Courseiva
vSphere SecurityhardMultiple ChoiceObjective-mapped

VCP-DCV vSphere Security Practice Question

A financial institution operates a vSphere 7.0 environment with three vCenter Servers in linked mode, each managing separate clusters. The company uses vSAN encryption with an external KMS appliance from a third-party vendor. The KMS appliance has a certificate that expires every two years. The storage administrator recently renewed the KMS certificate as per the vendor's instructions. After the renewal, the vCenter Server's 'Key Management Servers' view shows the KMS status as 'Unhealthy'. The administrator attempts to decrypt a test virtual machine, but the operation fails with an error: 'No key providers are available'. The KMS appliance is reachable from the vCenter Server, and the new certificate is installed on the KMS. The administrator has confirmed that the KMS IP address and port are correctly configured in vCenter. What is the most likely cause of the failure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The new KMS certificate has not been imported into the vCenter Server trust store

The most likely cause is that the new KMS certificate was not imported into the vCenter Server trust store. Even though the KMS appliance is reachable and the new certificate is installed on the KMS, vCenter Server must trust the KMS certificate to establish a secure connection. Without the certificate in the trust store, vCenter considers the KMS unhealthy, leading to the 'No key providers are available' error. The vSAN encryption keys are not lost during certificate renewal—they remain stored on the KMS. Recreating the KMS cluster is unnecessary because the configuration is still valid, and restarting vCenter services would not resolve the trust issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The vSAN encryption keys were lost during the certificate renewal

    Why it's wrong here

    Keys are stored in the KMS, not lost; certificate renewal does not affect stored keys.

  • The KMS cluster in vCenter needs to be recreated

    Why it's wrong here

    Recreating the KMS cluster is not needed; the configuration remains valid, only trust is broken.

  • The new KMS certificate has not been imported into the vCenter Server trust store

    Why this is correct

    vCenter must trust the KMS certificate to communicate; otherwise, it shows the KMS as unhealthy.

  • The vCenter Server services need to be restarted

    Why it's wrong here

    Restarting services does not fix trust issues; the certificate must be imported.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 498 original VCP-DCV practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.