Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

VMware 3V0-21.23 Exam - Topic 1 Question 21 Discussion

An architect is reviewing the security and compliance requirements for a new application that will be hosted on a vSphere 8 environment.The following information has been noted about the new application:The application stores and processes confidential dataThe supporting virtual infrastructure is shared with other departmentsNo other application stores or processes confidential dataThe application virtual machines must be able to run on any ESXi host in the clusterThe storage layer is a iSCSI attached SANData at Rest Encryption is in place for each presented LUN validated to FIPS 140-2No budget is available for additional infrastructure components or softwareApplication data must not be accessible outside of the application's virtual machinesThe architect has been tasked with providing a secure virtual machine design to host the application.Which three design elements must the architect include to meet the requirements? (Choose three.)
A) Virtual Machine Encryption and B) The vSphere Native Key Provider and D) External Key Management Service (KMS) provider
C) A new encrypted iSCSI LUN
E) A new local VMFS volume
F) VMware vSAN

VMware 3V0-21.23 Exam - Topic 1 Question 21 Discussion

Actual exam question for VMware's 3V0-21.23 exam
Question #: 21
Topic #: 1
[All 3V0-21.23 Questions]

An architect is reviewing the security and compliance requirements for a new application that will be hosted on a vSphere 8 environment.

The following information has been noted about the new application:

The application stores and processes confidential data

The supporting virtual infrastructure is shared with other departments

No other application stores or processes confidential data

The application virtual machines must be able to run on any ESXi host in the cluster

The storage layer is a iSCSI attached SAN

Data at Rest Encryption is in place for each presented LUN validated to FIPS 140-2

No budget is available for additional infrastructure components or software

Application data must not be accessible outside of the application's virtual machines

The architect has been tasked with providing a secure virtual machine design to host the application.

Which three design elements must the architect include to meet the requirements? (Choose three.)

Show Suggested Answer Hide Answer
Suggested Answer: A, B, D

Virtual Machine Encryption

To ensure that the application's confidential data is protected, Virtual Machine Encryption should be applied. This will ensure that even if someone gains access to the storage layer or the underlying infrastructure, the data in the virtual machine is encrypted and cannot be accessed outside of the VM, as required by the security and compliance requirements.

The vSphere Native Key Provider

The vSphere Native Key Provider can be used to manage encryption keys within the vSphere environment. Since no budget is available for additional infrastructure components or software, leveraging vSphere's native capabilities for key management ensures that encryption is securely handled without introducing external dependencies. This also aligns with the requirement to not introduce additional infrastructure.

External Key Management Service (KMS) provider

While the vSphere Native Key Provider can manage keys within the environment, if there is a requirement for a more secure or compliant key management solution, an External Key Management Service (KMS) may be used. The KMS provider allows for centralized management of encryption keys, ensuring that the keys are securely stored and controlled according to compliance standards (e.g., FIPS 140-2). Although the Native Key Provider may suffice, this option ensures that key management adheres to stricter compliance needs, especially for confidential data.


Contribute your Thoughts:

0/2000 characters
Luther
4 days ago
C seems unnecessary since we have iSCSI already.
upvoted 0 times
...
Delisa
9 days ago
B is also important for key management.
upvoted 0 times
...
Lura
14 days ago
Agreed! A is essential for VM security.
upvoted 0 times
...
Paulina
19 days ago
I think A, B, and D are key. Encryption is a must.
upvoted 0 times
...
Elvera
25 days ago
This question is tough! Security is critical.
upvoted 0 times
...
Loreta
30 days ago
Definitely A and B, but I’d skip D due to budget limits.
upvoted 0 times
...
Marya
1 month ago
I feel like A and B are essential for VM security.
upvoted 0 times
...
Vincenza
1 month ago
C isn’t necessary since iSCSI is already encrypted.
upvoted 0 times
...
Angella
2 months ago
I agree, but what about C? We need secure storage too.
upvoted 0 times
...
Luther
2 months ago
I think A, B, and D are key. Encryption is a must.
upvoted 0 times
...
Kerry
2 months ago
This question is tough! Security is critical.
upvoted 0 times
...
Shantay
2 months ago
Agree, VM Encryption is essential, but what about the KMS?
upvoted 0 times
...
Sommer
2 months ago
Wait, can we really trust the current setup without extra budget?
upvoted 0 times
...
Felicidad
2 months ago
A new encrypted iSCSI LUN seems unnecessary since FIPS is already validated.
upvoted 0 times
...
Nadine
4 months ago
I think the vSphere Native Key Provider is a must too!
upvoted 0 times
...
Elbert
4 months ago
Definitely need Virtual Machine Encryption for security.
upvoted 0 times
...
Noah
5 months ago
I’m uncertain about the need for a new local VMFS volume; it seems unnecessary since we already have an iSCSI SAN in place.
upvoted 0 times
...
Dorothy
5 months ago
This question reminds me of a practice exam where we had to secure shared resources. I feel like VM encryption is definitely a must-have here.
upvoted 0 times
...
Ahmed
5 months ago
I think we might need the vSphere Native Key Provider for managing encryption keys, but I’m a bit confused about whether we need an external KMS as well.
upvoted 0 times
...
Tyisha
5 months ago
I remember studying about VM encryption, but I'm not sure if we need a new encrypted iSCSI LUN since the existing one is already validated to FIPS.
upvoted 0 times
...

Save Cancel