2V0-621 · Question #17
Strict Lockdown Mode has been enabled on an ESXi host. Which action should an administrator perform to allow ESXi Shell or SSH access for users with administrator privileges?
The correct answer is B. Add the users to Exception Users and enable the service. In Strict Lockdown Mode, direct ESXi Shell or SSH access is only possible for users explicitly added to the Exception Users list, combined with enabling the relevant service.
Question
Strict Lockdown Mode has been enabled on an ESXi host. Which action should an administrator perform to allow ESXi Shell or SSH access for users with administrator privileges?
Options
- AGrant the users the administrator role and enable the service.
- BAdd the users to Exception Users and enable the service.
- CNo action can be taken, Strict Lockdown Mode prevents direct access.
- DAdd the users to vsphere.local and enable the service.
How the community answered
(35 responses)- A9% (3)
- B77% (27)
- C11% (4)
- D3% (1)
Why each option
In Strict Lockdown Mode, direct ESXi Shell or SSH access is only possible for users explicitly added to the Exception Users list, combined with enabling the relevant service.
Holding the administrator role does not grant an exemption from Strict Lockdown Mode - only placement on the Exception Users list allows a user to bypass the lockdown restriction for direct host access.
The Exception Users list in ESXi allows specific local or Active Directory users to retain their defined access privileges even when Strict Lockdown Mode is active on the host. The administrator must also enable the ESXi Shell or SSH service independently, as the Exception Users list only preserves privilege status and does not automatically start services. This is the only VMware-supported mechanism to permit direct host access under Strict Lockdown Mode.
Strict Lockdown Mode does not entirely prevent all direct access; it specifically permits access for users who appear on the Exception Users list, making this statement technically incorrect.
Adding users to vsphere.local (the SSO domain used by vCenter) has no effect on ESXi Strict Lockdown Mode exception handling, which is controlled exclusively through the per-host Exception Users list.
Concept tested: ESXi Strict Lockdown Mode Exception Users list
Source: https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.security.doc/GUID-F8F105F7-CF93-46DF-9319-D8991FF406CF.html
Topics
Community Discussion
No community discussion yet for this question.