vRealize Automation ICM Flashcards

1
Q

What can vRA do?

A

It can automate the deployment of infrastructure components (such as vms, apps, and services)

It can also automate collaboration between multiple cloud providers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Why don’t you have to be a programmer to consumer vRA?

A

You don’t have to be a programmer because vRA automates the placement of software and objects in an environment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What business cases does vRA solve ?

A
  • ability to manage multiple cloud infrastructure from one interface
  • Achieve IaaS, SaaS, ZaaS
  • Decrease organization inefficiencies to app deployment
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the components of vRA?

A
  • Cloud Assembly
  • Service Broker
  • Code Stream
  • vRealize Orchestrator
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does cloud assembly do?

A
  • Setups basic cloud infra by pulling in cloud accounts from VMware on AWS, VMware Azure , etc
  • Infra as code templates are contained her and can be used by teams
  • Kubernetes integration support for native kubes, vSphere with Tanzu, and pivotal container service
  • marketplace access for ready-made templates for cloud templates
  • vm templates
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the function of service broker in vRA?

A
  • Gathers info from multiple sources into a single catalog for users
  • Where the self-service catalog is located
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the benefits of VMware Cloud services

A
  • 45 day free trial
  • no need to patch, upgrade, or monitor vRA
  • earlier access to new features
  • single view across multiple clouds and data centers
  • chat support available if an org has production support
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

vRealize Automation On Prem vs vRealize Automation Cloud

A

Who vRealize Automation on Prem is for:

  • existing vRealize Customer
  • org that needs a large big cloud management solution
  • a business that can’t use SaaS because of security and compliance reqs
  • Entities dependent on-prem tools such as service desk IPAM and physical load balancers

Who vRealize cloud is for:

  • orgs new to vRealize suite
  • small IT orgs
  • Orgs that have adopted SaaS strategy
  • Orgs that need fast provision and deployment of a cloud infrastructure
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the vRealize Cloud Universal Licensing Model

A
  • it is the hybrid bundling on prem and SaaS vRealize suite products
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the benefits of the vRealize Cloud Universal licensing model?

A
  • Since on prem and Saas vRealize Suite licenses can be bundled together, it removes the need for separate licenses to manage vRealize suite products
  • can monitor on prem and cloud products from one single pane via self service catalog
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How can vRa be deployed?

A

It cann be deployed as a standard deployment or a clustered infrastructure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a VRA standard deployment for?

A
  • Only meant for POC and testing

* has no HA feature(if appliance fails there is no failover mechanism to support high availability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the components of vRA standard deployment?

A
  • vRealize suite lifecycle management
  • VMware identity Manager
  • vRealize Appliance
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are all components in the standard vRA architecture deployment based on?

A

Photon OS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the order of installation for a vRA standard deployment architecture?

A
  1. vRealize Suite Lifecycle Manager suite is installed

2. vIDM and vRA appliance installed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a clustered vRA architecture deployment used for?

A
  • It is used for production environments and large enterprises
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Why is a clustered vRA deployment better than a standard vRA deployment?

A

*has high availability to provide infrastructure redundancy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What are the required components of a clustered vRA architecture deployment?

A

*load balancers to support vIDM instance and vRA instances
*lifecycle manager
*3 nodes for vIDM cluster
3 nodes for vRA cluster

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

How would you scale if you started with a vRA standard deployment and wanted to migrate to a vRA clustered department?

A

Go to vRSLCM options and scale out additional nodes, loadbalancers for vIDM and vRA clusters

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What are the steps to install vRA?

A
  1. Go to downloads.vmware.com
  2. download the easy installer iso
  3. mount the easy installer iso to a guest os
  4. run the easy installer executable
  5. follow easy installer prompts
  6. Once installation is complete there will be 3 vms (vRealize suite Lifecycle manger, vIDM, and vRA > can scale vIDM and vRA clusters to 3 nodes from this point
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Can vRA be a standalone appliance?

A

vRA cannot be a standalone appliance because all 3 components (vrslcm, vidm, and vra) must work together

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What does vRSLCM do?

A
  • automates the deployment of vIDM and vRA

* helps to patch and upgrade vREalize suite products passwords, user account management, certificate managemen

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What does vIDM do?

A

*provide authentication mechanism for vRealize suite products, vRA appliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

How does the vIDM authentication process work? (simplistic overview)

A
  1. someone logs into vRA console or vrealize suite product
  2. request is sent to vIDM
  3. vIDM authenticates user’s username and password against an AD or LDAP
  4. If the user’s account information and ad/ldap privileges match…then an SAML token is issued
  5. The SAML token is given to console/app that the user requested access to
  6. user now has access
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

What is the purpose of the vRA appliance (simplistic overview)?

A

The vRA appliance provides the services that are needed to support vRealize infrastructure and products

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

What is the vRealize Automation Appliance Powered By?

A

Photon OS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

What do all vRA services run as?

A

Kubernetes PODs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

How did vRA services run before 8.x?

A
  • SUSE based environment from port 5408
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

What commands have to be used in vRA?

A

kubectl

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

What does rabbitMQ do?

A

Exchanges information between pods and is also a pod

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

Can Microsoft SQL be used with a vRA appliance?

A

No, can only use Postgre SQL

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

What are the steps to run kubernetes on a vRA appliance?

A
  1. vRA powered on
  2. Docker is installed and kubernetes clusters are configured
  3. images are taken from private registry and deploy PODs
  4. vREalize Automation services are running as PODs
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

What is helm?

A

Where images are pulled (private registry) for containers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

what runs inside kubernetes PODs?

A

containters

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

What kind of containers are used in vRA?

A

Docker

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

What are the components of a postgres POD?

A
  • data is stored within as a file mount
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

How many containers can a POD have?

A

many

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

What is a file mount ?

A

persistent storage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

what is contained within the vco-app pod?

A

three containers : control center app, vco app (orchestrator services), vco-polygot-support (for multiple programming languages)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

What is a namespace?

A

allocation of resources to a user in order to allow them to run kubernetes services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

what happens with the “kubectl describe POD” command?

A

How running containers in a POD can be viewed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

what happens with the “kubectl get PID” command?

A

how you view running PODs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

What happens with the “kubectl get services ~ namespace” command?

A

provides networking for a POD

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

what does the ‘kubectl get deployments ~namespace’ command do?

A

decides the replica set and the services required to be running for a set of containers. If POds fail it ensures another with the same roles and services is brought back online

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q

What are the steps to use the vRealize Automation Easy Installer?

A
  1. Download the vRealize Easy Installer ISO
  2. Mount the ISO and run the executable
  3. vRLCM is deployed and configured
  4. vRLSCM installs vIDM
  5. vRLSCM install vRealize automation
  6. vRealize automation is configured and running
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
46
Q

Do vRLSCM, vIDM, and vRA share the same datastore?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
47
Q

FIPS compliance can be placed on

A

vRSLCM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
48
Q

The installation of vIDM with the vRA easy installer can be __

A

skipped and later, manually setup

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
49
Q

An existing instance of vIDM can be ____

A

Imported with the easy installer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
50
Q

What is the default size for vIDM?

A

medium, 8 vCPUs 16gb RAM 60 GB of storage

51
Q

What is the size of a large vIDM?

A

12 cpu 24 GB of RAM

52
Q

How can all members of an AD added to vIDM be synchronized?

A

check the “sync group members to the directiory when adding group: setting when at the vIDm step in the easy installer

53
Q

What are the default sizes for the vRA appliance?

A

medium, extra large,

54
Q

What is the automatic default size of vRA?

A

medium; 12 cpus, 40 gb ram

55
Q

what happns after vrslcm is installed?

A

vidm and vra binaries are moved to deploy vIDM and vRA (vidm.ova and vra.ova)

56
Q

if a vRA installation fails, where should you go?

A
  • “installer log location C:"

* Go to lifecycle manager ui/fqdn and sign in with default credentials used during installation of vrslcm

57
Q

What can vRA quickstart be used for?

A

to quickly setup the vRA appliance

58
Q

What will vRA quickstart allow you to do ?

A

allows you to pull in vCenter instances , NSX

59
Q

What is vRA quickstart best for?

A

A quick proof of concept

60
Q

What is the minimum resource requirement for vRSLCM?

A

2 vCPU, 6 GB, 78 gb

61
Q

What is the minimum system resource requirement for vIDM

A

8 vCPU 16 GB 60 GB

62
Q

What is the minimum resource requirement for the vRA appliance?

A

12 vCPU 42 GB 236 GB

63
Q

What are the two configuration options for vRealize easy installer configurations

A
  • common configs
  • appliance-specific configs
    *
64
Q

What configuration options are avaiable at the vRealize Easy Installer screen?

A
  • Target vCenter Server System
  • Target data center or VM folder
  • Target compute resources
  • Target datastore
  • Common network settings
  • Common password
65
Q

At the vRealize suite Lifecycle Manager Configuration setup page what options are present?

A
  • data center name
  • vCenter name
  • disk size
  • FIPS complianception
  • Virtual Machine settings
  • Ip address settings for appliance
  • host name for appliance
66
Q

At the identity manager configuration page, what options are available?

A
  • vRA environment name
  • license key
    -FIPs compliance settings
  • node size
  • vm name
  • ip address
    hostname
    -internal pods and services configuration customization option for k6s cluster IP range
  • option to skip vRA installation
    -option to do standard or clustered deployment
    option to select custom certificates and load balancers if clustered deployment is chosen
67
Q

What is the difference between authentication and authorization

A

Authentication confirms identitym verifies ab object or person is who they say they are, requires login credentials while authorization determines what an objecct or person has access to, grants permissions to resources, requires user roles

68
Q

How does identity manager work?

A
  1. identity service send a request to vidm via url
  2. the vIDM appliance validates the user’s credentials against an org ad
  3. If user credentials match their authorization in AD, then user gains access to vRA console
69
Q

How does vIDM run?

A

As a kubernetes POD

70
Q

What makes the vIDM kubernetes pod different from other POD services (in respect to architecture)?

A
  • it runs vIDM services

- it has a FQDN and pull number required for communication with vRA

71
Q

What is the database for vIDM?

A

Identity-db

72
Q

What does vidm’s identity-db do?

A

It is a database that keeps a user’s login request (after they attempt to login into the vRA appliance) so that vIDM can query the user’s credentials against a connected AD/LDAP to gauge access

73
Q

What does vIDM manage?

A
  • user authentication
  • access policies
  • user resource entitlements
74
Q

How do you login to vIDM?

A

via the default configuration admin user credentials specified during the installation of vIDM

75
Q

What three directory types are supported by vIDM?

A
  • active directory over LDAP
  • active directory integrated windows
  • Openlad directory
76
Q

How do you see the current directories connected to vIDM?

A

go to vIDM’s FQDN > select identity and access management > select directories

77
Q

What is the integrated windows authentication designed for?

A
  • active directories with a forest architecture
78
Q

You integrate a new directory to vIDM by going to:

A

FQDN of vIDM > identity access and management > directories > add directory > put directory name > select authentication options > select directory search attribute > input bind user details

79
Q

what is a domain another name for in relation to vIDM?

A

forest

80
Q

LDAP = _ FOREST, intergrated windows = _ forest

A

1, multi

81
Q

What is the mechanism that connects a vIDM directory to an org’s active directory

A

a connector (sync connector)

82
Q

what are the features of vIDM?

A
  • access policies
  • support for multiple user authentication methods
  • two factor authentication can also incorporate mobile SSO or VMware verify
  • password recovery assistant
  • just in time user provision
83
Q

what does it mean to map attributes in vIDM?

A

it means you select the attributes that are synchronized between an org’s AD and vIDM

84
Q

Are all attributes between an AD and vIDM required to be mapped?

A

No, some attributes are required and some are optional

85
Q

Can required attributes be changed?

A

Yes

86
Q

What are the attributes that can be mapped between an AD and vIDM?

A
  • lastName
  • firstName
  • email
  • userName
  • phone
  • disabled
87
Q

What attributes are required to be defined between an AD and vIDM?

A
  • lastname
  • firstname
  • email
  • username
88
Q

How do you synchronize AD groups to vIDM?

A

after vIDM mapping page > specify the group under “specify the group DNs”

89
Q

What members of an AD group group will be synchronized with vIDM?

A

members of the group that are OU

90
Q

When you click “sync nested group members” on the “select the groups you want to sync page”, what happens?

A

all nested members of a selected group are synchronized (regardless if they are OU or not )

91
Q

What does do access policies mean in relation to vIDM?

A

conditional access for users by a set criteria. Ex. only allow logins from this user when they are on a specific network address

92
Q

What is the password recovery assistant feature in vRA?

A

Can configure a “forgot password” prompt so that users can set a new password when they forget their current one

93
Q

What tabs will a default config admin for vRA have access to in the vRA console ?

A
  • services
  • identity and access management
  • branding
94
Q

By default, How many vRealize orgs can correlate with one vRA environment?

A

1

95
Q

How can you edit the organization associated with a vRA environment?

A

By going to the vRA console > right clicking the org > view organizations > click “edit”

96
Q

How do you change the banner design shown in the vRA Automation cloud service console?

A

go to branding > header

97
Q

What are roles in vRA categorized as?

A

organization roles or service roles

98
Q

What is the simplified process to install vRA

A
  1. Download the vRealize Easy Installer ISO
  2. Mount the ISO and run the executable
  3. vRSLCM is deployed and configured
  4. vRSLCM installs vIDM
  5. vRSLCM installs vRealize Automation
  6. vRealize Automation is configured and deployed
99
Q

Are all vRA appliances placed on the same datastore?

A

Yes

100
Q

What is the default node size for a (medium) vIDM deployment?

A
  • 8 vCPUs
  • 16GB RAM
  • 60 GB of storage
101
Q

What is the node size for a large vIDM appliance?

A
  • 12 vCPU

* 24 gb of RAM

102
Q

What happens when you add an Active directory into vIDM by checking “sync group members to the directory when adding group” during vIDM deployment ?

A

All members of the AD are synchronized to vIDM

103
Q

What is the default size for the vRA appliance?

A

Medium,

  • 12 vCPUs
  • 40 gb Ram
104
Q

Where fo you go first if vRSLCM fails to install?

A
  • “installer log location C:"

* click lifecycle manager’s UI link > enter “admin” & “password” > lifecycle operations > requests

105
Q

What is another name for vIDM in vRSLCM?

A

globalenvironment

106
Q

What happens if an vRSLCM installation fails and a vRA appliance currently exists?

A
  • The easy installer can not be restarted

* Troubleshooting must start with vRSLCM log review

107
Q

Can a basic cloud template be created with vRA quickstart?

A

Yes

108
Q

What settings are included in configuration options for vRSLCM?

A
  • data center name
  • vCenter name
  • disk size
  • FIPs compliance
  • virtual machine
  • IP address
  • hostname
109
Q

What settings are included in the configuration options for vIDM?

A
  • option to skip vIDM installation
  • option to import vIDM installation
  • option to create a new installation of vIDM
  • VM names
  • IP addresses
  • hostname
  • default configuration admin
  • default configuration email
  • node size
  • “sync groups to the directory when adding group” setting
110
Q

What settings are included in the configuration options for vRealize Automation?

A
  • vRA environment name
  • license key
  • FIPS Compliance settings
  • Node size
  • VM name
  • IP address
  • hostname
  • internal pods and services customization for k8s cluster IP range settings
  • option to skip vRA installation
  • option to perform clustered or single node deployment
  • option to add custom certificates and load balancers needed to support clustered deployment
111
Q

How do you monitor the progress of vRSLCM setup for vRSLCM, vIDM, and vRA appliances?

A

via vRSLCM > Requests

112
Q

What will vRSLCM do after its initial creation?

A

It will create the global environment (vIDM) and vRA environment

113
Q

Why is vIDM also called the global environment?

A

Because only vIDM can authenticate across vRealize suite products

114
Q

How would you initiate vRA quickstart if it is not initially used in the deployment of vRSLCM?

A

You would go to the FQDN/IP of the vRealize appliance

115
Q

What can vRA Quickstart be used for?

A
  • set up an on-prem SDDC
  • Populate the self service catalog
  • deploy 1st cloud template
116
Q

Authentication vs Authorization

A

Authentication confirms who you are, what you have access to via credentials while authorization determines what you have access to, grants permissions to network resources, and requires the associate of roles to credentials/identity

117
Q

How does vIDM run?

A

As a kubernetes service pod

118
Q

What happens when a user logs into vRA?

A
  1. the identity service send the user’s request to vDIM (url)
  2. The vIDM appliance takes the user’s associated credentials from the request and compares it against an org’s active directory
  3. If the user’s credentials are found in the active directory, the vIDM hands over a key to the vRA console
  4. The key is accepted by vRA and the user can access the vRA console
119
Q

what is the identity-app pod?

A
  • It is a kubernetes POD on the vIDM appliance that runs vIDM services.
  • It stores the FQDN and pull number vRA needs to communicate to vIDM
  • It redirects login requests to vRealize suite services to vIDM
120
Q

What is the identity-db pod?

A
  • It is a kubernetes pod that runs on the vIDM appliance
  • It stores a database for vIDM that is used to store a user’s login request so that vIDM can validate the users identity in an associated active directory
121
Q

What account is used to log into vIDM?

A

the default configuration admin that was configured during the deployment of vIDM

122
Q

What does vIDM use to validate and manage user access?

A
  • user authentication
  • access policies
  • user entitlements
123
Q

How do you configure or review active directories connected to vIDM?

A

go to vIDM UI > select “active directory”