2V0-21.23 Question 88
Select 3An organization wants to ensure that its virtual machines (VMs) are running on trusted hardware and are protected from potential threats to the hypervisor. They plan to use VMware vSphere Trust Authority to achieve this. Which of the following components are required to establish a trusted infrastructure using vSphere Trust Authority?
- A
Trusted Cluster with both Attestation and Workload hosts
- B
Key Management Server (KMS) integrated with vSphere
- C
vCenter Server configured as Identity Federation
- D
Attestation Service to verify the hardware and hypervisor integrity
- E
Workload Encryption Service for securing VM data in transit
Show answer and explanation
Correct answers: A, B, D
Explanation
vSphere Trust Authority establishes a trusted infrastructure by leveraging a Trusted Cluster, Key Management Server (KMS), and Attestation Service. The Trusted Cluster integrates Attestation Hosts and Workload Hosts, while the KMS manages encryption keys. The Attestation Service ensures the integrity of the hardware and hypervisor. These components work together to secure the virtual environment, ensuring that VMs run on trusted hardware.
- A. Correct.
Correct: A Trusted Cluster in vSphere Trust Authority includes both Attestation Hosts, which verify the integrity of the environment, and Workload Hosts, which run the VMs.
- B. Correct.
Correct: A Key Management Server (KMS) is required for managing encryption keys, which are used to secure the trusted infrastructure.
- C. Incorrect.
Incorrect: While vCenter Server can be configured for Identity Federation, it is not a specific requirement for vSphere Trust Authority.
- D. Correct.
Correct: The Attestation Service is an essential component of vSphere Trust Authority, responsible for verifying the hardware and hypervisor integrity.
- E. Incorrect.
Incorrect: Workload Encryption Service is not a component of vSphere Trust Authority; it relates to securing VM data in transit and at rest, but it is not specifically tied to this feature.