nerdexam
Broadcom-VMware

2V0-621 · Question #31

Which group in the vsphere.local domain will have administrator privileges for the VMware Certificate Authority (VMCA)?

The correct answer is B. CAAdmins. The CAAdmins group in the vsphere.local domain is the designated group for managing the VMware Certificate Authority.

Section 1 – Configure and Administer vSphere 6.x Security

Question

Which group in the vsphere.local domain will have administrator privileges for the VMware Certificate Authority (VMCA)?

Options

  • ASolutionUsers
  • BCAAdmins
  • CDCAAdmins
  • DSystemConfiguration.Administrators

How the community answered

(26 responses)
  • A
    4% (1)
  • B
    92% (24)
  • C
    4% (1)

Why each option

The CAAdmins group in the vsphere.local domain is the designated group for managing the VMware Certificate Authority.

ASolutionUsers

SolutionUsers is a group for vSphere solution accounts that need to authenticate to vCenter services, not for administering the certificate authority.

BCAAdminsCorrect

The CAAdmins group in vsphere.local is specifically designated to grant members administrative privileges over the VMCA, allowing them to issue, revoke, and manage certificates within the vSphere environment.

CDCAAdmins

DCAAdmins is not a valid built-in vsphere.local group in vSphere's SSO domain structure.

DSystemConfiguration.Administrators

SystemConfiguration.Administrators grants rights to manage system configuration and services in vSphere, not specifically the VMCA.

Concept tested: vsphere.local built-in groups and VMCA administration

Source: https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.authentication.doc/GUID-73EFCEDB-A01D-4B5C-B8E0-FE342F1BD20A.html

Topics

#VMCA administration#vsphere.local groups#CAAdmins#SSO groups

Community Discussion

No community discussion yet for this question.

Full 2V0-621 Practice