VCP-DCV vSphere Security Practice Question
A company runs a critical e-commerce platform on a vSphere 7 cluster with ESXi hosts connected to a vSAN datastore. The environment uses vSphere Trust Authority (vTA) and VM encryption with an external KMS. Recently, after a successful vTA attestation, one of the VMs (WebServer-01) failed to power on with the error: 'Unable to decrypt the encrypted virtual machine upon re-registration. Reason: The KMS server is unreachable.' The administrator verifies that other encrypted VMs on the same host power on successfully. The KMS cluster consists of two servers: KMS-01 and KMS-02, both accessible from the management network. The administrator checks the VM's configuration and finds that it uses a custom storage policy with encryption. What is the most likely cause of this specific VM's failure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The VM's encryption key was retrieved from a different KMS server that is now unavailable, and the key ID in the VM's metadata points to that KMS server.
The error 'Unable to decrypt the encrypted virtual machine upon re-registration. Reason: The KMS server is unreachable' indicates that the ESXi host cannot contact the KMS server to retrieve the VM's encryption key. Since other encrypted VMs on the same host power on successfully, the host can reach the KMS cluster, but this specific VM's encryption key may have been issued by a different KMS server (e.g., an older or alternative KMS) that is now unavailable. The key ID stored in the VM's metadata points to that unreachable server, causing the failure. Option A is incorrect because if the vCenter KMS cluster configuration were deleted, all VMs would be affected. Option B is incorrect because modifying the storage policy does not change the existing encryption key; the VM remains encrypted with its original key. Option C is incorrect because vTA attestation is separate from KMS key retrieval; the error message is specific to KMS unavailability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The vCenter Server's KMS cluster configuration has been deleted, affecting all VMs but not this one.
Why it's wrong here
If the vCenter Server's KMS cluster configuration were deleted, all VMs would be affected, not just this one. Additionally, the error would likely occur for all encrypted VMs, but other VMs power on successfully.
- ✗
The storage policy used by the VM has been modified and no longer includes encryption.
Why it's wrong here
Modifying the storage policy to no longer include encryption would not affect the existing encryption of the VM. The VM remains encrypted with its original key, and the storage policy change only applies to new disks or VMs. The error is about key retrieval, not policy.
- ✗
The vTA attestation process failed for the VM's host, but the error message is misleading.
Why it's wrong here
vTA attestation is used to establish trust for encryption operations, but a failed attestation would cause a different error (e.g., 'Host not trusted'). The error message specifically states the KMS server is unreachable, indicating a different issue.
- ✓
The VM's encryption key was retrieved from a different KMS server that is now unavailable, and the key ID in the VM's metadata points to that KMS server.
Why this is correct
Correct. The VM's encryption key may have been issued by a specific KMS server (e.g., KMS-01) that is now unreachable, while the KMS cluster overall is accessible. Other VMs may have keys from a different, reachable server (e.g., KMS-02), explaining why they power on successfully.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VCP-DCV question from scratch — 498 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.