2V0-71.23 exam dumps

2V0-71.23 practice question 68 of 355

VMware Certified Professional - Tanzu for Kubernetes Operations 2024. Associate level, VMware. Free question with the correct answer and a full explanation.

2V0-71.23 Question 68

Select 3

Your organization has recently adopted VMware Tanzu Mission Control (TMC) to manage multiple Kubernetes clusters across different cloud providers. As part of the administration requirements, you need to ensure that cluster access is properly managed and audit trails are maintained for compliance purposes. Which of the following actions can you take in Tanzu Mission Control to achieve this goal?

  1. A

    Create role-based access control (RBAC) policies to assign specific permissions to users and groups.

  2. B

    Enable cluster-level logging within Tanzu Mission Control to capture audit trails.

  3. C

    Use Tanzu Mission Control to enforce namespace-level network policies for isolation.

  4. D

    Integrate Tanzu Mission Control with an external identity provider (IdP) to manage user authentication.

  5. E

    Manually configure kubeconfig files across all clusters to ensure user access is consistent.

Show answer and explanation

Correct answers: A, B, D

Explanation

To manage access and maintain compliance in Tanzu Mission Control, administrators can leverage RBAC policies to define permissions, enable cluster-level logging for audit trails, and integrate with an external identity provider for centralized authentication. These features ensure proper access control and compliance while reducing the administrative burden of manual configuration.

  • A. Correct.

    Correct: Tanzu Mission Control supports the creation of RBAC policies to define user and group permissions, ensuring proper access control across clusters.

  • B. Correct.

    Correct: TMC allows enabling cluster-level logging, including audit trails, which are essential for compliance and security monitoring.

  • C. Incorrect.

    Incorrect: While TMC can manage policies, namespace-level network policies are typically enforced through Kubernetes or specific CNI plugins, not directly through TMC.

  • D. Correct.

    Correct: Integrating TMC with an identity provider allows centralized authentication management, enhancing security and simplifying access control.

  • E. Incorrect.

    Incorrect: Manually managing kubeconfig files is error-prone and not aligned with TMC's centralized approach to managing cluster access.

Timed practice exam

Take a 2V0-71.23 practice test under exam conditions

63 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam