nerdexam
Cisco

350-601 · Question #195

An engineer is implementing Cisco Intersight in a secure environment. The environment must use LDAP directory service and ensure information integrity and confidentiality. Which two steps must be…

The correct answer is A. Enable Encryption for LDAP. D. Add a trusted root LDAP certificate to Cisco Intersight. To implement secure LDAP directory services with Cisco Intersight, ensuring information integrity and confidentiality, the engineer must enable encryption for LDAP and add a trusted root LDAP certificate to Intersight. Encryption secures the communication, while the trusted…

Security

Question

An engineer is implementing Cisco Intersight in a secure environment. The environment must use LDAP directory service and ensure information integrity and confidentiality. Which two steps must be taken to implement the solution? (Choose two.)

Options

  • AEnable Encryption for LDAP.
  • BAdd a self-signed LDAP certificate to Cisco Intersight.
  • CEnable Certificate Signing Request in Cisco Intersight.
  • DAdd a trusted root LDAP certificate to Cisco Intersight
  • EAdd a trusted OAuth token to Cisco Intersight.

How the community answered

(28 responses)
  • A
    86% (24)
  • B
    7% (2)
  • C
    4% (1)
  • E
    4% (1)

Why each option

To implement secure LDAP directory services with Cisco Intersight, ensuring information integrity and confidentiality, the engineer must enable encryption for LDAP and add a trusted root LDAP certificate to Intersight. Encryption secures the communication, while the trusted root certificate validates the LDAP server's identity.

AEnable Encryption for LDAP.Correct

Enabling encryption for LDAP (LDAPS) ensures confidentiality and integrity of the communication between Cisco Intersight and the LDAP directory service by encrypting the data in transit. This addresses the requirement for information integrity and confidentiality.

BAdd a self-signed LDAP certificate to Cisco Intersight.

Adding a self-signed LDAP certificate directly to Intersight is generally not recommended for secure, production environments as it bypasses the chain of trust provided by a Certificate Authority.

CEnable Certificate Signing Request in Cisco Intersight.

Enabling a Certificate Signing Request (CSR) in Cisco Intersight is used to generate a request for Intersight's own server certificate, not for importing an LDAP server's certificate for client-side trust.

DAdd a trusted root LDAP certificate to Cisco IntersightCorrect

To establish trust and validate the identity of the LDAP server when using LDAPS, Cisco Intersight must be configured with the trusted root certificate of the certificate authority that issued the LDAP server's certificate. This is crucial for secure communication.

EAdd a trusted OAuth token to Cisco Intersight.

OAuth tokens are used for API authentication and authorization, not for securing LDAP directory service connections for user authentication.

Concept tested: Cisco Intersight secure LDAP integration

Source: https://www.cisco.com/c/en/us/td/docs/unified_computing/intersight/sw/admin-guide/b_Cisco_Intersight_Administration_Guide/b_Cisco_Intersight_Administration_Guide_chapter_01000.html

Topics

#Cisco Intersight#LDAP Integration#Secure Communication#Certificates

Community Discussion

No community discussion yet for this question.

Full 350-601 Practice