Courseiva

VCP-DCV Configure and Manage vSphere Networking Practice Question

A network administrator needs to isolate traffic between VMs in the same VLAN on a distributed switch. Which feature should be used?

⚠ Common exam trap

VCP-DCV often tests the confusion between bandwidth features (NIOC, traffic shaping) and isolation features (PVLAN), catching candidates who pick a QoS option for a segmentation requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Private VLAN

Private VLANs (PVLANs) on a vSphere Distributed Switch allow Layer 2 isolation between VMs in the same VLAN by using primary and secondary VLANs with promiscuous, isolated, and community port types. This is the specific feature designed to prevent VM-to-VM traffic within a single VLAN while still allowing communication with a gateway or designated promiscuous ports. It directly addresses the requirement to isolate same-VLAN VM traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Network I/O Control

    Why it's wrong here

    Network I/O Control allocates bandwidth shares and limits across traffic types on a distributed switch; it does not prevent VM-to-VM communication within a VLAN. It is tempting because it governs traffic on the switch, and would be correct when prioritising or reserving bandwidth between flows.

  • ✓

    Private VLAN

    Why this is correct

    Private VLANs subdivide a single VLAN into isolated secondary VLANs, preventing VM-to-VM traffic on the same segment while permitting promiscuous uplinks. This delivers the required Layer 2 isolation on a distributed switch, which port groups alone cannot enforce between members of one VLAN.

  • ✗

    VLAN trunking

    Why it's wrong here

    VLAN trunking carries multiple VLAN tags over one uplink; it does not filter traffic between VMs sharing a VLAN. It is tempting because trunking segments traffic at Layer 2, but it would be correct when passing several VLANs between switches or to a VM needing multiple VLANs, not for intra-VLAN isolation.

  • ✗

    Traffic shaping

    Why it's wrong here

    Traffic shaping limits average and peak bandwidth for a port or virtual machine, but it does not block communication between VMs sharing a VLAN. It is tempting because it controls traffic on the distributed switch, and would be correct when constraining a VM's throughput rather than isolating peers.

  • ✗

    Port binding

    Why it's wrong here

    Port binding determines how a virtual port is assigned to a VM (static or dynamic), not how traffic is filtered between VMs. It is tempting because binding controls port-level connectivity, but it would be the correct choice when assigning ports to VMs or configuring ephemeral versus static binding, not for isolating same-VLAN traffic.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every VCP-DCV question from scratch — 281 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official VMware exam blueprint

This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.