nerdexam
Broadcom-VMware

5V0-43.21 · Question #69

How would an operator replace the default certificate used by the Avi GUI with a trusted certificate?

The correct answer is A. Generate a certificate of type Controller Certificate, then assign it to the management VS. Option A is correct because Avi requires a certificate specifically typed as Controller Certificate - this type is purpose-built for the management plane. Once created, it must be assigned to the management Virtual Service (VS), which is the VS that serves the Avi GUI; without…

Avi Vantage Platform Deployment and Configuration

Question

How would an operator replace the default certificate used by the Avi GUI with a trusted certificate?

Options

  • AGenerate a certificate of type Controller Certificate, then assign it to the management VS.
  • BGenerate a certificate of type Controller Certificate, then update the Access Settings under
  • CAvi can auto-generate a trusted certificate from the GUI and use it for the GUI access.
  • DThe default certificate used by the Avi GUI is already trusted.

How the community answered

(26 responses)
  • A
    81% (21)
  • B
    4% (1)
  • C
    12% (3)
  • D
    4% (1)

Explanation

Option A is correct because Avi requires a certificate specifically typed as Controller Certificate - this type is purpose-built for the management plane. Once created, it must be assigned to the management Virtual Service (VS), which is the VS that serves the Avi GUI; without that assignment step, the certificate exists in inventory but is never used.

Option B is a near-miss distractor - "Access Settings" is a real location in Avi, but the authoritative path to apply a trusted cert to the GUI is through the management VS assignment, not just updating Access Settings. The answer is also visibly truncated, signaling an incomplete/incorrect workflow.

Option C is wrong because Avi has no built-in ACME/CA integration to auto-generate a trusted certificate. It can only generate self-signed certificates on its own, which browsers will still flag as untrusted.

Option D is wrong because the factory-default certificate is self-signed by Avi's own CA, which is not in any browser trust store - hence the browser warning on first login.

Memory tip: Think "type then target" - first pick the right type (Controller Certificate), then hit the right target (management VS). If either step is missing or mismatched, the trusted cert never takes effect.

Topics

#Certificate Management#Controller Certificate#Management Virtual Service#Avi GUI Security

Community Discussion

No community discussion yet for this question.

Full 5V0-43.21 Practice