2V0-71.23 exam dumps

2V0-71.23 practice question 89 of 355

VMware Certified Professional - Tanzu for Kubernetes Operations 2024. Associate level, VMware. Free question with the correct answer and a full explanation.

2V0-71.23 Question 89

Select 3

Your organization is deploying a new Kubernetes cluster using VMware Tanzu Kubernetes Grid, and you have been tasked with ensuring that all internal services within the cluster can securely communicate using TLS certificates. The team decides to use cert-manager for certificate management. Which of the following are valid roles of cert-manager in this scenario?

  1. A

    Automating the issuance and renewal of TLS certificates for Kubernetes resources.

  2. B

    Managing external DNS records for services running in the Kubernetes cluster.

  3. C

    Providing integration with certificate issuers such as Let's Encrypt or HashiCorp Vault.

  4. D

    Enabling dynamic certificate generation directly within application containers.

  5. E

    Ensuring certificates are stored securely within Kubernetes secrets.

Show answer and explanation

Correct answers: A, C, E

Explanation

cert-manager is a Kubernetes-native solution designed to simplify certificate management. It automates the issuance, renewal, and storage of TLS certificates by integrating with various certificate issuers and securely storing certificates in Kubernetes secrets. While it focuses on managing certificates, it does not handle tasks like DNS management or dynamic generation of certificates within application containers.

  • A. Correct.

    Correct. cert-manager is commonly used to automate the issuance and renewal of TLS certificates for Kubernetes resources, simplifying certificate management.

  • B. Incorrect.

    Incorrect. cert-manager does not handle DNS record management; this is typically the responsibility of external DNS management tools like ExternalDNS.

  • C. Correct.

    Correct. cert-manager integrates with certificate issuers such as Let's Encrypt and HashiCorp Vault to request and manage certificates.

  • D. Incorrect.

    Incorrect. cert-manager does not dynamically generate certificates within application containers; it works at the resource level, issuing certificates and storing them in Kubernetes secrets.

  • E. Correct.

    Correct. cert-manager ensures that certificates are securely stored in Kubernetes secrets, allowing applications to access them when needed.

Timed practice exam

Take a 2V0-71.23 practice test under exam conditions

63 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam