20+ practice questions focused on vSphere Security — one of the most tested topics on the VMware Certified Professional Data Center Virtualization VCP-DCV exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start vSphere Security PracticeWhich TWO actions are required to enable encrypted vSphere vMotion for all virtual machines in a cluster?
Explanation: Setting the vMotion encryption policy to 'Encrypt all data' enforces encryption for all vMotion migrations in the cluster, using TLS 1.2 and host-based certificates. Option D is incorrect because Active Directory domain membership is not required; vMotion encryption works with the default host certificates as long as the hosts trust each other's certificates, which is achieved by default in a cluster. A KMS (Option B) is not needed for vMotion encryption, only for VM-level encryption. Storage DRS (Option C) is unrelated. Option E, 'Encrypt when supported', does not enforce encryption for all VMs; it only encrypts when both source and target hosts support it, which may not apply to all migrations.
An organization is implementing vSphere Trust Authority for sensitive workloads. The administrator must configure the trusted ESXi hosts to attest to vCenter Server. Which component is responsible for performing attestation?
Explanation: VSphere Trust Authority uses a dedicated vCenter Server instance (Trust Authority vCenter) to perform attestation of ESXi hosts. Option A is incorrect because the administrator's workstation is not part of the trust chain and does not perform attestation. Option C is incorrect because the Key Provider (KMS) server is used for encryption key management, not for host attestation. Option D is incorrect because the trusted ESXi hosts themselves are the subjects of attestation; they do not perform attestation.
An organization is using vSphere Trust Authority (vTA) to secure ESXi hosts. A newly added ESXi host fails to attest with the Trust Authority. The administrator verifies that the host is connected to the vTA cluster and the trust relationship is configured. What is the most likely cause of the attestation failure?
Explanation: VTA attestation requires the ESXi host's TPM to be enabled and properly initialized. Option A is incorrect because the administrator verified that the host is connected to the vTA cluster, so network isolation is unlikely. Option B is incorrect because the ESXi host does not need to be in the same cluster as the Trust Authority; trust is configured separately. Option C is incorrect because vTA relies on the host's physical TPM, not a virtual TPM (vTPM).
An organization wants to secure management traffic between vCenter Server and ESXi hosts. The security policy mandates disabling all versions of TLS below 1.2. After the administrator configures vCenter to use only TLS 1.2, several ESXi hosts (all version 6.0) lose connectivity to vCenter. The hosts remain operational but show as disconnected in the vSphere Web Client. The administrator needs to restore management while maintaining the security requirement. Which action should the administrator take?
Explanation: ESXi 6.0 only supports TLS 1.0; to use TLS 1.2, hosts must be upgraded to ESXi 6.5 or later. Option B is wrong because disabling certificate verification does not address the TLS version issue and weakens security. Option C is wrong because SSH is not used for vCenter-to-ESXi management communication. Option D is wrong because re-enabling TLS 1.0 would violate the security policy.
An administrator is troubleshooting a situation where a virtual machine cannot be powered on. The error message indicates insufficient permissions. The VM is in a folder named 'Production' and the administrator has been assigned a custom role with 'Virtual machine > Power On' permission at the folder level. However, the VM is also in a resource pool. What additional permission is most likely missing?
Explanation: To power on a virtual machine that resides in a resource pool, the user must have the 'Resource > Assign virtual machine to resource pool' permission on that resource pool. Even though the user has 'Virtual machine > Power On' at the folder level, the VM's association with the resource pool introduces an additional authorization check. Without this resource pool permission, the power-on operation fails with an insufficient permissions error.
+15 more vSphere Security questions available
Practice all vSphere Security questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of vSphere Security. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
vSphere Security questions on the VCP-DCV frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. vSphere Security is tested as part of the VMware Certified Professional Data Center Virtualization VCP-DCV blueprint. Practicing with targeted vSphere Security questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free VCP-DCV practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but vSphere Security is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full vSphere Security practice session with instant scoring and detailed explanations.
Start vSphere Security Practice →