nerdexam
Broadcom-VMware

5V0-43.21 · Question #84

An operator has been asked by the security team to list all the private keys exported from the Avi GUI for the past month. Can the operator fulfill this request?

The correct answer is A. No, Avi does not record key exports. Option A is correct because Avi Vantage does not maintain audit log entries for private key export operations - when a certificate's private key is exported through the GUI, that action is simply not captured in the system's event log, making it impossible for an operator to…

Avi Vantage Platform Operations and Management

Question

An operator has been asked by the security team to list all the private keys exported from the Avi GUI for the past month. Can the operator fulfill this request?

Options

  • ANo, Avi does not record key exports.
  • BYes, Avi records such events if an account exporting the key is different than the account used to
  • CYes, Avi records such events if the Sensitive option has been enabled when importing/creating the
  • DYes, Avi records key export events by default.

How the community answered

(23 responses)
  • A
    96% (22)
  • D
    4% (1)

Explanation

Option A is correct because Avi Vantage does not maintain audit log entries for private key export operations - when a certificate's private key is exported through the GUI, that action is simply not captured in the system's event log, making it impossible for an operator to produce such a list.

Option B is wrong because Avi does not differentiate logging behavior based on whether the exporting account matches the importing account - no such conditional logging exists for key exports.

Option C is wrong because the "Sensitive" flag in Avi controls visibility of the private key field within the UI (masking it from display), not whether export events are audited; enabling it does not activate export logging.

Option D is wrong because Avi does log many administrative events by default, which makes this option tempting - but private key exports are a specific gap in that logging coverage.

Memory tip: Think of it this way - Avi treats the key export action itself as "sensitive" by hiding the key value on screen, but ironically forgets to write it down. No log = no list.

Topics

#Key Export Audit#Security Logging#Certificate Management#Access Controls

Community Discussion

No community discussion yet for this question.

Full 5V0-43.21 Practice