Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

VMware 2V0-13.25 Exam - Topic 2 Question 21 Discussion

During the design workshop, the customer stated the following requirement:* The solution will support secure communication.Which design decision should be included in the logical design for the workload domain?
A) Use a SHA-2 algorithm or higher for signed certificates.
B) Set promiscuous mode port group security policy to reject.
C) Verify all physical components used for the deployments are on the hardware compatibility list.
D) Ensure the host servers have TPM 2.0 hardware.

VMware 2V0-13.25 Exam - Topic 2 Question 21 Discussion

Actual exam question for VMware's 2V0-13.25 exam
Question #: 21
Topic #: 2
[All 2V0-13.25 Questions]

During the design workshop, the customer stated the following requirement:

* The solution will support secure communication.

Which design decision should be included in the logical design for the workload domain?

Show Suggested Answer Hide Answer
Suggested Answer: A

Comprehensive and Detailed Explanation from VMware Cloud Foundation 9.0 Documentation:

According to VMware Cloud Foundation 9.0 Design Guide (Table 59, ''Certificate Management Design Recommendations''), VMware explicitly mandates that ''Use a SHA-2 algorithm or higher for signed certificates. The SHA-1 algorithm is considered less secure and has been deprecated.'' This recommendation (VCF-SEC-RCMD-CERT-002) is a foundational part of securing communication between management components and workload domains across the VCF environment.

The use of SHA-2 or higher ensures that all certificates used for SSL/TLS communication within the SDDC ecosystem (including vCenter, NSX Manager, and SDDC Manager) meet modern cryptographic standards to prevent vulnerabilities such as collision attacks. VMware Cloud Foundation enforces certificate management policies that require replacement of default VMCA-signed certificates with CA-signed certificates, and the SHA-2 algorithm ensures cryptographic integrity, authenticity, and resistance to tampering or impersonation.

This configuration directly satisfies the customer's requirement for secure communication in the logical design of the workload domain. It ensures data in transit between components---such as management clusters, workload domains, and external systems---remains encrypted and trustworthy, aligning with VMware's zero-trust and compliance-focused architectural principles.

Reference (VMware Cloud Foundation 9.0.1 Architecture Guide):

Table 59: Certificate Management Design Recommendations --- ''VCF-SEC-RCMD-CERT-002 Use a SHA-2 algorithm or higher for signed certificates.''

VMware Cloud Foundation 9.0.1 PDF, pp. 306--308, 376, and 592 (Certificate Management Design Recommendations Sections).

VMware Cloud Foundation Security Governance and Compliance Design Section (VCF-SEC-RCMD-CERT-002).


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel