nerdexam
Broadcom-VMware

2V0-21.23 · Question #18

An administrator is tasked with migrating a single virtual machine (VM) from an existing VMware vCenter to a secure environment where corporate security policy requires that all VMs be encrypted…

The correct answer is A. Ensure that the source and destination vCenter instances share the same Key Management C. Ensure that the VM is encrypted before attempting the migration. To successfully migrate a virtual machine (VM) to an environment requiring encryption, the VM must first be encrypted, and both source and destination vCenter instances must share the same Key Management Server (KMS).

Administrative and Operational Tasks

Question

An administrator is tasked with migrating a single virtual machine (VM) from an existing VMware vCenter to a secure environment where corporate security policy requires that all VMs be encrypted. The secure environment consists of a dedicated vCenter instance with a 4-node vSphere cluster and already contains a number of encrypted VMs. Which two steps must the administrator take to ensure the migration is a success? (Choose two.)

Options

  • AEnsure that the source and destination vCenter instances share the same Key Management
  • BEnsure that Encrypted vMotion is turned off for the VM.
  • CEnsure that the VM is encrypted before attempting the migration.
  • DEnsure that the VM is powered off before attempting the migration.
  • EEnsure that the source and destination vCenter Servers have a different Key Management Server

How the community answered

(46 responses)
  • A
    80% (37)
  • B
    7% (3)
  • D
    11% (5)
  • E
    2% (1)

Why each option

To successfully migrate a virtual machine (VM) to an environment requiring encryption, the VM must first be encrypted, and both source and destination vCenter instances must share the same Key Management Server (KMS).

AEnsure that the source and destination vCenter instances share the same Key ManagementCorrect

For an encrypted VM to be accessible and manageable in the destination environment, both vCenter instances must be able to retrieve the decryption keys. Sharing the same Key Management Server (KMS) ensures that the destination environment can decrypt the VM's data using the appropriate keys.

BEnsure that Encrypted vMotion is turned off for the VM.

Encrypted vMotion should generally be enabled for encrypted VMs to maintain data confidentiality during live migration, not turned off.

CEnsure that the VM is encrypted before attempting the migration.Correct

Since the corporate security policy requires all VMs in the secure environment to be encrypted, the VM must be encrypted on the source vCenter before migration to comply with this requirement and ensure operational success post-migration.

DEnsure that the VM is powered off before attempting the migration.

vSphere supports live migration (vMotion) of encrypted virtual machines, meaning the VM does not need to be powered off for the migration to occur.

EEnsure that the source and destination vCenter Servers have a different Key Management Server

Having different Key Management Servers would prevent the destination vCenter from accessing the encryption keys used by the source, making the migrated VM unusable.

Concept tested: vSphere VM encryption migration requirements

Source: https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-E262512F-8924-4363-A816-7B836585160E.html

Topics

#VM Encryption#vMotion#Key Management Server#vCenter Migration

Community Discussion

No community discussion yet for this question.

Full 2V0-21.23 Practice