Following an internal security audit of the new VMware Cloud Foundation (VCF) instance, the following audit finding was documented for priority remediation: All users from the custom administrators group could access the Direct Console User Interface (DCUI) on all ESXi hosts within the workload domain. RISK=High, IMPACT=High The company IT security policy around accessing ESXi servers states the following: Users within the custom administrators group must access ESXi host configurations from within vCenter Server or the vSphere Web Client only. Only users within the restricted administrators group must be allowed direct access to ESXi hosts. Which two actions should the administrator perform on each of the hosts within the workload domain to remediate the security finding? (Choose two.)
Select an option, then click Submit answer.
Reference / correct answer:
Add the restricted administrators group to the DCUI.Access advanced system setting.
Most accepted answer: C. Add the restricted administrators group to the DCUI.Access advanced system setting.
Community votes: C=3, D=1, E=2
Selected Answer: CE E to enable DCUI to Administrators group. C to disable DCUI access to non-Administrators group. upvoted 4 times
Selected Answer: CD A. Disable SSH and ESXi Shell – Helpful but not sufficient. You still need to control DCUI and lockdown behavior. B. Add the custom administrators group to DCUI.Access – This would violate the security policy. They’re explicitly not supposed to have direct host access. E. Enable Normal Lockdown Mode – Normal mode allows access via DCUI by any user with local shell permissions, which doesn’t enforce the strict separation your policy requires. upvoted 3 times
Selected Answer: CE CE Strict lockdown would shut down DCUI service altogether. Normal allows roles with 'DCUI.Access' permission to use it https://techdocs.broadcom.com/us/en/vmware-cis/vsphere/vsphere/8-0/vsphere-security-8-0/securing-esxi-hosts/customizing-hosts-with-the-security-profile/lockdown-mode.html upvoted 4 times xmtpcs10 1 year, 2 months ago Yes, but it doesn't allow "Only users within the restricted administrators group must be allowed direct access to ESXi hosts", so you need DCUI up and running. upvoted 1 times xmtpcs10 1 year, 2 months ago Sorry, I didn't read that well, you're right. upvoted 1 times ... ...
Yes, but it doesn't allow "Only users within the restricted administrators group must be allowed direct access to ESXi hosts", so you need DCUI up and running. upvoted 1 times xmtpcs10 1 year, 2 months ago Sorry, I didn't read that well, you're right. upvoted 1 times ...
Sorry, I didn't read that well, you're right. upvoted 1 times