nerdexam
Broadcom-VMware

2V0-621 · Question #28

Which two statements are correct regarding vSphere certificates? (Choose two.)

The correct answer is B. ESXi host upgrades preserve the existing SSL certificate. C. ESXi hosts have assigned SSL certificates from the VMware Certificate Authority (VMCA) during. In vSphere, ESXi hosts receive SSL certificates from VMCA when added to vCenter, and those certificates are retained - not replaced - when the host is upgraded.

Section 1 – Configure and Administer vSphere 6.x Security

Question

Which two statements are correct regarding vSphere certificates? (Choose two.)

Options

  • AESXi host upgrades do not preserve the SSL certificate and reissue one from the VMware
  • BESXi host upgrades preserve the existing SSL certificate.
  • CESXi hosts have assigned SSL certificates from the VMware Certificate Authority (VMCA) during
  • DESXi hosts have self-signed SSL certificates by default.

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    91% (20)
  • D
    5% (1)

Why each option

In vSphere, ESXi hosts receive SSL certificates from VMCA when added to vCenter, and those certificates are retained - not replaced - when the host is upgraded.

AESXi host upgrades do not preserve the SSL certificate and reissue one from the VMware

This statement is incorrect - ESXi host upgrades preserve the existing certificate rather than reissuing a new one from VMCA, maintaining continuity of secure management connections.

BESXi host upgrades preserve the existing SSL certificate.Correct

ESXi host upgrades preserve the existing SSL certificate rather than issuing a new one, ensuring that trust relationships, certificate pinning, and management connectivity are not disrupted by the upgrade process. This behavior prevents the need for re-trust operations across vCenter and any external tools that have pinned the host certificate after an upgrade.

CESXi hosts have assigned SSL certificates from the VMware Certificate Authority (VMCA) duringCorrect

When an ESXi host is provisioned or added to a vCenter Server environment, VMCA automatically generates and assigns a signed SSL certificate to the host as part of the default certificate management workflow introduced in vSphere 6.0. This replaces the older model of purely self-signed certificates and centralizes certificate authority management under VMCA.

DESXi hosts have self-signed SSL certificates by default.

ESXi hosts managed by a vCenter Server receive VMCA-signed certificates by default rather than purely self-signed certificates, which was the pre-vSphere 6.0 behavior before VMCA was introduced.

Concept tested: vSphere VMCA certificate assignment and upgrade certificate preservation

Source: https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.authentication.doc/GUID-AFEFB75D-7E55-4791-9CC0-E36A10CC8773.html

Topics

#SSL certificates#VMCA#ESXi upgrade#certificate management

Community Discussion

No community discussion yet for this question.

Full 2V0-621 Practice