VCP-DCV vSphere Security Practice Question
A financial institution operates a vSphere 7 environment with 1,000 VMs, many of which process sensitive data. The security team mandates VM encryption at rest using a Key Management Server (KMS) cluster. The administrator has configured the KMS cluster as a key provider in vCenter and enabled encryption on a test VM, which works correctly. However, after adding a new ESXi host to the cluster and attempting to power on a previously encrypted VM, the VM fails to start with the error: 'Key provider unavailable for host <hostname>.' The new host is correctly licensed for encryption and has network connectivity to the KMS. The administrator verifies that the KMS cluster is operational and that other hosts can power on encrypted VMs. What is the most likely cause of this issue?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The ESXi host has not been added to the Key Provider's trust list or KMS configuration.
When a new ESXi host is added to the cluster, it must be added to the Key Provider's trust list or the KMS must be configured to trust the host's certificate. Without this, the host cannot retrieve keys from the KMS, even though it has network connectivity and is properly licensed. Option B is incorrect: a firewall issue would typically cause a connection timeout or refusal error, not a 'key provider unavailable' error. Option C is incorrect because the host is verified to have the correct encryption license. Option D is incorrect because the error indicates the KMS is not available to that host, not a policy mismatch.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The ESXi host has not been added to the Key Provider's trust list or KMS configuration.
Why this is correct
Hosts must be trusted by the KMS to retrieve keys; a newly added host is not automatically trusted.
- ✗
The ESXi host's firewall is blocking outbound connections to the KMS cluster.
Why it's wrong here
The administrator verified network connectivity, so firewall is not the issue.
- ✗
The ESXi host does not have the required encryption feature license.
Why it's wrong here
The administrator verified the host is correctly licensed for encryption.
- ✗
The VM's encryption policy is set to 'vSphere Native Key Provider' instead of 'KMS'.
Why it's wrong here
The VM was originally encrypted using the KMS, so the policy is correct; the error is host-specific.
Go deeper
Related to this question
About these practice questions
This VCP-DCV question is part of Courseiva's 498-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.