VMCE Practice Question - 25 April 2024


Userlevel 7
Badge +17

Guess what day it is?! Yep, it’s VMCE Practice Exam Question day! As I shared on Tue, questions are going to be a bit more difficult. When attempting to answer, try and make your attempt “exam like”. Hide any comments (answers) already shared, and try to answer the question on your own without researching, & see how well you do.

Starting next week, I’m going to add an additional question day on Wed, providing a question from a Veeam Technical Trainer. I’ll keep the post subject the same for Hub searching purposes, but will add “(VTT)” so you know it’s an extra question and from a Veeam Technical Trainer (VTT) 😊 Hope you’re finding all the questions beneficial! And don’t forget, tomorrow I’ll provide answers/comments/links to both today’s and Tue’s questions. So, without further ado….

 

The Security Administrator at your company comes to you, the Backup Administrator, wanting assurance your backup environment meets server hardening requirements. You log onto the Backup Server and run the Security & Compliance Analyzer. What are parameters this feature test checks for (Select Two)?

  1. TLS 1.0 and 1.1 are disabled
  2. Backup Server Remote Registry is turned off
  3. Windows Powershell is disabled
  4. Immutability is found in the backup environment
  5. SMBv3 is disabled
  6. MFA is disabled

 


4 comments

Userlevel 7
Badge +20

Answers A & B

 

Userlevel 3
Badge +1

Without read any previous comments….. i say the B) and f) 

:-)

Userlevel 4
Badge

I would answer with:

B & D

Got it?

Userlevel 7
Badge +17

Good morning! It’s time to provide the answer and link!

First off, I want to apologize for the question. I do try to look at & review my questions/answers a few times after I write them up, and again before I post, to make sure it’s not too vague & is accurate. Unfortunately, I didn’t fully succeed at this one. 

That being said...let’s get to the answer/explanation and link. First, the answer is indeed B & D. But, Chris’s answer isn’t totally incorrect either. Veeam does a real good job at their questions now and imo wouldn’t have a “semi-correct answer” question on their exam like this one. What is semi-correct? One of Chris’s provided answer of A. Why I didn’t have that as an answer is because the listed parameters do not explicitly say TLS 1.0 and 1.1 disabled in the S&CA. But, upon 4th or 5th glance at them (yes, I did look at them that many times, at least), it does say in the list Deprecated versions of SSL and TLS should be disabled. So for that reason, Chris isn’t entirely wrong. My guess is if Veeam did have a question like this, if you selected A as one of your answers, you’d get partial credit (Veeam does grade their exam this way, even with their questions being more explicit and ‘black and white’ in the answers they list than my question above).

BONUS question: What are some other parameters the S&CA checks for?

Link: https://helpcenter.veeam.com/docs/backup/vsphere/best_practices_analyzer.html?ver=120#configuration-parameters

Comment