2V0-21.23 Question 89
Single answerAn organization wants to enhance the security posture of their vSphere environment by ensuring that only trusted hosts can run sensitive workloads. They are considering implementing vSphere Trust Authority. Which of the following is a key requirement to set up vSphere Trust Authority?
- A
A separate cluster designated as the Trusted Cluster
- B
Enabling Fault Tolerance on all vSphere hosts
- C
Configuring a Key Management Server (KMS)
- D
Using a vSAN datastore for the Trusted Cluster
Show answer and explanation
Correct answer: C
Explanation
vSphere Trust Authority relies on a Key Management Server (KMS) to handle encryption keys and ensure only trusted hosts can run sensitive workloads. This setup enhances the security of a vSphere environment by enabling attestation and securing workloads using cryptographic operations.
- A. Incorrect.
A separate cluster is not required to set up vSphere Trust Authority. Instead, it involves designating specific trusted hosts within the existing infrastructure.
- B. Incorrect.
Fault Tolerance is not a requirement for vSphere Trust Authority. Fault Tolerance is a feature for workload availability, not for establishing trust between hosts.
- C. Correct.
Configuring a Key Management Server (KMS) is a critical requirement for vSphere Trust Authority. A KMS is used to manage and distribute encryption keys, which are essential for the secure operations of trusted hosts in the environment.
- D. Incorrect.
While vSAN can be part of the infrastructure, it is not a specific requirement for setting up vSphere Trust Authority. Trust Authority focuses on attestation and encryption rather than storage.