2V0-13.25 · Question #16
An architect has been tasked with designing a new VMware Cloud Foundation (VCF) solution. The following design decisions were documented after requirements gathering workshops with the customer…
The correct answer is A. Use the external VCF Identity Broker model. C. Deploy a dedicated VCF Identity Broker for each VCF instance within a VCF Fleet. To support MFA and integration with third-party authentication, the external VCF Identity Broker model (VIDB) is required. The external model is designed to interface with advanced identity providers supporting MFA, which the embedded model cannot accommodate. Furthermore, to…
Question
An architect has been tasked with designing a new VMware Cloud Foundation (VCF) solution. The following design decisions were documented after requirements gathering workshops with the customer:
- Deploy a VCF Fleet into each of the DC1 and DC2 datacenters.
- Deploy two VCF instances (VCF1 and VCF2) into each VCF Fleet.
- Use the existing, supported third-party solution to provide
Multifactor Authentication (MFA) for users accessing the VCF components. The architect also documented the following information from the workshops:
- The customer wants to minimize the risk of a single operational task
performed by an administrator impacting multiple components.
- The customer wants to avoid single points of failure by using high
availability architectures. Which two design decisions should the architect include for the authentication approach based on the information provided? (Choose two.)
Options
- AUse the external VCF Identity Broker model.
- BDeploy a shared VCF Identity Broker for all VCF Instances across all VCF Fleets.
- CDeploy a dedicated VCF Identity Broker for each VCF instance within a VCF Fleet.
- DDeploy a shared VCF Identity Broker for all VCF instances within a VCF Fleet.
- EUse the embedded VCF Identity Broker model.
How the community answered
(24 responses)- A67% (16)
- B8% (2)
- D21% (5)
- E4% (1)
Explanation
To support MFA and integration with third-party authentication, the external VCF Identity Broker model (VIDB) is required. The external model is designed to interface with advanced identity providers supporting MFA, which the embedded model cannot accommodate. Furthermore, to avoid shared components across multiple VCF instances and to reduce the impact of operational errors (e.g., configuration or certificate issues), a dedicated Identity Broker per VCF instance ensures complete separation and fault isolation. This approach aligns with VMware's recommended high availability and security practices for VCF 9.0. It ensures the MFA requirement is met and operational risks are minimized.
Topics
Community Discussion
No community discussion yet for this question.