Courseiva
vSphere Security →mediumMultiple Choice

VCP-DCV vSphere Security Practice Question

A retail company's vSphere 8 environment uses vCenter Single Sign-On (SSO) with an external identity provider via SAML. The security team wants to enforce multi-factor authentication (MFA) for all administrators logging into vCenter Server. Which SSO configuration should the administrator implement?

⚠ Common exam trap

The trap here is thinking that enabling password policies or smart cards alone fulfills MFA, when MFA specifically requires multiple authentication factors, often best enforced by the external identity provider.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the identity provider to require MFA and set the vCenter SSO to use the external identity provider as the authentication source.

To enforce MFA for vCenter administrators, the most effective method is to delegate authentication to an external identity provider that already enforces MFA. When vCenter SSO is configured to use that provider via SAML, MFA becomes mandatory for all logins. Other options either do not provide MFA or are not aligned with the existing SAML integration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure vCenter SSO to use Integrated Windows Authentication (IWA) and enable Kerberos pre-authentication.

    Why it's wrong here

    IWA with Kerberos provides single sign-on for Windows users but does not inherently enforce MFA. Kerberos pre-authentication is not a second factor; it is part of the Kerberos protocol. This option does not satisfy the MFA requirement for all administrators.

  • ✓

    Configure the identity provider to require MFA and set the vCenter SSO to use the external identity provider as the authentication source.

    Why this is correct

    When vCenter SSO is configured to use an external identity provider via SAML, authentication is delegated to that provider. If the identity provider enforces MFA, administrators must complete MFA to log in. This approach centralizes MFA enforcement and meets the requirement without additional vCenter configuration.

  • ✗

    Enable Smart Card Authentication in vCenter SSO and require administrators to use smart cards.

    Why it's wrong here

    Smart Card Authentication is a form of MFA, but it requires a smart card infrastructure and does not integrate with the existing external identity provider. The requirement is to enforce MFA for all administrators, and the existing SAML integration already provides a path to MFA via the identity provider.

  • ✗

    Set the vCenter SSO password policy to require complex passwords and frequent changes.

    Why it's wrong here

    Password complexity and rotation are not MFA; they only strengthen single-factor authentication. MFA requires at least two different factors, such as something you know and something you have. This option does not meet the MFA requirement.

About these practice questions

Courseiva writes every VCP-DCV question from scratch — 281 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official VMware exam blueprint

This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.