nerdexam
Broadcom-VMware

2V0-13.24 · Question #97

A VMware Cloud Foundation design incorporates the following technical requirements: - All management components must have their login sessions timeout after 2 minutes of inactivity. - Communication…

The correct answer is C. Consult the Compliance Kit for VMware Cloud Foundation. These requirements focus on security and compliance for VCF management components (e.g., vCenter, NSX Manager). Option C, "Consult the Compliance Kit for VMware Cloud Foundation," provides specific guidance on configuring session timeouts (via SSO settings), restricting ports…

Section 4 – Secure VMware Cloud Foundation Solutions

Question

A VMware Cloud Foundation design incorporates the following technical requirements:

  • All management components must have their login sessions timeout

after 2 minutes of inactivity.

  • Communication between management components should be limited to

required ports only.

  • Modifications required by compliancy should not impact the management

components' functionality. What would be the recommendation from a design perspective that would aid in achieving the above requirements?

Options

  • AConsult the vSphere Security Configuration kit
  • BLeverage the results of a vulnerability assessment and apply the recommendations
  • CConsult the Compliance Kit for VMware Cloud Foundation
  • DApply NSX DFW (Distributed Firewall) to achieve zero-trust

How the community answered

(57 responses)
  • A
    4% (2)
  • B
    16% (9)
  • C
    74% (42)
  • D
    7% (4)

Explanation

These requirements focus on security and compliance for VCF management components (e.g., vCenter, NSX Manager). Option C, "Consult the Compliance Kit for VMware Cloud Foundation," provides specific guidance on configuring session timeouts (via SSO settings), restricting ports (via firewall rules), and ensuring compliance changes maintain functionality, tailored to VCF 5.2. Option A (vSphere Security kit) is vSphere-specific, less comprehensive for VCF's multi- component environment. Option B (vulnerability assessment) is reactive, not prescriptive. Option D (NSX DFW) addresses networking but not session timeouts or compliance holistically. The VCF Compliance Kit is purpose-built for such requirements.

Topics

#Compliance Kit#security configuration#session timeout#management components

Community Discussion

No community discussion yet for this question.

Full 2V0-13.24 Practice