PKI as the trusted certificate source.

  5. E

    The default VMware Certificate Authority (CA) is automatically disabled when an Enterprise PKI is integrated.

Show answer and explanation

Correct answers: A, B, D

Explanation

To integrate an Enterprise PKI with vSphere, the PKI's role is to issue certificates that replace the default self-signed certificates provided by VMware. Administrators use vSphere Certificate Manager to configure and manage the certificate replacement process. This ensures secure, trusted SSL communication between vSphere components in enterprise environments. However, the VMware default CA is not automatically disabled and must be replaced through proper configuration steps.

  • A. Correct.

    Correct: The Enterprise PKI issues certificates to vSphere components, allowing them to establish trusted SSL communication. This is the central role of an Enterprise PKI in such environments.

  • B. Correct.

    Correct: VMware's default self-signed certificates are not trusted in enterprise environments. An administrator must replace these with certificates signed by the Enterprise PKI to ensure secure and trusted communication.

  • C. Incorrect.

    Incorrect: The Enterprise PKI does not act as an intermediary CA for the VMware built-in CA. Instead, it replaces or supplements the built-in CA by directly issuing certificates.

  • D. Correct.

    Correct: The administrator must configure vSphere Certificate Manager to use the Enterprise PKI as the source for certificates. This is a key step in integrating the Enterprise PKI with vSphere.

  • E. Incorrect.

    Incorrect: The default VMware CA is not automatically disabled. Administrators must explicitly configure vSphere to use the Enterprise PKI or manually replace certificates.

Timed practice exam

Take a 2V0-21.23 practice test under exam conditions

70 questions in 135 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam