VCP-VCF Administrator 2024 exam dumps

VCP-VCF Administrator 2024 practice question 214 of 379

VMware Certified Professional - VMware Cloud Foundation Administrator 2024. Free level, VMware. Free question with the correct answer and a full explanation.

VCP-VCF Administrator 2024 Question 214

Select 3

An organization is running critical workloads on their VMware Cloud Foundation environment. They are required to meet compliance requirements by encrypting sensitive data at the host level. As a VMware Cloud Foundation Administrator, which steps should you take to implement host-based encryption to secure these workloads?

  1. A

    Enable vSphere Native Key Provider (vSphere NKP) for encryption key management.

  2. B

    Configure each VM for encryption by enabling VM Encryption in the VM settings.

  3. C

    Ensure the hardware supports AES-NI and Trusted Platform Module (TPM).

  4. D

    Enable encrypted vMotion to ensure data-in-transit security.

  5. E

    Manually install a third-party key management server (KMS) on each ESXi host.

Show answer and explanation

Correct answers: A, C, D

Explanation

To secure workloads using host-based encryption in VMware Cloud Foundation, administrators must ensure the environment is prepared with necessary hardware features like AES-NI and TPM, enable a key management solution like vSphere Native Key Provider, and configure encrypted vMotion for secure migrations. These steps ensure that sensitive data is protected both at rest and in transit across the VMware Cloud Foundation environment.

  • A. Correct.

    vSphere Native Key Provider (vSphere NKP) is a built-in key management solution within VMware environments and is required for host-based encryption without depending on external KMS solutions.

  • B. Incorrect.

    VM Encryption is different from host-based encryption. VM Encryption secures individual virtual machines, whereas host-based encryption secures the underlying ESXi host's storage.

  • C. Correct.

    Host-based encryption requires hardware that supports AES-NI for efficient encryption and a Trusted Platform Module (TPM) for secure key storage and attestation.

  • D. Correct.

    Encrypted vMotion is essential to ensure that encrypted workloads are protected during live migrations, which is a critical step when implementing host-based encryption.

  • E. Incorrect.

    Manually installing a third-party KMS is not necessary as VMware provides built-in options, such as vSphere NKP, for managing encryption keys.

Timed practice exam

Take a VCP-VCF Administrator 2024 practice test under exam conditions

70 questions in 135 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam