nerdexam
Broadcom-VMware

2V0-621 · Question #19

An administrator wants to configure an ESXi 6.x host to use Active Directory (AD) to manage users and groups. The AD domain group ESX Admins is planned for administrative access to the host. Which…

The correct answer is A. If administrative access for ESX Admins is not required, this setting can be altered. C. An ESXi host provisioned with Auto Deploy cannot store AD credentials. Joining an ESXi host to Active Directory grants the ESX Admins group full host admin privileges by default, and Auto Deploy hosts cannot persistently store AD credentials across reboots.

Section 1 – Configure and Administer vSphere 6.x Security

Question

An administrator wants to configure an ESXi 6.x host to use Active Directory (AD) to manage users and groups. The AD domain group ESX Admins is planned for administrative access to the host. Which two conditions should be considered when planning this configuration? (Choose two.)

Options

  • AIf administrative access for ESX Admins is not required, this setting can be altered.
  • BThe users in ESX Admins are not restricted by Lockdown Mode.
  • CAn ESXi host provisioned with Auto Deploy cannot store AD credentials.
  • DThe users in ESX Admins are granted administrative privileges in vCenter Server.

How the community answered

(40 responses)
  • A
    80% (32)
  • B
    8% (3)
  • D
    13% (5)

Why each option

Joining an ESXi host to Active Directory grants the ESX Admins group full host admin privileges by default, and Auto Deploy hosts cannot persistently store AD credentials across reboots.

AIf administrative access for ESX Admins is not required, this setting can be altered.Correct

By default, ESXi automatically grants full administrative privileges to any AD group named 'ESX Admins', but this default group name and behavior can be changed by the administrator if that level of automatic privilege assignment is not desired for the environment.

BThe users in ESX Admins are not restricted by Lockdown Mode.

Members of the ESX Admins AD group are subject to Lockdown Mode restrictions just like other users - they are not automatically exempted unless they are also added to the Exception Users list on the host.

CAn ESXi host provisioned with Auto Deploy cannot store AD credentials.Correct

ESXi hosts provisioned via Auto Deploy boot statelessly from a network image and have no persistent local storage, so they cannot retain Kerberos tickets or other AD credentials between reboots, which requires additional planning for AD-based authentication in Auto Deploy environments.

DThe users in ESX Admins are granted administrative privileges in vCenter Server.

The ESX Admins group grants administrative privileges only on the ESXi host itself, not in vCenter Server, as vCenter Server manages its own separate permissions system independent of ESXi host-level AD group assignments.

Concept tested: ESXi Active Directory integration and Auto Deploy AD credential limitations

Source: https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.security.doc/GUID-DC96FFDB-F5F2-43EC-8C73-05ACDAE6BE43.html

Topics

#Active Directory integration#ESX Admins group#Auto Deploy#AD credentials

Community Discussion

No community discussion yet for this question.

Full 2V0-621 Practice