2V0-621 Flashcards
(240 cards)
An administrator wants to provide users restricted access. The users should only be able to perform the following tasks:
- Create and consolidate virtual machine snapshots
- Add/Remove virtual disks
- Snapshot Management
Which default role in vCenter Server would meet the administrator’s requirements for the users?
A. Virtual machine power user
Which two roles can be modified? (Choose two.)
B. Network Administrator
C. Datastore Consumer
An administrator with global administrator privileges creates a custom role but fails to assign any privileges to it.
Which two privileges would the custom role have? (Choose two.)
A. System.View
B. System.Anonymous
An administrator wishes to give a user the ability to manage snapshots for virtual machines.
Which privilege does the administrator need to assign to the user?
A. Datastore.Allocate Space
An object has inherited permissions from two parent objects.
What is true about the permissions on the object?
B. The permissions are combined from both parent objects.
What is the highest object level from which a virtual machine can inherit privileges?
C. Data Center Folder
Which three Authorization types are valid in vSphere? (Choose three.)
A. Group Membership in vsphere.local
B. Global
D. vCenter Server
Which three components should an administrator select when configuring vSphere permissions? (Choose three.)
A. Inventory Object
B. Role
C. User/Group
In which two vsphere.local groups should an administrator avoid adding members? (Choose two.)
A. SolutionUsers
B. Administrators
An administrator has configured three vCenter Servers and vRealize Orchestrator within a Platform Services Controller domain, and needs to grant a user privileges that span all environments.
Which statement best describes how the administrator would accomplish this?
A. Assign a Global Permission to the user.
Which two methods are recommended for managing the VMware Directory Service? (Choose two).
A. Utilize the vmdir command.
B. Manage through the vSphere Web Client.
What are two sample roles that are provided with vCenter Server by default? (Choose two.)
A. Virtual machine User
B. Network Administrator
An administrator would like to use the VMware Certificate Authority (VMCA) as an Intermediate Certificate Authority (CA). The first two steps performed are:
- Replace the Root Certificate
- Replace Machine Certificates (Intermediate CA)
Which two steps would need to be performed next? (Choose two.)
A. Replace Solution User Certificates (Intermediate CA)
C. Replace the VMware Directory Service Certificate
Which three options are available for ESXi Certificate Replacement? (Choose three.)
A. VMware Certificate Authority mode
B. Custom Certificate Authority mode
C. Thumbprint mode
Lockdown Mode has been enabled on an ESXi 6.x host and users are restricted from logging into the Direct Console User Interface (DCUI).
Which two statements are true given this configuration? (Choose two.)
A. A user granted administrative privileges in the Exception User list can login.
B. A user defined in the DCUI.Access without administrative privileges can login.
Strict Lockdown Mode has been enabled on an ESXi host.
Which action should an administrator perform to allow ESXi Shell or SSH access for users with administrator privileges?
B. Add the users to Exception Users and enable the service.
An administrator wants to configure an ESXi 6.x host to use Active Directory (AD) to manage users and groups. The AD domain group ESX Admins is planned for administrative access to the host.
Which two conditions should be considered when planning this configuration? (Choose two.)
A. If administrative access for ESX Admins is not required, this setting can be altered.
C. An ESXi host provisioned with Auto Deploy cannot store AD credentials.
Which password meets ESXi 6.x host password requirements?
A. 8kMVnn2x!
An administrator would like to use a passphrase for their ESXi 6.x hosts which has these characteristics:
- Minimum of 21 characters
- Minimum of 2 words
Which advanced options must be set to allow this passphrase configuration to be used?
B. retry=3 min=disabled, disabled, 21, 7, 7 passphrase=2
Which Advanced Setting should be created for the vCenter Server to change the expiration policy of the vpxuser password?
A. VimPasswordExpirationInDays
An administrator has been instructed to secure existing virtual machines in vCenter Server.
Which two actions should the administrator take to secure these virtual machines? (Choose two.)
B. Restrict Remote Console access
D. Prevent use of Independent Non-Persistent virtual disks
An administrator has recently audited the environment and found numerous virtual machines with sensitive data written to the configuration files.
To prevent this in the future, which advanced parameter should be applied to the virtual machines?
A. isolation.tools.setinfo.disable = true
Which two statements are correct regarding vSphere certificates? (Choose two.)
B. ESXi host upgrades preserve the existing SSL certificate.
C. ESXi hosts have assigned SSL certificates from the VMware Certificate Authority (VMCA)
Which three options are available for replacing vCenter Server Security Certificates? (Choose three.)
A. Replace with Certificates signed by the VMware Certificate Authority.
B. Make VMware Certificate Authority an Intermediate Certificate Authority.
C. Do not use VMware Certificate Authority, provision your own Certificates.