nerdexam
Cisco

350-601 · Question #394

An engineer is configuring HTTPS access to Cisco UCS Manager. The engineer created a keyring and created the certificate request for the keyring Cisco UCS Manager continues to receive untrusted…

The correct answer is A. Create a trusted point. After generating a certificate signing request (CSR) in Cisco UCS Manager, to resolve untrusted messages in browsers, the next step is to obtain the signed certificate from a Certificate Authority (CA) and then install that trusted certificate as a "trusted point" within UCS…

Security

Question

An engineer is configuring HTTPS access to Cisco UCS Manager. The engineer created a keyring and created the certificate request for the keyring Cisco UCS Manager continues to receive untrusted messages from a Firefox browser and a Chrome browser. Which action must be taken as the next step in the HTTPS access configuration?

Options

  • ACreate a trusted point
  • BSign the certificate using the Cisco UCS Manager.
  • CObtain a validated certificate from Cisco
  • DInstall a trusted certificate in the browser store

How the community answered

(35 responses)
  • A
    74% (26)
  • B
    3% (1)
  • C
    14% (5)
  • D
    9% (3)

Why each option

After generating a certificate signing request (CSR) in Cisco UCS Manager, to resolve untrusted messages in browsers, the next step is to obtain the signed certificate from a Certificate Authority (CA) and then install that trusted certificate as a "trusted point" within UCS Manager.

ACreate a trusted pointCorrect

When UCS Manager receives a signed certificate from a CA, along with any intermediate and root CA certificates, these must be imported into UCS Manager as a "trusted point." This establishes the complete trust chain within UCS Manager, enabling it to present a fully trusted certificate to client browsers.

BSign the certificate using the Cisco UCS Manager.

Cisco UCS Manager typically acts as a client generating a CSR to be signed by an external CA, not as a CA itself to sign its own certificate for external browser trust.

CObtain a validated certificate from Cisco

While obtaining a validated certificate from a CA is a necessary part of the process, it's not the next *action* to be taken within UCS Manager after the request is created; the next step is to import the CA's response.

DInstall a trusted certificate in the browser store

Installing a trusted certificate in the browser store is generally for adding an enterprise CA's root certificate to the client, but the problem states UCS Manager receives untrusted messages, implying UCS Manager itself needs the trust chain configured as a trusted point.

Concept tested: Cisco UCS Manager HTTPS certificate management

Source: https://www.cisco.com/c/en/us/td/docs/unified_computing/ucs/sw/gui/config/guide/2-0/b_UCSM_GUI_Configuration_Guide_2_0/b_UCSM_GUI_Configuration_Guide_2_0_chapter_01000.html

Topics

#UCS Manager#SSL/TLS Certificates#HTTPS Access#Certificate Trust Chain

Community Discussion

No community discussion yet for this question.

Full 350-601 Practice