nerdexam
Cisco

350-601 · Question #70

An engineer has a primary fabric that is named UCS-A and a secondary fabric that is named UCS-B. A certificate request that has a subject name of sjc2016 for a keyring that is named kr2016 needs to…

The correct answer is D. UCS-A# scope security. In Cisco UCS Manager, PKI certificate operations must be performed on the primary fabric interconnect (UCS-A). The correct command sequence begins with 'UCS-A# scope security' to enter the security configuration context, then 'scope keyring kr2016' to enter the specific…

Security

Question

An engineer has a primary fabric that is named UCS-A and a secondary fabric that is named UCS-B. A certificate request that has a subject name of sjc2016 for a keyring that is named kr2016 needs to be created. The cluster IP address is 10.68.68.68. Which command set creates this certificate request?

Options

  • AUCS-A # scope keyring kr2016
  • BUCS-B # scope keyring kr2016
  • CUCS-B# scope security
  • DUCS-A# scope security

How the community answered

(17 responses)
  • C
    6% (1)
  • D
    94% (16)

Explanation

In Cisco UCS Manager, PKI certificate operations must be performed on the primary fabric interconnect (UCS-A). The correct command sequence begins with 'UCS-A# scope security' to enter the security configuration context, then 'scope keyring kr2016' to enter the specific keyring, followed by 'create certreq subject-name sjc2016 ip 10.68.68.68' to generate the certificate signing request (CSR). Option B and C are incorrect because certificate requests must originate from the primary fabric (UCS-A), not the subordinate fabric (UCS-B). Option A is incorrect because it starts directly with 'scope keyring' without first entering the security scope, which is not a valid command sequence in UCS Manager's CLI hierarchy.

Topics

#Cisco UCS Manager#Certificate Management#CLI Configuration#Security

Community Discussion

No community discussion yet for this question.

Full 350-601 Practice