2V0-21.23 exam dumps

2V0-21.23 practice question 93 of 452

VMware Certified Professional - Data Center Virtualization 2024. Associate level, VMware. Free question with the correct answer and a full explanation.

2V0-21.23 Question 93

Single answer

An organization is using VMware vSphere to host its virtual machines and has implemented VM encryption to protect sensitive data. The administrator is tasked with configuring a Key Management Server (KMS) in vSphere. What is the role of the KMS in this setup?

  1. A

    The KMS stores encryption keys and provides them to vCenter Server when required for encrypting or decrypting virtual machines.

  2. B

    The KMS stores encrypted backups of virtual machines and ensures their integrity during restoration.

  3. C

    The KMS manages user authentication for accessing encrypted virtual machines.

  4. D

    The KMS directly encrypts and decrypts the virtual machines’ data stored on the datastore.

Show answer and explanation

Correct answer: A

Explanation

The Key Management Server (KMS) plays a crucial role in vSphere's encryption framework by securely generating, storing, and supplying encryption keys. vSphere uses these keys to encrypt and decrypt virtual machine files without the KMS directly interacting with the data. This ensures secure access to sensitive data while delegating encryption and decryption tasks to vSphere.

  • A. Correct.

    Correct: The KMS is responsible for generating, storing, and managing encryption keys. When vSphere encrypts or decrypts a virtual machine or disk, it communicates with the KMS to obtain the necessary encryption keys.

  • B. Incorrect.

    Incorrect: The KMS does not store backups or manage their integrity. Backup storage and management are handled by backup solutions, not the KMS.

  • C. Incorrect.

    Incorrect: The KMS does not handle user authentication; vSphere and vCenter manage user access and permissions.

  • D. Incorrect.

    Incorrect: The KMS does not perform the encryption or decryption directly. Instead, it provides the keys needed for vSphere to handle encryption and decryption operations.

Timed practice exam

Take a 2V0-21.23 practice test under exam conditions

70 questions in 135 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam