Courseiva
vSphere SecurityhardMultiple ChoiceObjective-mapped

VCP-DCV vSphere Security Practice Question

A company has a vSphere environment with 20 ESXi hosts and 500 VMs. The security team mandates that all administrative access to vCenter Server must be through a single, highly restricted account with multi-factor authentication (MFA). The account must be used for both the vSphere Client and API integrations. Which step should the administrator take?

⚠ Common exam trap

It's easy for candidates to assume the built-in administrator account can be directly configured with MFA for all access types, but vCenter Server does not natively support MFA for local accounts or API integrations without an external identity provider.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Integrate vCenter Server with an external identity provider (e.g., ADFS, Okta) that supports MFA, and use a service account with MFA for API access.

Integrating vCenter Server with an external identity provider (IdP) such as ADFS or Okta allows the use of a single service account that supports multi-factor authentication (MFA) for both the vSphere Client and API integrations. This approach meets the security mandate by centralizing authentication through an IdP that enforces MFA, while also supporting OAuth 2.0 token-based API access, which is required for modern vSphere API integrations. The built-in administrator account cannot be directly configured with MFA in a way that satisfies both interactive and API access requirements without external integration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configure the built-in administrator account to require smart card authentication.

    Why it's wrong here

    Smart card authentication is not equivalent to MFA and may not be supported for API integrations.

  • Integrate vCenter Server with an external identity provider (e.g., ADFS, Okta) that supports MFA, and use a service account with MFA for API access.

    Why this is correct

    External identity providers can enforce MFA and work with both UI and API access.

  • Create a new local account and configure it as a member of the Administrators group, then enforce MFA via a third-party tool on the vCenter Server OS.

    Why it's wrong here

    Third-party MFA on the OS is not supported and would not cover API access.

  • Disable the built-in administrator account and create a new local account with the same privileges.

    Why it's wrong here

    Local accounts do not support MFA; disabling the built-in account can cause issues.

About these practice questions

Courseiva writes every VCP-DCV question from scratch — 498 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.