nerdexam
Broadcom-VMware

3V0-21.23 · Question #156

An architect is tasked with creating a design for a vSphere-based solution. Reviewing requirements with the security team, the architect makes the following design decision: ESXi hosts in the…

The correct answer is A. Only certain commands can be executed in the sandboxed shell. When the shell sandbox is enabled on ESXi hosts, it restricts the execution of commands within the shell to ensure that only authorized or safe commands are allowed. This provides a level of isolation that limits the potential for accidental or malicious commands to be run in…

Design for security

Question

An architect is tasked with creating a design for a vSphere-based solution. Reviewing requirements with the security team, the architect makes the following design decision:

ESXi hosts in the environment will enable shell sandbox for SSH connections and the local ESXi shell What is an implication of the design decision to enable shell sandboxing?

Options

  • AOnly certain commands can be executed in the sandboxed shell
  • BOnly administrative accounts can access the sandbox shell
  • CAll commands executed in the sandbox shell will be logged
  • DThe vSphere 8 hosts will operate in strict lockdown mode

How the community answered

(32 responses)
  • A
    91% (29)
  • B
    6% (2)
  • D
    3% (1)

Explanation

When the shell sandbox is enabled on ESXi hosts, it restricts the execution of commands within the shell to ensure that only authorized or safe commands are allowed. This provides a level of isolation that limits the potential for accidental or malicious commands to be run in the shell, enhancing security while still providing necessary administrative access.

Topics

#ESXi shell sandbox#SSH security#security hardening#lockdown mode

Community Discussion

No community discussion yet for this question.

Full 3V0-21.23 Practice