Exam 5v0-3122 All QuestionsBrowse all questions from this exam
Question 57

The architect of a multi-site VMware Cloud Foundation solution is tasked with ensuring that the prerequisites for vSAN data at rest encryption have been achieved. The existing design calls for use of the vSphere Native Key Provider. NSX-T is configured with Federation, and both sites benefit from a stretched T0 and T1 network topology.

A new security policy requires the use of vSphere Virtual Machine encryption, in addition to the at-rest encryption already configured. During a failover test from Site-A to Site-B using Site Recovery Manager, the virtual machines were unable to power-on.

How does the design need to be changed to support the new requirement?

    Correct Answer: C

    To support vSphere Virtual Machine encryption in addition to vSAN data at rest encryption during a failover with Site Recovery Manager, the design needs to ensure that the encryption keys are available at both sites. A third-party Key Management Service (KMS) solution that allows for key replication ensures that the necessary encryption keys are accessible at the disaster recovery site, facilitating the power-on of encrypted VMs during a failover. This solution addresses the requirement of maintaining key availability across multiple sites, which is crucial for encryption-based operations in a failover scenario.

Discussion
SawanmOption: D

its D https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.security.doc/GUID-54B9FBA2-FDB1-400B-A6AE-81BF3AC9DF97.html

diegof1Option: C

For me C is the most secure option On the other hand, I couda find in vSphere Native Key Provider (NKP) Questions & Answers this: I use Site Recovery Manager. What considerations are there to ensure encrypted virtual machines can run on the DR site? When using Site Recovery Manager, you must configure both vCenter instances with the same vSphere Native Key Provider key encryption key (KEK). This requires you to export the vSphere Native Key Provider from one vCenter instance and import it into the DR vCenter instance. For more see Site Recovery Manager and Virtual Machine Encryption. https://core.vmware.com/native-key-provider-questions-answers#is-native-key-provider-a-kms Although D sounds fine, I could not find any reference guide about the need for Cryptographer.ReadKeyServersInfo privileges.