Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 2V0-21.23 All Questions

View all questions & answers for the 2V0-21.23 exam

Exam 2V0-21.23 topic 1 question 16 discussion

Actual exam question from VMware's 2V0-21.23
Question #: 16
Topic #: 1
[All 2V0-21.23 Questions]

An administrator is tasked with configuring certificates for a VMware software-defined data center (SDDC) based on the following requirements:
All certificates should use certificates trusted by the Enterprise Certificate Authority (CA).
The solution should minimize the ongoing management overhead of replacing certificates.
Which three actions should the administrator take to ensure that the solution meets corporate policy? (Choose three.)

  • A. Replace the VMware Certificate Authority (VMCA) certificate with a self-signed certificate generated from the VMCA.
  • B. Replace the machine SSL certificates with custom certificates generated from the Enterprise CA.
  • C. Replace the machine SSL certificates with trusted certificates generated from the VMware Certificate Authority (VMCA).
  • D. Replace the VMware Certificate Authority (VMCA) certificate with a custom certificate generated from the Enterprise CA.
  • E. Replace the solution user certificates with custom certificates generated from the Enterprise CA.
  • F. Replace the solution user certificates with trusted certificates generated from the VMware Certificate Authority (VMCA).
Show Suggested Answer Hide Answer
Suggested Answer: CDF 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
michael24
Highly Voted 1 year, 5 months ago
BDE is the correct answer.
upvoted 13 times
...
DeeTeeM
Highly Voted 1 year, 1 month ago
Selected Answer: CDF
You can use the following vSphere Certificate Manager options: Replace VMCA Root Certificate with Custom Signing Certificate and Replace All Certificates Replace Machine SSL Certificate with VMCA Certificate (multi-node enhanced linked mode deployment) Replace Solution User Certificate with VMCA Certificate (multi-node enhanced linked mode deployment) https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-authentication/GUID-4469A6D3-048A-471C-9CB4-518A15EA2AC0.html#making-vmca-an-intermediate-certificate-authority-1
upvoted 7 times
...
NahIgotPride
Most Recent 3 weeks, 4 days ago
Selected Answer: CDF
https://docs.vmware.com/en/VMware-vSphere/6.7/com.vmware.psc.doc/GUID-7F63F6D3-67E5-4C8B-B5EF-5C67F71E82B4.html
upvoted 1 times
...
Rospi
1 month, 3 weeks ago
Today I took the exam and I got the following variant to this question: An administrator is tasked with configuring certificates for a VMware software-defined data center (SDDC) based on the following new corporate security policy: - All solutions must only use certificates signed by the Enterprise Certificate Authority (CA). - No intermediate CAs are allowed in the certificate chain. Which two actions should the administrator take to ensure the solution meets corporate policy? (Choose two.) A. Replace the solution user certificates with trusted certificates generated from the VMware Certificate Authority (VMCA). B. Replace the solution user certificates with custom certificates generated from the Enterprise CA. C. Replace the machine SSL certificates with trusted certificates generated from the VMware Certificate Authority (VMCA). D. Replace the VMware Certificate Authority (VMCA) certificate with a custom certificate generated from the Enterprise CA. E. Replace the machine SSL certificates with custom certificates generated from the Enterprise CA.
upvoted 1 times
amorcle
2 weeks, 2 days ago
B and E because No intermediate CAs are allowed in the certificate chain.
upvoted 1 times
...
nocenta
2 weeks, 6 days ago
Confirmed, I took the exam recently and there are 5 options, the ones Rospi wrote, and two answers to give
upvoted 1 times
...
...
Rospi
1 month, 3 weeks ago
An administrator is tasked with configuring certificates for a VMware software-defined data center (SDDC) based on the following new corporate security policy: - All solutions must only use certificates signed by the Enterprise Certificate Authority (CA). - No intermediate CAs are allowed in the certificate chain. Which two actions should the administrator take to ensure the solution meets corporate policy? (Choose two.) A. Replace the solution user certificates with trusted certificates generated from the VMware Certificate Authority (VMCA). B. Replace the solution user certificates with custom certificates generated from the Enterprise CA. C. Replace the machine SSL certificates with trusted certificates generated from the VMware Certificate Authority (VMCA). D. Replace the VMware Certificate Authority (VMCA) certificate with a custom certificate generated from the Enterprise CA. E. Replace the machine SSL certificates with custom certificates generated from the Enterprise CA.
upvoted 1 times
...
Rospi
1 month, 3 weeks ago
A. Replace the solution user certificates with trusted certificates generated from the VMware Certificate Authority (VMCA). B. Replace the solution user certificates with custom certificates generated from the Enterprise CA. C. Replace the machine SSL certificates with trusted certificates generated from the VMware Certificate Authority (VMCA). D. Replace the VMware Certificate Authority (VMCA) certificate with a custom certificate generated from the Enterprise CA. E. Replace the machine SSL certificates with custom certificates generated from the Enterprise CA.
upvoted 1 times
...
Rospi
1 month, 3 weeks ago
today I took the exam and I got the following variant to this question:
upvoted 1 times
...
Rospi
2 months ago
Selected Answer: BDE
Selected this based on these are the only options using the External Enterprise CA.
upvoted 2 times
...
HenryDCase
5 months ago
Selected Answer: BDE
This one line gives you the answer: All certificates should use certificates trusted by the Enterprise Certificate Authority (CA).
upvoted 5 times
...
DCT
5 months, 1 week ago
Selected Answer: ACF
Hybird mode should be only replace machine SSL signed by Enterprise CA. The rest still handling by VMCA.
upvoted 1 times
...
MalGil
5 months, 4 weeks ago
Selected Answer: BDE
Selected this based on these are the only options using the External Enterprise CA.
upvoted 3 times
...
elekgeek
9 months, 2 weeks ago
CDF is the correct thing to do after all. Looking at this article: https://openssl-ca.readthedocs.io/en/latest/create-the-intermediate-pair.html it is possible to create intermediate certificate that can sign certificates on behalf of the root CA. This vmware article makes it possible https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-authentication/GUID-5FE583A2-3737-4B62-A905-5BB38D479AE0.html#GUID-5FE583A2-3737-4B62-A905-5BB38D479AE0
upvoted 2 times
...
vaaws
11 months, 2 weeks ago
BDF(Hybrid Approach) https://core.vmware.com/resource/vsphere-certificate-management#section2
upvoted 2 times
...
fabianovidalrocha
11 months, 3 weeks ago
I had a question like this, but with two options.
upvoted 2 times
...
Joaquino
1 year, 2 months ago
Selected Answer: CDF
I think CDF is the correct answer. You can issue a Certificate for the VMCA, making the VMCA an Intermediate CA in the process. Then, issue the rest of the certs using the VMCA to simplify the renewal process. https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-authentication/GUID-4469A6D3-048A-471C-9CB4-518A15EA2AC0.html#making-vmca-an-intermediate-certificate-authority-1 ("Making VMCA an Intermediate Certificate Authority" approach)
upvoted 3 times
...
[Removed]
1 year, 2 months ago
Selected Answer: CDF
View the table in the link. It talks about using subordinate CA apporach. https://blogs.vmware.com/vsphere/files/2017/01/Hybrid-PWT-Table.png https://blogs.vmware.com/vsphere/2017/01/walkthrough-hybrid-ssl-certificate-replacement.html
upvoted 2 times
pleaseletmepassthistest
1 year, 2 months ago
have you taken the test? Were the same questions from here on it?
upvoted 1 times
...
...
schuecl
1 year, 2 months ago
Selected Answer: CDF
CDF. As others have stated, this accomplishes the goal of easy certificate deployment, and since your VMCA cert is issued by the Company CA, all certs issued by the VMCA will be in that chain.
upvoted 3 times
pleaseletmepassthistest
1 year, 2 months ago
have you taken the test? Were the same questions from here on it?
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...