VCP-VMC 2024 exam dumps

VCP-VMC 2024 practice question 203 of 252

VMware Certified Professional - VMware Cloud 2024. Associate level, VMware. Free question with the correct answer and a full explanation.

VCP-VMC 2024 Question 203

Select 4

A VMware Cloud Administrator is investigating a security issue where unauthorized virtual machines have been deployed in their VMware environment. Upon review, it was discovered that an administrator account was compromised, and excessive permissions were granted to it. Which of the following actions should the administrator take to troubleshoot and secure the environment?

  1. A

    Review the permissions assigned to all administrator accounts and remove unnecessary privileges.

  2. B

    Enable Multi-Factor Authentication (MFA) for all administrator accounts in the VMware Cloud environment.

  3. C

    Disable logging in the VMware Cloud environment to prevent sensitive information from being exposed.

  4. D

    Use the VMware Cloud Activity Log to identify the source of unauthorized actions.

  5. E

    Change the compromised administrator account password and monitor for further suspicious activity.

Show answer and explanation

Correct answers: A, B, D, E

Explanation

When troubleshooting security issues in VMware Cloud, it is critical to follow security best practices to mitigate risks and prevent future incidents. This includes auditing permissions, enabling MFA, leveraging logs for forensic analysis, and securing compromised accounts. Disabling logging would counteract these efforts and is not a recommended practice.

  • A. Correct.

    Reviewing permissions ensures that the principle of least privilege is followed, reducing the risk of excessive permissions being exploited.

  • B. Correct.

    Enabling MFA adds an additional layer of security to administrator accounts, making it harder for attackers to use stolen credentials.

  • C. Incorrect.

    Disabling logging would hinder the ability to investigate security incidents and is not a recommended action.

  • D. Correct.

    Using the VMware Cloud Activity Log helps identify when and where unauthorized actions originated, which is critical for troubleshooting and preventing future incidents.

  • E. Correct.

    Changing the compromised password ensures that the attacker can no longer use the stolen credentials, and monitoring for further suspicious activity helps detect any ongoing issues.

Timed practice exam

Take a VCP-VMC 2024 practice test under exam conditions

70 questions in 135 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam