2V0-71.23 exam dumps

2V0-71.23 practice question 215 of 355

VMware Certified Professional - Tanzu for Kubernetes Operations 2024. Associate level, VMware. Free question with the correct answer and a full explanation.

2V0-71.23 Question 215

Select 2

You are configuring authentication and authorization for a Tanzu Kubernetes Cluster. The cluster must integrate with your organization's Active Directory (AD) for user authentication, and you want to ensure that users can only perform specific actions based on their assigned Kubernetes roles. Which steps should you take to achieve this integration?

  1. A

    Configure Pinniped to use Active Directory as the external identity provider.

  2. B

    Assign Kubernetes roles to users and groups through RoleBindings or ClusterRoleBindings.

  3. C

    Enable the default kubeconfig file for user authentication without any additional configuration.

  4. D

    Configure the cluster's API server to use a static token file for authentication.

  5. E

    Deploy an OpenID Connect (OIDC) provider and configure Pinniped to use it for authentication.

Show answer and explanation

Correct answers: A, B

Explanation

To integrate Active Directory with Tanzu Kubernetes Clusters for authentication, you should configure Pinniped to act as the intermediary between the Kubernetes cluster and the external identity provider (AD). For authorization, Kubernetes roles must be assigned to users or groups from AD using RoleBindings or ClusterRoleBindings. These steps ensure secure and role-based access to the cluster while leveraging your organization's existing identity management system.

  • A. Correct.

    Correct: Pinniped provides integration with external identity providers, such as Active Directory, allowing you to use AD for user authentication in Tanzu Kubernetes Clusters.

  • B. Correct.

    Correct: Kubernetes uses RoleBindings and ClusterRoleBindings to control what actions authenticated users and groups can perform, fulfilling the requirement for authorization.

  • C. Incorrect.

    Incorrect: The default kubeconfig file does not support Active Directory integration out of the box and requires additional configuration for external authentication.

  • D. Incorrect.

    Incorrect: Using a static token file is not a secure or scalable approach for integrating with Active Directory.

  • E. Incorrect.

    Incorrect: While OpenID Connect (OIDC) is a valid authentication method supported by Pinniped, it is not required when directly integrating with Active Directory.

Timed practice exam

Take a 2V0-71.23 practice test under exam conditions

63 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam