VCP-DCV vSphere Security Practice Question
A multinational corporation runs a vSphere environment with 100 ESXi hosts managed by a single vCenter Server. The security team mandates that all virtual machine disks (VMDKs) must be encrypted at rest. The administrator enables vSphere Virtual Machine Encryption and creates a Key Management Server (KMS) cluster. After encrypting a test VM, the VM powers on successfully, but the administrator notices that the VM's configuration files (VMX, NVRAM) are not encrypted. The security policy requires that all VM files, including configuration files, be encrypted. The administrator checks the VM storage policy and sees that the policy is set to 'VM Encryption Policy' with 'Disk Encryption' enabled. What should the administrator do to ensure the entire VM is encrypted?
⚠ Common exam trap
Test-takers frequently assume 'VM Encryption Policy' with 'Disk Encryption' covers all VM files, but VMware explicitly separates disk encryption from home file encryption in the storage policy settings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Modify the VM storage policy to include encryption of VM home files
The VM storage policy 'VM Encryption Policy' with only 'Disk Encryption' enabled encrypts VMDK files but not the VM configuration files (VMX, NVRAM, logs, etc.). To encrypt all VM files, the storage policy must include the 'Encrypt VM home files' option, which applies encryption to the entire VM home directory on the datastore. This ensures compliance with the security mandate for full VM encryption at rest.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Modify the VM storage policy to include encryption of VM home files
Why this is correct
The VM storage policy's VM Encryption Policy encrypts only VMDKs by default; VM home files (VMX, NVRAM) require the separate 'Encrypt VM home files' setting. Enabling that component in the policy satisfies the mandate that configuration files be encrypted at rest.
- ✗
Enable encryption on the datastore where the VM resides
Why it's wrong here
Datastores hold VM files but provide no encryption mechanism; encryption is applied through storage policies on the VM's objects. Datastore-level encryption is tempting because array-based encryption protects everything stored on a LUN, but vSphere VM Encryption requires a VM storage policy with the VM Encryption Policy applied to all VM files.
- ✗
Add a second KMS cluster for redundancy
Why it's wrong here
A second KMS cluster provides key-server redundancy if the primary fails; it does not extend encryption to VMX and NVRAM files. Adding KMS clusters is tempting when designing resilient key management, but the stem's issue is that the storage policy only enables Disk Encryption rather than full VM encryption.
- ✗
Enable vSphere Host Encryption on each ESXi host
Why it's wrong here
Host Encryption is not a vSphere feature; encryption is driven by VM storage policies, not per-host settings. Enabling something on each ESXi host is tempting because host-level configuration feels global, but only applying a VM Encryption Policy that encrypts configuration files, not just disks, satisfies the requirement.
Go deeper
Related to this question
About these practice questions
One of 281 original VCP-DCV practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.