5V0-22.23 · Question #133
A vSAN administrator has been asked to encrypt all traffic for data and metadata across all hosts in a vSAN cluster. Which action is necessary to achieve this level of encryption?
The correct answer is B. Enable vSAN Data In-Transit encryption at the cluster level; no KMS or NKP is required. vSAN Data In-Transit encryption secures all traffic for data and metadata between hosts in a cluster. It is enabled at the cluster level and does not require a Key Management Server (KMS) or Native Key Provider (NKP). This feature ensures end-to-end encryption for inter-host…
Question
A vSAN administrator has been asked to encrypt all traffic for data and metadata across all hosts in a vSAN cluster. Which action is necessary to achieve this level of encryption?
Options
- ADeploy KMS server, and enable vSAN Data at Rest and In-Transit encryption at the host level
- BEnable vSAN Data In-Transit encryption at the cluster level; no KMS or NKP is required
- CEnable vSAN Cluster level encryption via Storage Policy; no KMS or NKP is required
- DDeploy NKP server, and enable vSAN Data at Rest encryption at the cluster level
How the community answered
(49 responses)- A2% (1)
- B84% (41)
- C10% (5)
- D4% (2)
Explanation
vSAN Data In-Transit encryption secures all traffic for data and metadata between hosts in a cluster. It is enabled at the cluster level and does not require a Key Management Server (KMS) or Native Key Provider (NKP). This feature ensures end-to-end encryption for inter-host communication without affecting storage encryption or requiring additional external configuration.
Topics
Community Discussion
No community discussion yet for this question.