nerdexam
Broadcom-VMware

2V0-621 · Question #36

An administrator needs to create an Integrated Windows Authentication (IWA) Identity Source on a newly deployed vCenter Server Appliance (VCSA). Which two actions will accomplish this? (Choose two.)

The correct answer is A. Use a Service Principal Name (SPN) to configure the Identity Source. C. Join the VCSA to Active Directory and configure the Identity Source with a Machine Account. IWA identity source on VCSA is configured either by joining the appliance to Active Directory using a Machine Account or by specifying a Service Principal Name (SPN).

Section 1 – Configure and Administer vSphere 6.x Security

Question

An administrator needs to create an Integrated Windows Authentication (IWA) Identity Source on a newly deployed vCenter Server Appliance (VCSA). Which two actions will accomplish this? (Choose two.)

Options

  • AUse a Service Principal Name (SPN) to configure the Identity Source.
  • BUse a Domain administrator to configure the Identity Source.
  • CJoin the VCSA to Active Directory and configure the Identity Source with a Machine Account.
  • DCreate a computer account in Active Directory for the VCSA and configure the Identity Source.

How the community answered

(58 responses)
  • A
    84% (49)
  • B
    10% (6)
  • D
    5% (3)

Why each option

IWA identity source on VCSA is configured either by joining the appliance to Active Directory using a Machine Account or by specifying a Service Principal Name (SPN).

AUse a Service Principal Name (SPN) to configure the Identity Source.Correct

Using a Service Principal Name (SPN) is a valid method to configure an IWA identity source on a VCSA that has not been domain-joined, as the SPN provides the necessary Kerberos identity mapping to Active Directory without requiring full domain membership.

BUse a Domain administrator to configure the Identity Source.

Providing a Domain Administrator credential alone is not a recognized configuration method for IWA on VCSA - the identity source requires either a Machine Account (via domain join) or an SPN, not a generic administrative account.

CJoin the VCSA to Active Directory and configure the Identity Source with a Machine Account.Correct

Joining the VCSA to Active Directory and using the resulting Machine Account is the standard domain-join method for IWA - the domain join process automatically registers the VCSA as a computer object in AD, and that Machine Account is then used to authenticate the IWA identity source connection.

DCreate a computer account in Active Directory for the VCSA and configure the Identity Source.

Manually creating a separate computer account in AD is not a distinct supported approach - when joining the VCSA to the domain (option C), the machine account is created automatically as part of that process, making a separate manual creation step redundant and not a prescribed workflow.

Concept tested: Configuring IWA identity source on vCenter Server Appliance

Source: https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-authentication/GUID-D2EEF652-6B8E-4708-ABFD-B1572C968898.html

Topics

#IWA identity source#VCSA Active Directory#SPN#machine account

Community Discussion

No community discussion yet for this question.

Full 2V0-621 Practice