2V0-32.24 Question 226
Select 2Your organization uses vRealize Log Insight to monitor logs across multiple systems. You are tasked with configuring authentication and access for the platform. The security team requires you to integrate vRealize Log Insight with Active Directory (AD) for user authentication. Additionally, they want to ensure that only specific AD groups have access to the system. What steps should you take to meet these requirements?
- A
Integrate vRealize Log Insight with Active Directory by configuring the directory settings under the Authentication tab.
- B
Create local users in vRealize Log Insight for members of the AD groups that require access.
- C
Map the required AD groups to roles in vRealize Log Insight using the Access Control settings.
- D
Enable Single Sign-On (SSO) with vRealize Log Insight to support AD integration.
- E
Disable all local user accounts to enforce authentication exclusively through Active Directory.
Show answer and explanation
Correct answers: A, C
Explanation
To manage authentication and access in vRealize Log Insight with Active Directory, you first need to configure the directory settings to integrate with AD. Once integrated, you must map specific AD groups to roles in the Access Control settings to assign permissions and control access. This ensures that only those group members can access the platform while maintaining centralized authentication through AD.
- A. Correct.
Correct. To integrate vRealize Log Insight with Active Directory, you must configure the directory settings under the Authentication tab.
- B. Incorrect.
Incorrect. Creating local users is not required when integrating with Active Directory, as AD users are authenticated directly.
- C. Correct.
Correct. After integrating with Active Directory, you need to map specific AD groups to roles in vRealize Log Insight to control access and permissions.
- D. Incorrect.
Incorrect. While Single Sign-On (SSO) is a valid authentication method, it is not mandatory for Active Directory integration in this scenario.
- E. Incorrect.
Incorrect. Disabling all local user accounts is not necessary for enforcing Active Directory authentication, and doing so could lock you out of the system in certain situations.