VCP-VCF Administrator 2024 exam dumps

VCP-VCF Administrator 2024 practice question 154 of 379

VMware Certified Professional - VMware Cloud Foundation Administrator 2024. Free level, VMware. Free question with the correct answer and a full explanation.

VCP-VCF Administrator 2024 Question 154

Select 3

You are tasked with integrating an organization's Active Directory (AD) as an identity source in vCenter. During the configuration process, you are required to ensure that users in the AD domain can authenticate. Which of the following must be configured correctly to successfully add the AD identity source to vCenter?

  1. A

    Specify the fully qualified domain name (FQDN) of the Active Directory server.

  2. B

    Use the 'Integrated Windows Authentication' option when the vCenter server is not joined to the AD domain.

  3. C

    Provide a user account with administrator privileges in the Active Directory domain.

  4. D

    Ensure the time settings on the vCenter server and AD domain controller are synchronized.

  5. E

    Use the Lightweight Directory Access Protocol (LDAP) without requiring SSL or TLS.

Show answer and explanation

Correct answers: A, C, D

Explanation

To successfully add an AD identity source to vCenter, the AD server's FQDN must be specified so that vCenter can locate the domain controller, and a user account with sufficient privileges in the AD domain must be provided for authentication. Additionally, time synchronization is crucial as Kerberos, which vCenter uses for authentication, is sensitive to time discrepancies. The use of secure communication protocols like LDAP with SSL/TLS is recommended, but the question does not mandate this as a requirement, so it is not a correct option here.

  • A. Correct.

    Specifying the fully qualified domain name (FQDN) of the AD server is necessary for vCenter to locate and communicate with the AD domain controller.

  • B. Incorrect.

    The 'Integrated Windows Authentication' option is only applicable when the vCenter server is joined to the AD domain. If vCenter is not joined to the domain, this option will not work, making it incorrect in this scenario.

  • C. Correct.

    Providing a user account with administrator privileges in the AD domain is required to establish the connection and perform the necessary operations to add the identity source.

  • D. Correct.

    Time synchronization between the vCenter server and the AD domain controller is critical for Kerberos authentication to work properly.

  • E. Incorrect.

    Using LDAP without SSL or TLS is not recommended because it does not secure the communication between vCenter and the AD server, and modern setups typically require secure connections.

Timed practice exam

Take a VCP-VCF Administrator 2024 practice test under exam conditions

70 questions in 135 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam