2V0-32.24 exam dumps

2V0-32.24 practice question 178 of 249

VMware Certified Professional - Cloud Operations 2024. Associate level, VMware. Free question with the correct answer and a full explanation.

2V0-32.24 Question 178

Select 3

A cloud administrator is configuring authentication and user access control for a VMware vSphere environment integrated with Active Directory. The administrator wants to ensure that only specific user groups from Active Directory have access to the vSphere environment and that permissions are assigned based on roles. What steps must the administrator take to achieve this goal?

  1. A

    Add the Active Directory domain as an identity source in vSphere.

  2. B

    Assign permissions directly to individual users from Active Directory to maintain granular control.

  3. C

    Map Active Directory groups to predefined vSphere roles such as Administrator or Read-Only.

  4. D

    Enable the vSphere Single Sign-On (SSO) service and configure it to deny access to all users by default.

  5. E

    Create custom roles in vSphere and assign them to Active Directory groups according to organizational requirements.

Show answer and explanation

Correct answers: A, C, E

Explanation

To manage authentication and user access control effectively in a vSphere environment, the administrator must configure Active Directory as an identity source to enable authentication via existing credentials. Permissions should be assigned to Active Directory groups rather than individual users to ensure scalability and manageability. Additionally, creating custom roles in vSphere enables fine-grained access control aligned with the organization's specific requirements, which can then be mapped to relevant user groups in Active Directory.

  • A. Correct.

    Adding the Active Directory domain as an identity source in vSphere is necessary to allow authentication using Active Directory credentials.

  • B. Incorrect.

    Assigning permissions directly to individual users is not a best practice because it becomes difficult to manage and scale; permissions should typically be assigned to groups instead.

  • C. Correct.

    Mapping Active Directory groups to predefined vSphere roles is a scalable and efficient method to assign permissions, ensuring role-based access control.

  • D. Incorrect.

    While vSphere SSO is essential for authentication, denying access to all users by default is not a step required for this scenario. Instead, access should be controlled through roles and permissions.

  • E. Correct.

    Creating custom roles in vSphere allows for fine-grained access control tailored to organizational needs, which can then be assigned to Active Directory groups.

Timed practice exam

Take a 2V0-32.24 practice test under exam conditions

60 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam