ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 19 - 2V0-21.23 discussion

Report
Export

An administrator is tasked with configuring an appropriate Single Sign-On (SSO) solution for VMware vCenter based on the following criteria:

• The solution should support the creation of Enhanced Link Mode groups.

• All user accounts are stored within a single Active Directory domain and the solution must support only this Active Directory domain as the identity source.

• All user account password and account lockout policies must be managed within the Active

Directory domain.

• The solution should support token-based authentication.

Which SSO solution should the administrator choose based on the criteria?

A.
vCenter Identity Provider Federation with Active Directory Federation Services as the identity provider
Answers
A.
vCenter Identity Provider Federation with Active Directory Federation Services as the identity provider
B.
vCenter Single Sign-On with Active Directory over LDAP as the identity source
Answers
B.
vCenter Single Sign-On with Active Directory over LDAP as the identity source
C.
vCenter Single Sign-On with Active Directory (Windows Integrated Authentication) as the identity source
Answers
C.
vCenter Single Sign-On with Active Directory (Windows Integrated Authentication) as the identity source
D.
vCenter Identity Provider Federation with Active Directory over LDAP as the identity provider
Answers
D.
vCenter Identity Provider Federation with Active Directory over LDAP as the identity provider
Suggested answer: A

Explanation:

Option C is correct because it indicates that vCenter Single Sign-On with Active Directory (Windows Integrated Authentication) as the identity source is the best SSO solution for VMware vCenter based on the criteria, as this solution supports Enhanced Link Mode groups, supports only one Active Directory domain as the identity source, delegates password and account lockout policies to Active Directory, and supports token-based authentication. Option A is incorrect because vCenter Identity Provider Federation with Active Directory Federation Services as the identity provider is not necessary for a single Active Directory domain scenario and may introduce additional complexity and overhead. Option B is incorrect because vCenter Single Sign-On with Active Directory over LDAP as the identity source does not support token-based authentication and may require additional configuration for password and account lockout policies. Option D is incorrect because vCenter Identity Provider Federation with Active Directory over LDAP as the identity provider does not support token-based authentication and may introduce additional complexity and overhead.

Reference: https://docs.vmware.com/en/VMwarevSphere/ 7.0/com.vmware.vcenter.install.doc/GUID-A2A4371A-B888-404C-B23F-C422A8C40F54.html

asked 16/09/2024
ABDUL AZEEZ
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first