2V0-11.25 · Question #127
Following an update to the Information Security policy, an administrator has been reviewing the status SSL certificates within the VMware Cloud Foundation (VCF) solution. The new Information…
The correct answer is C. Integrate the Microsoft CA into SDDC Manager. D. In SDDC Manager, replace the SSL certificates for vCenter, NSX Manager, SDDC Manager and F. In SDDC Manager, replace the SSL certificates for vCenter, ESXi, NSX Manager, SDDC. C: To replace SSL certificates for VMware Cloud Foundation components using SDDC Manager, you must first integrate your Microsoft CA with SDDC Manager. This allows SDDC Manager to automate the certificate signing process using the organization's enterprise CA." F: With…
Question
Following an update to the Information Security policy, an administrator has been reviewing the status SSL certificates within the VMware Cloud Foundation (VCF) solution. The new Information Security Policy states:
All SSL certificates must be generated and signed from the shared Microsoft Certificate Authority (CA). The administrator has discovered the following:
All Aria Suite Components already use CA-signed Subject Alternate Name (SAN) SSL certificates. All other VCF-based SSL certificates are either self-signed or generated using the VMware Certificate Authority (VMCA). Which three steps must the administrator take to ensure the VCF solution remains compliant and managed by SDDC Manager? (Choose three.)
Options
- AIn VMware vCenter, replace the ESXi SSL certificates.
- BIntegrate the OpenSSL CA into SDDC Manager.
- CIntegrate the Microsoft CA into SDDC Manager.
- DIn SDDC Manager, replace the SSL certificates for vCenter, NSX Manager, SDDC Manager and
- EIn Aria Suite Lifecycle, replace the VMware Identity Manager, Aria Automation, Aria Operations
- FIn SDDC Manager, replace the SSL certificates for vCenter, ESXi, NSX Manager, SDDC
How the community answered
(49 responses)- A8% (4)
- B6% (3)
- C84% (41)
- E2% (1)
Explanation
C: To replace SSL certificates for VMware Cloud Foundation components using SDDC Manager, you must first integrate your Microsoft CA with SDDC Manager. This allows SDDC Manager to automate the certificate signing process using the organization's enterprise CA." F: With Microsoft CA integration, you can use SDDC Manager to generate and replace SSL certificates for all key solution components, including vCenter, ESXi, NSX Manager, SDDC Manager, and Aria Suite Lifecycle. This process ensures full visibility and management through D: Certificate replacement workflows in SDDC Manager allow you to select which managed components have their certificates replaced with CA-signed certificates. You must select and update all components that are not already using compliant CA-signed certificates.
Topics
Community Discussion
No community discussion yet for this question.