VCP-VCF Administrator 2024 exam dumps

VCP-VCF Administrator 2024 practice question 209 of 379

VMware Certified Professional - VMware Cloud Foundation Administrator 2024. Free level, VMware. Free question with the correct answer and a full explanation.

VCP-VCF Administrator 2024 Question 209

Select 3

An organization has deployed VMware Cloud Foundation to host its critical workloads. The administrator has been tasked with securing both the workload VMs and the infrastructure by leveraging encryption. Which of the following actions should the administrator take to meet the requirements?

  1. A

    Enable vSAN encryption and configure a Key Management Server (KMS).

  2. B

    Enable VM-level encryption and ensure the appropriate encryption policy is applied to the VMs.

  3. C

    Enable NSX-T encryption for all network traffic between VMs.

  4. D

    Use encrypted vMotion to secure live migrations of workload VMs.

  5. E

    Enable Secure Boot for all hardware components in the infrastructure.

Show answer and explanation

Correct answers: A, B, D

Explanation

To secure workloads and infrastructure using encryption in VMware Cloud Foundation, administrators need to focus on encrypting data at rest (vSAN encryption), securing individual VMs (VM-level encryption), and protecting data in transit (encrypted vMotion). These measures collectively ensure that sensitive information is safeguarded at multiple layers of the infrastructure. Other features like NSX-T and Secure Boot, while important for security, are not specifically related to encryption in this context.

  • A. Correct.

    vSAN encryption ensures that all data stored in the vSAN datastore is encrypted, thereby securing the infrastructure's storage layer. A Key Management Server (KMS) is required to manage the encryption keys.

  • B. Correct.

    VM-level encryption secures individual virtual machines by encrypting their virtual disks and files. Applying the correct encryption policy ensures that the required VMs are protected.

  • C. Incorrect.

    NSX-T does not provide encryption for all network traffic by default. While it offers micro-segmentation and other security features, encryption would require additional configurations or third-party integrations.

  • D. Correct.

    Encrypted vMotion secures live migration traffic of VMs, protecting sensitive data during the migration process. This feature is crucial for securing workloads in a multi-host environment.

  • E. Incorrect.

    While Secure Boot is an important feature for ensuring the integrity of hardware and firmware, it does not directly relate to encryption of workloads or infrastructure.

Timed practice exam

Take a VCP-VCF Administrator 2024 practice test under exam conditions

70 questions in 135 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam