Q: 9
Which feature should be enabled to prevent password access to the CVM for both the nutanix and admin user accounts?
Options
Discussion
A is it. Cluster lockdown specifically blocks password SSH for both nutanix and admin, so you have to use key-based auth after that. RBAC or STIG don't actually cut off the password method by themselves as far as I know. Pretty sure that's right but correct me if I'm missing some config detail.
Maybe B, since STIG covers a lot of security hardening steps around password use.
B tbh, since STIGs usually enforce a bunch of hardening steps including password restrictions. I've seen environments where applying STIG disables password logins. Not fully sure though, could be mixing it up.
A
RBAC won't block direct CVM password logins, Cluster lockdown does. Saw this in practice tests, B is a trap.
RBAC won't block direct CVM password logins, Cluster lockdown does. Saw this in practice tests, B is a trap.
A
Its A, but only if public key auth is still allowed for those users. Some get tripped up by that.
Wouldn't B (STIG) only recommend settings and not actually block password access itself? A seems like the only Nutanix feature that directly disables password login for both nutanix and admin accounts, unless I'm missing something.
Nah, B is a common trap, you want A here. Only Cluster Lockdown blocks password logins for both accounts.
A seen this in a few practice sets. Cluster lockdown actually disables password access for those accounts.
Option A saw a similar question in some exam reports.
Be respectful. No spam.