Michael_G_Ander- client certificate can be run via the silentclient.cmd also. The fact that CA trust is being established, means that the process works.
I went through the log files and finally found the reason of certificate deployment failure. The VM is provisioned by SCCM in a temporary VLAN and uses DHCP. Once the provisioned part completes via SCCM, our VM admins do final configurations on the VM which includes the correct IP address and VLAN.
The silentclient.cmd fails certificate deployment with EXIT STATUS 5954: The host name could not be resolved to the requesting host's IP address. Unless we change that, the certificate deployment portion cannot be done successfully during the SCCM deployment.
Do note that the rest of the configuration of NetBackup client works though: setting up CA trust, client host name, master server, and additional servers, using the silentclient.cmd.