V6-FC Flashcards
(242 cards)
Question NO: 1
An administrator wants to provide users restricted access. The users should only be able to perform the following tasks: Create and consolidate virtual machine snapshots Add/Remove virtual disks Snapshot Management Which default role in vCenter Server would meet the administrator's requirements for the users? A. Virtual machine user B. Virtual machine power user C. Virtual Datacenter administrator D. VMware Consolidated Backup user
Answer:
B
Explanation:
Virtual Machine Power User is a sample role that grants a useraccess rights only to virtual
machines; can alter the virtual hardware or create snapshots of the VM.
Reference:http://blog.pluralsight.com/vmware-access-control-101-roles-and-permissions
Question NO: 2
Which two roles can be modified? (Choose two.) A. Administrator Vmware 2V0-621D Exam Pass Any Exam. Any Time. - www.actualtests.com 2 B. Network Administrator C. Datastore Consumer D. Read-Only
Answer:
B,C
Explanation:
It is a common knowledge that you cannot modify Administrator role and grant whatever privileges
you like. Same is the case with read-only. This role is created solely for ready only purposes. So
you are left with two viable options ? Network administrator and Datastore consumer both of which
can be modified to add or delete privileges according to your specifications.
Question NO: 3
An administrator with global administrator privileges creates a custom role but fails to assign any privileges to it. Which two privileges would the custom role have? (Choose two.) A. System.View B. System.Anonymous C. System.User D. System.ReadOnly
Answer:
A,B
Explanation:
When you add a custom role and do not assign any privileges to it, the role is created as a Read
Only role with three system-defined privileges: System.Anonymous, System.View, and
System.Read.
Vmware 2V0-621D Exam
Pass Any Exam. Any Time. - www.actualtests.com 3
Reference:https://pubs.vmware.com/vsphere-
51/index.jsp?topic=%2Fcom.vmware.vsphere.security.doc%2FGUID-93B962A7-93FA-4E96-
B68F-AE66D3D6C663.html
Question NO: 4
An administrator wishes to give a user the ability to manage snapshots for virtual machines.
Which privilege does the administrator need to assign to the user?
A.
Datastore.Allocate Space
B.
Virtual machine.Configuration.create snapshot
C.
Virtual machine.Configuration.manage snapshot
D.
Datastore.Browse Datastore
Answer:
A
Explanation:
Datastore.Allocate space allows allocating space on a datastore for avirtual machine, snapshot,
clone, or virtual disk.
Reference:https://pubs.vmware.com/vsphere-
51/index.jsp?topic=%2Fcom.vmware.vsphere.security.doc%2FGUID-B2426ACC-D73F-4732-
8BBC-DE9B1B2263D9.html
Question NO: 5
An object has inherited permissions from two parent objects.
What is true about the permissions on the object?
Vmware 2V0-621D Exam
Pass Any Exam. Any Time. - www.actualtests.com 4
A.
The common permissions between the two are applied and the rest are discarded.
B.
The permissions are combined from both parent objects.
C.
No permissions are applied from the parent objects.
D.
The permission is randomly selected from either of the two parent objects.
Answer:
B
Explanation:
Most inventory objects inherit permissions from a single parent object in the hierarchy. For
example, a datastore inherits permissions from either its parent datastore folder or parent
datacenter. Virtual machines inherit permissions from both the parent virtual machine folder and
the parent host, cluster, or resource pool simultaneously. To restrict a user?s privileges on a virtual
machine, you must set permissions on both the parent folder and the parent host, cluster, or
resource pool for thatvirtual machine.
Reference:http://pubs.vmware.com/vsphere-4-esxvcenter/
index.jsp?topic=/com.vmware.vsphere.dcadmin.doc_41/vsp_dc_admin_guide/managing_
users_groups_roles_and_permissions/c_hierarchical_inheritance_of_permissions.html
Question NO: 6
What is the highest object level from which a virtual machine can inherit privileges? A. Host Folder B. Data Center C. Data Center Folder D. VM Folder
Answer:
C
Vmware 2V0-621D Exam
Pass Any Exam. Any Time. - www.actualtests.com 5
Explanation:
Reference:http://www.vmware.com/pdf/vi3_vc_roles.pdf
Question NO: 7
Which three Authorization types are valid in vSphere? (Choose three.) A. Group Membership in vsphere.local Vmware 2V0-621D Exam Pass Any Exam. Any Time. - www.actualtests.com 6 B. Global C. Forest D. vCenter Server E. Group Membership in system-domain
Answer:
A,B,D
Explanation:
Sphere 6.0 and later allows privileged users to give other users permissions to perform tasks in
the following ways. These approaches are, for the most part, mutually exclusive; however, you can
assign use global permissions to authorizecertain users for all solution, and localvCenter
Serverpermissions to authorize other users for individualvCenter Serversystems.
vCenter ServerPermissions
The permission model forvCenter Serversystems relies on assigning permissions to objects in
theobject hierarchy of thatvCenter Server. Each permission gives one user or group a set of
privileges, that is, a role for a selected object. For example, you can select anESXihost and assign
a role to a group of users to give those users the corresponding privileges on that host.
Global Permissions
Global permissions are applied to a global root object that spans solutions. For example, if
bothvCenter Serverand vCenter Orchestrator are installed, you can give permissions to all objects
in both object hierarchies using global permissions.
Global permissions are replicated across the vsphere.local domain. Global permissions to not
provide authorization for services managed through vsphere.local groups. SeeGlobal Permissions.
Group Membership in vsphere.local Groups
The user administrator@vsphere.local can perform tasks that are associated withservices
included with thePlatform Services Controller. In addition, members of a vsphere.local group can
perform the corresponding task. For example, you can perform license management if you are a
member of the LicenseService.Administrators group. SeeGroups in the vsphere.local Domain.
Reference:http://pubs.vmware.com/vsphere-
60/index.jsp?topic=%2Fcom.vmware.vsphere.security.doc%2FGUID-74F53189-EF41-4AC1-
A78E-D25621855800.html
Vmware 2V0-621D Exam
Pass Any Exam. Any Time. - www.actualtests.com 7
Question NO: 8
Which three components should an administrator select when configuring vSphere permissions? (Choose three.) A. Inventory Object B. Role C. User/Group D. Privilege E. Password
Answer:
A,B,C
Explanation:
InvSphere, permission consists of a user or group and an assigned role for an inventory object,
such as a virtual machine or ESX/ESXi host. Permissions grant users the right to perform the
activities specified by the role on the object to which the role is assigned.
Reference:http://pubs.vmware.com/vsphere-4-esxvcenter/
index.jsp?topic=/com.vmware.vsphere.dcadmin.doc_41/vsp_dc_admin_guide/managing_
users_groups_roles_and_permissions/c_permissions.html
Question NO: 9
In which two vsphere.local groups should an administrator avoid adding members? (Choose two.) A. SolutionUsers B. Administrators Vmware 2V0-621D Exam Pass Any Exam. Any Time. - www.actualtests.com 8 C. DCAdmins D. ExternalPDUsers
Answer:
A,B
Explanation:
The vsphere.local domain includes several predefined groups. Assign users to one of those
groups to be able to perform the corresponding actions.
For all objects in the vCenter Server hierarchy, permissions are assigned by pairing a user and a
role with the object. For example, you can select a resource pool and give a group of users read
privileges to that resource pool by givingthem the corresponding role.
For some services that are not managed by vCenter Server directly, privileges are determined by
membership to one of the vCenter Single Sign-On groups. For example, a user who is a member
of the Administrator group can managevCenter Single Sign-On. A user who is a member of the
CAAdmins group can manage the VMware Certificate Authority, and a user who is in the
LicenseService.Administrators group can manage licenses.
Reference:https://pubs.vmware.com/vsphere-
60/index.jsp?topic=%2Fcom.vmware.vsphere.security.doc%2FGUID-87DA2F34-DCC9-4DAB-
8900-1BA35837D07E.html
Question NO: 10
An administrator has configured three vCenter Servers and vRealize Orchestrator within a
Platform Services Controller domain, and needs to grant a user privileges that span all
environments.
Which statement best describes how the administrator would accomplish this?
A.
Assign a Global Permission to the user.
B.
Assign a vCenter Permission to the user.
C.
Vmware 2V0-621D Exam
Pass Any Exam. Any Time. - www.actualtests.com 9
Assign vsphere.local membership to the user.
D.
Assign an ESXi Permission to the user.
Answer:
A
Explanation:
Global permissions are applied to aglobal root object that spans solutions, for example, both
vCenter Server and vCenter Orchestrator. Use global permissions to give a user or group
privileges for all objects in all object hierarchies.
Reference:http://pubs.vmware.com/vsphere-
60/index.jsp?topic=%2Fcom.vmware.vsphere.security.doc%2FGUID-C7702E31-1623-4189-
89CB-E1136AA27972.html
Question NO: 11
Which two methods are recommended for managing the VMware Directory Service? (Choose two.) A. Utilize the vmdir command. B. Manage through the vSphere Web Client. C. Manage using the VMware Directory Service. D. Utilize the dc rep command.
Answer:
A,B
Explanation:
To manage VMware directory service, you can use vmdir command and vsphere web client.
VMware directory service is always managed using vmdir command which is specifically used for
directory services.
Vmware 2V0-621D Exam
Pass Any Exam. Any Time. - www.actualtests.com 10
Question NO: 12
What are two sample roles that are provided with vCenter Server by default? (Choose two.) A. Virtual machine User B. Network Administrator C. Content Library Administrator D. Storage Administrator
Answer:
A,B
Explanation:
Reference:https://books.google.com.pk/books?id=35TE4cSycNAC&pg=PA97&lpg=PA97&dq=sam
ple+roles+that+are+provided+with+vCenter+Server+by+default&source=bl&ots=ggd5VKGky5&sig
=-lc0JubytkvddWsrG_
zHgEDTQY&hl=en&sa=X&ved=0CDcQ6AEwBWoVChMIlZH2x8WExgIVxDoUCh2N1
AC2#v=onepage&q=sample%20roles%20that%20are%20provided%20with%20vCenter%20Serve
r%20by%20default&f=false
Question NO: 13
An administrator would like to use the VMware Certificate Authority (VMCA) as an Intermediate
Certificate Authority (CA). The first two steps performed are:
Replace the Root Certificate
Replace Machine Certificates (Intermediate CA)
Which two steps would need to be performed next? (Choose two.)
A.
Replace Solution User Certificates (Intermediate CA)
B.
Vmware 2V0-621D Exam
Pass Any Exam. Any Time. - www.actualtests.com 11
Replace the VMware Directory Service Certificate (Intermediate CA)
C.
Replace the VMware Directory Service Certificate
D.
Replace Solution User Certificates
Answer:
A,C
Explanation:
You can replace the VMCA root certificate with a third-party CA-signed certificate that includes
VMCAin the certificate chain. Going forward, all certificates that VMCA generates include the full
chain. You can replace existing certificates with newly generated certificates. This approach
combines the security of third-party CA-signed certificate with theconvenience of automated
certificate management.
Reference:http://pubs.vmware.com/vsphere-
60/index.jsp?topic=%2Fcom.vmware.vsphere.security.doc%2FGUID-5FE583A2-3737-4B62-
A905-5BB38D479AE0.html
Question NO: 14
Which three options are available for ESXi Certificate Replacement? (Choose three.) A. VMware Certificate Authority mode B. Custom CertificateAuthority mode C. Thumbprint mode D. Hybrid Deployment E. VMware Certificate Endpoint Authority Mode
Answer:
A,B,C
Explanation:
Vmware 2V0-621D Exam
Pass Any Exam. Any Time. - www.actualtests.com 12
You can perform different types of certificate replacement depending on company policy and
requirements for the system thatyou are configuring. You can perform each replacement with the
vSphere Certificate Manager utility or manually by using the CLIs included with your installation.
VMCA is included in each Platform Services Controller and in each embedded deployment. VMCA
provisions each node, each vCenter Server solution user, and each ESXi host with a certificate
that is signed by VMCA as the certificate authority. vCenter Server solution users are groups of
vCenter Server services. See vSphere Security for a list of solution users.
You can replace the default certificates. For vCenter Server components, you can use a set of
command-line tools included in your installation. You have several options.
Reference:http://pubs.vmware.com/vsphere-
60/index.jsp?topic=%2Fcom.vmware.vsphere.install.doc%2FGUID-4469A6D3-048A-471C-9CB4-
518A15EA2AC0.html
Question NO: 15
Lockdown Mode has been enabled on an ESXi 6.x host and users are restricted from logging into
the Direct Console User Interface (DCUI).
Which two statements are true given this configuration? (Choose two.)
A.
A user granted administrative privileges in the Exception Userlist can login.
B.
A user defined in the DCUI.Access without administrative privileges can login.
C.
A user defined in the ESXi Admins domain group can login.
D.
A user set to the vCenter Administrator role can login.
Answer:
A,B
Explanation:
Reference:https://pubs.vmware.com/vsphere-
60/index.jsp?topic=%2Fcom.vmware.vsphere.security.doc%2FGUID-F8F105F7-CF93-46DF-
9319-F8991839D265.html
Vmware 2V0-621D Exam
Pass Any Exam. Any Time. - www.actualtests.com 13
Question NO: 16
Strict Lockdown Mode has been enabled on an ESXi host.
Which action should an administrator perform to allow ESXi Shell or SSH access for users with
administrator privileges?
A.
Grant the users the administrator role and enable the service.
B.
Add the users to Exception Users and enable the service.
C.
No action can be taken, Strict Lockdown Mode prevents direct access.
D.
Add the users to vsphere.local and enable the service.
Answer:
B
Explanation:
Reference:https://pubs.vmware.com/vsphere-
60/index.jsp?topic=%2Fcom.vmware.vsphere.security.doc%2FGUID-F8F105F7-CF93-46DF-
9319-F8991839D265.html
Question NO: 17
An administrator wants to configure an ESXi 6.x host to use Active Directory (AD) to manage
users and groups. The AD domain group ESX Admins is planned for administrative access to the
host.
Which two conditions should be considered when planning this configuration? (Choose two.)
A.
If administrative access for ESX Admins is not required, this setting can be altered.
B.
The users in ESX Admins are not restricted by Lockdown Mode.
C.
Vmware 2V0-621D Exam
Pass Any Exam. Any Time. - www.actualtests.com 14
An ESXi host provisioned withAuto Deploy cannot store AD credentials.
D.
The users in ESX Admins are granted administrative privileges in vCenter Server.
Answer:
A,C
Explanation:
Question NO: 18
Which password meets ESXi 6.x host password requirements? A. 8kMVnn2x B. zNgtnJBA2 C. Nvgt34kn44 D.b74wr
Answer:
A
Explanation:
A valid password requires a mix of upper and lower case letters, digits, and other characters. You
can use a 7-character long password with characters from at leastthree of these four classes, or a
6-character long password containing characters from all the classes. A password that begins with
an upper case letter and ends with a numerical digit does not count towards the number of
character classes used. It is recommended that the password does not contain the username.
A passphrase requires at least 3 words, can be 8 to 40 characters long, and must contain enough
different characters.
Reference:http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=display
KC&externalId=1012033
Vmware 2V0-621D Exam
Pass Any Exam. Any Time. - www.actualtests.com 15
Question NO: 19
An administrator would like to use a passphrase for their ESXi 6.x hosts which has these
characteristics:
Minimum of 21 characters
Minimum of2 words
Which advanced options must be set to allow this passphrase configuration to be used?
A.
retry=3 min=disabled, disabled, 7, 21, 7 passphrase=2
B.
retry=3 min=disabled, disabled, 21, 7, 7 passphrase=2
C.
retry=3 min=disabled, disabled, 2, 21, 7
D.
retry=3 min=disabled, disabled, 21, 21, 2
Answer:
B
Explanation:
To force a specific password complexity and disable all others, replace the number with the word
with disabled. For example, to force passwords containing characters from all four-character
classes:
password requisite/lib/security/$ISA/pam_passwdqc.so retry=3 min=
disabled,disabled,disabled,disabled,7
Reference:http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=display
KC&externalId=1012033
Question NO: 20
Which Advanced Setting should be created for the vCenter Server to change the expiration policy of the vpxuser password? A. VimPasswordExpirationInDays Vmware 2V0-621D Exam Pass Any Exam. Any Time. - www.actualtests.com 16 B. VimExpirationPasswordDays C. VimPassExpirationInDays D. VimPasswordRefreshDays
Answer:
A
Explanation:
vCenter Server creates the vpxuser account on each ESX/ESXi host that it manages. The
password for each vpxuser accountis auto-generated when an ESX/ESXi host is added. The
password is updated by default every 30 days.
To modify default password settings:
Reference:http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=display
KC&externalId=1016736
Question NO: 21
An administrator has been instructed to secure existing virtual machines in vCenter Server.
Which two actions should the administrator take to secure these virtual machines? (Choose two.)
A.
Disable native remote management services
B.
Restrict Remote Console access
C.
Use Independent Non-Persistent virtual disks
D.
Prevent use of Independent Non-Persistent virtual disks
Answer:
B,D
Explanation:
Vmware 2V0-621D Exam
Pass Any Exam. Any Time. - www.actualtests.com 17
Reference:http://www.vmware.com/files/pdf/techpaper/VMW-TWP-vSPHR-SECRTY-HRDNGUSLET-
101-WEB-1.pdf(page 11, see the tables)
Question NO: 22
An administrator has recently audited the environment and found numerous virtual machines with sensitive data written to the configuration files. To prevent this in the future, which advanced parameter should be applied to the virtual machines? A. isolation.tools.setinfo.disable = true B. isolation.tools.setinfo.enable = true C. isolation.tools.setinfo.disable = false D. isolation.tools.setinfo.enable = false
Answer:
A
Explanation:
It is configured on a per-VM basis. You can increase the guest operating system variablememory
limit if large amounts of custom information are being stored in the configuration file. You can also
prevent guests from writing any name-value pairs to the configuration file. To do so, use the
following setting, and set it to ?true?:
Question NO: 23
Which two statements are correct regarding vSphere certificates? (Choose two.)
A.
ESXi host upgrades do not preserve the SSL certificate and reissue one from the VMware
Certificate Authority (VMCA).
B.
Vmware 2V0-621D Exam
Pass Any Exam. Any Time. - www.actualtests.com 18
ESXi host upgrades preserve the existing SSL certificate.
C.
ESXi hosts have assigned SSL certificates from the VMware Certificate Authority (VMCA) during
install.
D.
ESXi hosts have self-signed SSL certificates by default.
Answer:
B,C
Explanation:
Of course, ESXi host upgrades preserve existing SSLcertificate and it also have assigned SSL
certificates from VMCA during the installation process.
Question NO: 24
Which three options are available for replacing vCenter Server Security Certificates? (Choose
three.)
A.
Replace with Certificates signedby the VMware Certificate Authority.
B.
Make VMware Certificate Authority an Intermediate Certificate Authority.
C.
Do not use VMware Certificate Authority, provision your own Certificates.
D.
Use SSL Thumbprint mode.
E.
Replace all VMware Certificate Authority issued Certificates with self-signed Certificates.
Answer:
A,B,C
Explanation:
There are three options for replace vCenter server security certificates. You can replace it with
certificates signed by VMware certificate authority; you can make theVMCA an intermediate
certificate authority. Likewise, you can provision your own certificates.
Vmware 2V0-621D Exam
Pass Any Exam. Any Time. - www.actualtests.com 19