exam questions

Exam 2V0-21.23 All Questions

View all questions & answers for the 2V0-21.23 exam

Exam 2V0-21.23 topic 1 question 104 discussion

Actual exam question from VMware's 2V0-21.23
Question #: 104
Topic #: 1
[All 2V0-21.23 Questions]

An administrator is tasked with configuring certificates for a VMware software-defined data center (SDDC) based on the following requirements:

• The solution should minimize the ongoing management overhead of replacing certificates.
• No intermediate certificate authorities are allowed in the certificate chain.
• All external traffic should be secured using certificates signed by an Enterprise Certificate Authority (CA).

Which two actions should the administrator take to ensure the solution meets corporate policy? (Choose two.)

  • A. Replace the solution user certificates with custom certificates generated from the Enterprise CA.
  • B. Replace the machine SSL certificates with custom certificates generated from the Enterprise CA.
  • C. Replace the machine SSL certificates with self-signed certificates generated from the VMware Certificate Authority (VMCA).
  • D. Replace the VMware Certificate Authority (VMCA) certificate with a custom certificate gen-erated from the Enterprise CA.
  • E. Replace the solution user certificates with self-signed certificates generated from the VMware Certificate Authority (VMCA).
Show Suggested Answer Hide Answer
Suggested Answer: AB 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
anonymous1966
3 weeks, 4 days ago
Selected Answer: AB
VMCA-Signed Certificates will be replaced by Custom Certificates So there is nothing to configure envolving VMCA. Pay attention to this document: https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-authentication/GUID-4469A6D3-048A-471C-9CB4-518A15EA2AC0.html
upvoted 1 times
...
anonymous1966
1 month ago
Selected Answer: BD
B. Replace the machine SSL certificates with custom certificates generated from the Enterprise CA. This aligns with the requirement for all external traffic to be secured using certificates signed by an Enterprise CA. D. Replace the VMware Certificate Authority (VMCA) certificate with a custom certificate generated from the Enterprise CA. This eliminates the need for an intermediate CA (VMCA) in the certificate chain, fulfilling the second requirement.
upvoted 1 times
...
nadamos
1 month, 2 weeks ago
Selected Answer: AB
A and B not E because VMCA would be intermediate which are specifically prohibited.
upvoted 1 times
...
carlosj1088
2 months, 2 weeks ago
Selected Answer: BE
The correct answers are B and E because: B. Replace the machine SSL certificates with custom certificates generated from the Enterprise CA. This ensures that all external traffic is secured using certificates signed by the Enterprise Certificate Authority, fulfilling the third requirement. E. Replace the solution user certificates with self-signed certificates generated from the VMware Certificate Authority (VMCA). This minimizes the ongoing management overhead of replacing certificates because the VMCA automatically manages internal certificates, satisfying the first requirement. Additionally, since no intermediate certificate authorities are allowed in the certificate chain (second requirement), it is not appropriate to use the VMCA as an intermediate CA or replace its root certificate. Therefore, options B and E meet all the stated requirements.
upvoted 1 times
PCG1
2 months, 2 weeks ago
You forgot the requirement about any external traffic: solution certificates should definitely not be self signed / VMCA-signed ones, so the correct answer is AB.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago