Courseiva
vSphere Security →hardMultiple Choice

VCP-DCV vSphere Security Practice Question

A multinational corporation runs a vSphere environment with 100 ESXi hosts managed by a single vCenter Server. The security team mandates that all virtual machine disks (VMDKs) must be encrypted at rest. The administrator enables vSphere Virtual Machine Encryption and creates a Key Management Server (KMS) cluster. After encrypting a test VM, the VM powers on successfully, but the administrator notices that the VM's configuration files (VMX, NVRAM) are not encrypted. The security policy requires that all VM files, including configuration files, be encrypted. The administrator checks the VM storage policy and sees that the policy is set to 'VM Encryption Policy' with 'Disk Encryption' enabled. What should the administrator do to ensure the entire VM is encrypted?

⚠ Common exam trap

Test-takers frequently assume 'VM Encryption Policy' with 'Disk Encryption' covers all VM files, but VMware explicitly separates disk encryption from home file encryption in the storage policy settings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modify the VM storage policy to include encryption of VM home files

The VM storage policy 'VM Encryption Policy' with only 'Disk Encryption' enabled encrypts VMDK files but not the VM configuration files (VMX, NVRAM, logs, etc.). To encrypt all VM files, the storage policy must include the 'Encrypt VM home files' option, which applies encryption to the entire VM home directory on the datastore. This ensures compliance with the security mandate for full VM encryption at rest.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Modify the VM storage policy to include encryption of VM home files

    Why this is correct

    The VM storage policy's VM Encryption Policy encrypts only VMDKs by default; VM home files (VMX, NVRAM) require the separate 'Encrypt VM home files' setting. Enabling that component in the policy satisfies the mandate that configuration files be encrypted at rest.

  • ✗

    Enable encryption on the datastore where the VM resides

    Why it's wrong here

    Datastores hold VM files but provide no encryption mechanism; encryption is applied through storage policies on the VM's objects. Datastore-level encryption is tempting because array-based encryption protects everything stored on a LUN, but vSphere VM Encryption requires a VM storage policy with the VM Encryption Policy applied to all VM files.

  • ✗

    Add a second KMS cluster for redundancy

    Why it's wrong here

    A second KMS cluster provides key-server redundancy if the primary fails; it does not extend encryption to VMX and NVRAM files. Adding KMS clusters is tempting when designing resilient key management, but the stem's issue is that the storage policy only enables Disk Encryption rather than full VM encryption.

  • ✗

    Enable vSphere Host Encryption on each ESXi host

    Why it's wrong here

    Host Encryption is not a vSphere feature; encryption is driven by VM storage policies, not per-host settings. Enabling something on each ESXi host is tempting because host-level configuration feels global, but only applying a VM Encryption Policy that encrypts configuration files, not just disks, satisfies the requirement.

About these practice questions

One of 281 original VCP-DCV practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.