Chapter 7: vSphere Security Flashcards

1
Q

What is the default approach to provisioning certificates in vSphere 7.0?

A

The VMware Certificate Authority (VMCA).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Describe the function of the VMware Endpoint Certificate Store (VECS).

A

To store custom certificates.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What term best describes the following?

“A service that serves as an identity source that handles SAML certificate management for authentication with vCenter SSO.”

A

The VMware Directory Service (vmdir).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Describe the function of the VMware Certificate Authority (VMCA).

A

To issue certificates for users and machines.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What core identity service must be used to store all vCenter certificates and keys?

A

The VMware Endpoint Certificate Store (VECS).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

In regards to certificate requirements, what is the supported range for key size?

A

2048 to 16384 bits.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What PEM formats are supported by VMware?

A

PKCS8 & PKCS1.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What version of x509 is required to support certificates in vSphere?

A

Version 3.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What format of the certificate file is required in vSphere?

A

CRT format.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What keys must be available for vSphere certificates?

A

Digital signature and encipherment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Are wildcard certificates supported by VMCA?

A

No.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly