A + D (a Replication Appliance is not a required element whereas a PSC is ALWAYS required, and question does not ask about replication but states "single cluster" )
vCenter and PSC. You shouldn’t encrypt them using VM Encryption because they would then need to boot up to get their encryption key to boot up.
https://blogs.vmware.com/vsphere/2017/10/key-manager-concepts-toplogy-basics-vm-vsan-encryption.html
Answer is B,D
Encryption of vSphere replication is not supported: https://docs.vmware.com/en/VMware-vSphere/6.7/vsphere-esxi-vcenter-server-671-security-guide.pdf?hWord=N4IghgNiBcIKYDsDGAnAngBwC4AIBuAyhgBZwpw4BKcGEAlkmFnQPYI4CCGtdYycIAL5A
And as per best practices vCSA shouldn't be encrypted.
Answer BD is correct. VMware Best Practices, don't encrypt vCenter Server Appliances.
https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.security.doc/GUID-B3DA9865-A28F-4EFD-ACF4-CBC8813ED110.html
He obviously spent $250 just to answer this one question and check for us, what a good guy (100% KIDDING!)
It's probably A & B but he cannot actually prove it. Read McLinux' reply; a PSC is always required.
B and D are correct because provided link states not any vCenter Server Appliance VM should be encrypted.
https://docs.vmware.com/en/VMware-vSphere/6.7/com.vmware.vsphere.security.doc/GUID-B3DA9865-A28F-4EFD-ACF4-CBC8813ED110.html
B and D
"Do not encrypt any vCenter Server Appliance virtual machines"
https://docs.vmware.com/en/VMware-vSphere/6.7/com.vmware.vsphere.security.doc/GUID-B3DA9865-A28F-4EFD-ACF4-CBC8813ED110.html
Replication will not work with encryption
https://docs.vmware.com/en/VMware-vSphere/6.5/com.vmware.vsphere.security.doc/GUID-C0AF1F3A-67B4-41A6-A933-7E52A3603D9D.html
A and D, cause "Platform Services Controller and vCenter Server virtual machines should not be encrypted".
https://nolabnoparty.com/en/vsphere-vms-encryption-encrypt-virtual-machines-pt-3/
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
McLinux
Highly Voted 5 years, 6 months agodannyray
5 years, 5 months agoMR_J
5 years, 4 months agostysonchanvilla
Highly Voted 5 years, 5 months agoaldanetcloud
Most Recent 4 years, 7 months agovkum
4 years, 8 months agotgortva
4 years, 11 months agoChar250
4 years, 8 months agohsezer
5 years agosupport87
5 years agoEwoke
5 years, 1 month agoRenehurtado2020
5 years, 4 months agometapedro
5 years, 4 months agopedromi
5 years, 4 months agoreeeba
5 years agoamine2020
4 years, 6 months agoALF4
5 years, 6 months agowalee
4 years, 11 months agoMike666
5 years, 6 months agoCarbonfiber01
5 years, 7 months agoacryz
5 years, 7 months agoRagesh
5 years, 9 months agoAlexD
5 years, 10 months ago