nerdexam
Broadcom-VMware

2V0-621 · Question #14

An administrator would like to use the VMware Certificate Authority (VMCA) as an Intermediate Certificate Authority (CA). The first two steps performed are: - Replace the Root Certificate - Replace…

The correct answer is A. Replace Solution User Certificates (Intermediate CA) C. Replace the VMware Directory Service Certificate. When deploying VMCA as an Intermediate CA, after replacing the Root and Machine SSL certificates, the next required steps are replacing Solution User Certificates and the VMware Directory Service Certificate using the correct procedure variants.

Section 1 – Configure and Administer vSphere 6.x Security

Question

An administrator would like to use the VMware Certificate Authority (VMCA) as an Intermediate Certificate Authority (CA). The first two steps performed are:

  • Replace the Root Certificate
  • Replace Machine Certificates (Intermediate CA)

Which two steps would need to be performed next? (Choose two.)

Options

  • AReplace Solution User Certificates (Intermediate CA)
  • BReplace the VMware Directory Service Certificate (Intermediate CA)
  • CReplace the VMware Directory Service Certificate
  • DReplace Solution User Certificates

How the community answered

(58 responses)
  • A
    67% (39)
  • B
    10% (6)
  • D
    22% (13)

Why each option

When deploying VMCA as an Intermediate CA, after replacing the Root and Machine SSL certificates, the next required steps are replacing Solution User Certificates and the VMware Directory Service Certificate using the correct procedure variants.

AReplace Solution User Certificates (Intermediate CA)Correct

Replacing Solution User Certificates via the Intermediate CA procedure is the next required step after Machine SSL replacement, because solution users authenticate internally to vCenter using certificates that must chain back to the enterprise-signed VMCA root. Using the correct '(Intermediate CA)' variant ensures these certificates are issued with the proper intermediate chain.

BReplace the VMware Directory Service Certificate (Intermediate CA)

This option incorrectly labels the VMware Directory Service certificate replacement with an '(Intermediate CA)' qualifier that does not match the documented procedure, making it the wrong process variant to select.

CReplace the VMware Directory Service CertificateCorrect

The VMware Directory Service (vmdird) uses its own certificate for SSO domain replication and authentication, and this certificate must be replaced as part of the full Intermediate CA rollout to ensure all internal vSphere services trust the updated certificate hierarchy.

DReplace Solution User Certificates

Replacing Solution User Certificates without the '(Intermediate CA)' qualifier uses the standard replacement procedure rather than the Intermediate CA workflow, which would not properly chain certificates back to the enterprise-signed root.

Concept tested: VMCA as Intermediate CA certificate replacement workflow

Source: https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.authentication.doc/GUID-5C1A72C8-98F2-4C41-B58F-0E4CF2CF9FB1.html

Topics

#VMCA#Intermediate CA#certificate replacement#certificate authority workflow

Community Discussion

No community discussion yet for this question.

Full 2V0-621 Practice