nerdexam
Broadcom-VMware

2V0-622 · Question #28

Which two statements are correct regarding vSphere certificates? (Choose two.)

The correct answer is B. ESXi host upgrades preserve the existing SSL certificate. C. ESXi hosts have assigned SSL certificates from the VMware Certificate Authority (VMCA) during. ESXi hosts receive SSL certificates from VMCA during provisioning and retain those certificates across upgrades rather than having them replaced.

Section 1 – Configure and Administer vSphere 6.5 Security

Question

Which two statements are correct regarding vSphere certificates? (Choose two.)

Options

  • AESXi host upgrades do not preserve the SSL certificate and reissue one from the VMware
  • BESXi host upgrades preserve the existing SSL certificate.
  • CESXi hosts have assigned SSL certificates from the VMware Certificate Authority (VMCA) during
  • DESXi hosts have self-signed SSL certificates by default.

How the community answered

(24 responses)
  • A
    8% (2)
  • B
    88% (21)
  • D
    4% (1)

Why each option

ESXi hosts receive SSL certificates from VMCA during provisioning and retain those certificates across upgrades rather than having them replaced.

AESXi host upgrades do not preserve the SSL certificate and reissue one from the VMware

ESXi host upgrades do preserve the existing SSL certificate rather than reissuing one - this statement is the direct factual contradiction of correct answer B.

BESXi host upgrades preserve the existing SSL certificate.Correct

When an ESXi host is upgraded, the existing SSL certificate issued by VMCA is preserved and not replaced, ensuring continuity of trust relationships and preventing unnecessary certificate re-provisioning workflows.

CESXi hosts have assigned SSL certificates from the VMware Certificate Authority (VMCA) duringCorrect

During initial provisioning or addition to a vCenter environment, ESXi hosts are issued SSL certificates signed by the VMware Certificate Authority (VMCA), integrating the host into the vSphere certificate trust hierarchy managed by vCenter.

DESXi hosts have self-signed SSL certificates by default.

While standalone ESXi hosts generate self-signed certificates at initial installation, once managed by vCenter they receive VMCA-signed certificates, making the characterization of self-signed as the default inaccurate in a managed vCenter environment.

Concept tested: vSphere VMCA certificate assignment and upgrade behavior

Source: https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.security.doc/GUID-A5310A42-FA0A-4014-9D02-5FE77C1DBEF3.html

Topics

#vSphere certificates#SSL certificates#VMCA#ESXi host upgrades

Community Discussion

No community discussion yet for this question.

Full 2V0-622 Practice