An organization's security policy requires a design where the ESXi hosts will be manageable only through vCenter Server. Which two security configurations will help meet this requirement? (Choose two.)
Correct Answer:
AD
In the Lockdown mode strict mode the DCUI service is disabled, while in normal lockdown mode users of the DCUI.Access exception list can enter. Now, if the Shell is disabled, not even users in the exception list will be able to access this service.
https://docs.vmware.com/en/VMware-vSphere/6.5/com.vmware.vsphere.security.doc/GUID-F8F105F7-CF93-46DF-9319-F8991839D265.html#GUID-F8F105F7-CF93-46DF-9319-F8991839D265
I think A C
When the host is running, available services depend on whether lockdown mode is enabled, and on the type of lockdown mode.
In strict and normal lockdown mode, privileged users can access the host through vCenter Server, either from the vSphere Web Client or by using the vSphere Web Services SDK.
Direct Console Interface behavior differs for strict lockdown mode and normal lockdown mode.
In strict lockdown mode, the Direct Console User Interface (DCUI) service is disabled.
In normal lockdown mode, accounts on the Exception User list can access the DCUI if they have administrator privileges. In addition, all users who are specified in the DCUI.Access advanced system setting can access the DCUI.
If the ESXi Shell or SSH is enabled and the host is placed in lockdown mode, accounts on the Exception Users list who have administrator privileges can use these services. For all other users, ESXi Shell or SSH access is disabled. Starting with vSphere 6.0, ESXi or SSH sessions for users who do not have administrator privileges are terminated.
This section is not available anymore. Please use the main Exam Page.3V0-624 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
diegof1
Highly Voted 5 years, 9 months agoMohamedFouad
Highly Voted 5 years, 7 months agochafik
Most Recent 4 years, 3 months agolotso
4 years, 10 months agooud
5 years, 3 months agocharithabuddhika
5 years, 9 months ago