[Lead2pass New] Free Lead2pass VMware 2V0-621D VCE And PDF Instant Download (21-30)
If you are worried about your 2V0-621D exam and you are not prepared so, now you don't need to take any stress about it. Get most updated 2V0-621D braindumps with 100% accurate answers. Lead2pass.com is considered one of the best website where you can save extra money by getting 150-days of free updates after buying the 2V0-621D dumps practice exam. Following questions and answers are all new published by VMware Official Exam Center: https://www.lead2pass.com/2v0-621d.html QUESTION 21 To reduce the attack vectors for a virtual machine, which two settings should an administrator set to false? (Choose two.) A. ideX:Y.present B. serial.present C. ideX:Y.enabled D. serial.enabled Answer: AB Reference: http://jackiechen.org/2012/10/05/vsphere-5-0-security-hardening-recommended-vm-settings-configure-script/ QUESTION 22 Which two groups of settings should be reviewed when attempting to increase the security of virtual machines (VMs)? (Choose two.) A. Disable hardware devices B. Disable unexposed features C. Disable VMtools devices D. Disable VM Template features Answer: AB Explanation: Make sure you review hardware devices and disable the unnecessary ones. Also disable unexposed features before increasing virtual machines security. QUESTION 23 Which password meets ESXi 6.x host password requirements? A. 8kMVnn2x! B. zNgtnJBA2 C. Nvgt34kn44 D. !b74wr Answer: A Explanation: A valid password requires a mix of upper and lower case letters, digits, and other characters. You can use a 7-character long password with characters from at least three of these four classes, or a 6-character long password containing characters from all the classes. A password that begins with an upper case letter and ends with a numerical digit does not count towards the number of character classes used. It is recommended that the password does not contain the username. A passphrase requires at least 3 words, can be 8 to 40 characters long, and must contain enough different characters. Reference: http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=1012033 QUESTION 24 An administrator would like to use a passphrase for their ESXi 6.x hosts which has these characteristics: - Minimum of 21 characters - Minimum of 2 words Which advanced options must be set to allow this passphrase configuration to be used? A. retry=3 min=disabled, disabled, 7, 21, 7 passphrase=2 B. retry=3 min=disabled, disabled, 21, 7, 7 passphrase=2 C. retry=3 min=disabled, disabled, 2, 21, 7 D. retry=3 min=disabled, disabled, 21, 21, 2 Answer: B Explanation: To force a specific password complexity and disable all others, replace the number with the word with disabled. For example, to force passwords containing characters from all four-character classes: password requisite /lib/security/$ISA/pam_passwdqc.so retry=3 min= disabled,disabled,disabled,disabled,7 Reference: http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=1012033 QUESTION 25 Which Advanced Setting should be created for the vCenter Server to change the expiration policy of the vpxuser password? A. VimPasswordExpirationInDays B. VimExpirationPasswordDays C. VimPassExpirationInDays D. VimPasswordRefreshDays Answer: A Explanation: vCenter Server creates the vpxuser account on each ESX/ESXi host that it manages. The password for each vpxuser account is auto-generated when an ESX/ESXi host is added. The password is updated by default every 30 days. To modify default password settings: Connect vSphere Client to vCenter Server. Click Administration > vCenter Server Settings > Advanced Settings. Scroll to the parameter VirtualCenter.VimPasswordExpirationInDays and change the value from the default. Reference: http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=1016736 QUESTION 26 An administrator has been instructed to secure existing virtual machines in vCenter Server. Which two actions should the administrator take to secure these virtual machines? (Choose two.) A. Disable native remote management services B. Restrict Remote Console access C. Use Independent Non-Persistent virtual disks D. Prevent use of Independent Non-Persistent virtual disks Answer: BD Reference: http://www.vmware.com/files/pdf/techpaper/VMW-TWP-vSPHR-SECRTY-HRDNG-USLET-101-WEB-1.pdf (page 11, see the tables) QUESTION 27 An administrator has recently audited the environment and found numerous virtual machines with sensitive data written to the configuration files. To prevent this in the future, which advanced parameter should be applied to the virtual machines? A. isolation.tools.setinfo.disable = true B. isolation.tools.setinfo.enable = true C. isolation.tools.setinfo.disable = false D. isolation.tools.setinfo.enable = false Answer: A Explanation: It is configured on a per-VM basis. You can increase the guest operating system variable memory limit if large amounts of custom information are being stored in the configuration file. You can also prevent guests from writing any name-value pairs to the configuration file. To do so, use the following setting, and set it to 'true'. QUESTION 28 Which two statements are correct regarding vSphere certificates? (Choose two.) A. ESXi host upgrades do not preserve the SSL certificate and reissue one from the VMware Certificate Authority (VMCA). B. ESXi host upgrades preserve the existing SSL certificate. C. ESXi hosts have assigned SSL certificates from the VMware Certificate Authority (VMCA) during install. D. ESXi hosts have self-signed SSL certificates by default. Answer: BC Explanation: Of course, ESXi host upgrades preserve existing SSL certificate and it also have assigned SSL certificates from VMCA during the installation process. QUESTION 29 Which three options are available for replacing vCenter Server Security Certificates? (Choose three.) A. Replace with Certificates signed by the VMware Certificate Authority. B. Make VMware Certificate Authority an Intermediate Certificate Authority. C. Do not use VMware Certificate Authority, provision your own Certificates. D. Use SSL Thumbprint mode. E. Replace all VMware Certificate Authority issued Certificates with self-signed Certificates. Answer: ABC Explanation: There are three options for replace vCenter server security certificates. You can replace it with certificates signed by VMware certificate authority; you can make the VMCA an intermediate certificate authority. Likewise, you can provision your own certificates. QUESTION 30 When attempting to log in with the vSphere Web Client, users have reported the error: Incorrect Username/Password The administrator has configured the Platform Services Controller Identity Source as: - Type. Active Directory as an LDAP Server - Domain: vmware.com - Alias: VMWARE - Default Domain: Yes Which two statements would explain why users cannot login to the vSphere Web Client? (Choose two.) A. Users are typing the password incorrectly. B. Users are in a forest that has 1-way trust. C. Users are in a forest that has 2-way trust. D. Users are logging into vCenter Server with incorrect permissions. Answer: AB Explanation: The possible explanation for this error might be that the users are typing password incorrectly or they are in a forest with has only 1-way trust. You need 2-way trust to get the credentials accepted. More free Lead2pass 2V0-621D exam new questions on Google Drive: https://drive.google.com/open?id=0B3Syig5i8gpDa2xCVTdHZXoxYjA With the complete collection of 2V0-621D exam questions and answers, Lead2pass has assembled to take you through 2V0-621D dumps Questions and Answers for your Exam preparation. In this 2V0-621D exam we have compiled real exam questions with their answers so that you can prepare and pass exam in your first attempt. 2017 VMware 2V0-621D (All 256 Q&As) exam dumps (PDF&VCE) from Lead2pass: https://www.lead2pass.com/2v0-621d.html [100% Exam Pass Guaranteed]
|