Question No: 1 – (Topic 1)

What is the highest object level from which a virtual machine can inherit privileges?

  1. Host Folder

  2. Data Center

  3. Data Center Folder

  4. VM Folder

Answer: C Explanation:

Rahail HDD:Users:iMac:Desktop:Screen Shot 2015-06-09 at 3.20.28 PM.png Reference: http://www.vmware.com/pdf/vi3_vc_roles.pdf

Question No: 2 – (Topic 1)

An administrator is assigning a user the Content Library administrator role. The user will only be creating the library for a single vCenter Server.

What is the lowest level of the permission heirarchy that this role can be granted to the user and still allow them to create a Content Library?

  1. Global

  2. Datacenter Folder

  3. Virtual Center

  4. Datacenter

Answer: A Explanation:

To let a user manage a content library and its items, an Administrator can assign the Content Library Administrator role to that user as a global permission. The Content Library Administrator role is a sample role in the vSphere Web Client.

Users who are Administrators can also manage libraries and their contents. If a user is an Administrator at a vCenter Server level, they have sufficient privileges to manage the libraries that belong to this vCenter Server instance, but cannot see the libraries unless they have a Read-Only role as a global permission.

Reference: http://pubs.vmware.com/vsphere- 60/index.jsp?topic=/com.vmware.vsphere.vm_admin.doc/GUID-18F4B892-D685- 4473-AC25-3195D68DFD90.html

Question No: 3 – (Topic 1)

An administrator is able to manage an ESXi 6.x host connected to vCenter Server using the vSphere Web Client but is unable to connect to the host directly.

Which action should the administrator take to correct this behavior?

  1. Restart management agents on the ESXi host.

  2. Disable Lockdown Mode on the ESXi host through vCenter Server.

  3. Disable the ESXi firewall with the command esxcli network firewall unload.

  4. Reboot the ESXi host.

Answer: B Explanation:

Disable lockdown mode through the DCUI and then enable it through the vCenter Server instead. The vCenter Server does not keep track of lockdown mode state changes that initiated outside of the vCenter Server itself.

Reference: http://kb.vmware.com/selfservice/microsites/search.do?language=en_USamp;cmd=displayKC


Question No: 4 – (Topic 1)

Which password meets ESXi 6.x host password requirements?

  1. 8kMVnn2x!

  2. zNgtnJBA2

  3. Nvgt34kn44

  4. !b74wr

Answer: A Explanation:

A valid password requires a mix of upper and lower case letters, digits, and other characters. You can use a 7-character long password with characters from at least three of these four classes, or a 6-character long password containing characters from all the classes. A password that begins with an upper case letter and ends with a numerical digit does not count towards the number of character classes used. It is recommended that the password does not contain the username.

A passphrase requires at least 3 words, can be 8 to 40 characters long, and must contain enough different characters.

Reference: http://kb.vmware.com/selfservice/microsites/search.do?language=en_USamp;cmd=displayKC


Question No: 5 – (Topic 1)

An administrator is creating a new Content Library. It will subscribe to another remote Content Library without authentication enabled.

What information from the published library will they need in order to complete the subscription?

  1. Subscription URL

  2. A security password from the publishing Content Library

  3. Publisher#39;s Items.json file

  4. Username from the publishing Content Library

Answer: A Explanation:

Subscription URL from the published library is needed to complete the subscription.

Question No: 6 – (Topic 1)

Which three components should an administrator select when configuring vSphere permissions? (Choose three.)

  1. Inventory Object

  2. Role

  3. User/Group

  4. Privilege

  5. Password

Answer: A,B,C Explanation:

In vSphere, permission consists of a user or group and an assigned role for an inventory object, such as a virtual machine or ESX/ESXi host. Permissions grant users the right to perform the activities specified by the role on the object to which the role is assigned.

Reference: http://pubs.vmware.com/vsphere-4-esx- vcenter/index.jsp?topic=/com.vmware.vsphere.dcadmin.doc_41/vsp_dc_admin_guide/man aging_users_groups_roles_and_permissions/c_permissions.html

Question No: 7 – (Topic 1)

An administrator would like to use the VMware Certificate Authority (VMCA) as an Intermediate Certificate Authority (CA). The first two steps performed are:

->Replace the Root Certificate

->Replace Machine Certificates (Intermediate CA)

Which two steps would need to be performed next? (Choose two.)

  1. Replace Solution User Certificates (Intermediate CA)

  2. Replace the VMware Directory Service Certificate (Intermediate CA)

  3. Replace the VMware Directory Service Certificate

  4. Replace Solution User Certificates

Answer: A,C Explanation:

You can replace the VMCA root certificate with a third-party CA-signed certificate that includes VMCA in the certificate chain. Going forward, all certificates that VMCA generates include the full chain. You can replace existing certificates with newly generated certificates. This approach combines the security of third-party CA-signed certificate with the convenience of automated certificate management.

Reference: http://pubs.vmware.com/vsphere- 60/index.jsp?topic=/com.vmware.vsphere.security.doc/GUID-5FE583A2-3737- 4B62-A905-5BB38D479AE0.html

Question No: 8 – (Topic 1)

An administrator creates a custom ESXi firewall rule using an XML file, however the rules do not appear in the vSphere Web Client.

Which action should the administrator take to correct the problem?

  1. Load the new rules using esxcli network firewall reload.

  2. Load the new rules using esxcli network firewall refresh.

  3. Verify the entries in the XML file and then reboot the ESXi host.

  4. Remove the ESXi host from the inventory and add it back.

Answer: B Explanation:

Refresh the firewall configuration by reading the rule set files if the firewall module is loaded.

Reference: https://pubs.vmware.com/vsphere- 60/index.jsp?topic=/com.vmware.vsphere.security.doc/GUID-7A8BEFC8-BF86- 49B5-AE2D-E400AAD81BA3.html

Question No: 9 – (Topic 1)

An administrator has been instructed to secure existing virtual machines in vCenter Server.

Which two actions should the administrator take to secure these virtual machines? (Choose two.)

  1. Disable native remote management services

  2. Restrict Remote Console access

  3. Use Independent Non-Persistent virtual disks

  4. Prevent use of Independent Non-Persistent virtual disks

Answer: B,D

Reference: http://www.vmware.com/files/pdf/techpaper/VMW-TWP-vSPHR-SECRTY- HRDNG-USLET-101-WEB-1.pdf (page 11, see the tables)

Question No: 10 – (Topic 1)

An administrator wants to clone a virtual machine using the vSphere Client.

Which explains why the Clone option is missing?

  1. The vSphere Client is directly connected to the ESXi host.

  2. The virtual machine is configured with a thin-provisioned virtual disk.

  3. The virtual machine is configured with outdated Virtual Hardware.

  4. Cloning can only be performed with vRealize Orchestrator.

Answer: A Explanation:

The Clone option is missing because vSphere client is directly connected to the ESXi host. To enable the option, you have to connect it through vcenter server because cloning is a vCenter Server feature. You need install vCenter server on one of the Windows Server and connect vCenter Server via vSphere client and create cluster, add host after that you will see cloning and template option and much more

