VCP-DCV vSphere Security Practice Question
A retail company's vSphere 8 environment uses vCenter Single Sign-On (SSO) with an external identity provider via SAML. The security team wants to enforce multi-factor authentication (MFA) for all administrators logging into vCenter Server. Which SSO configuration should the administrator implement?
⚠ Common exam trap
The trap here is thinking that enabling password policies or smart cards alone fulfills MFA, when MFA specifically requires multiple authentication factors, often best enforced by the external identity provider.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the identity provider to require MFA and set the vCenter SSO to use the external identity provider as the authentication source.
To enforce MFA for vCenter administrators, the most effective method is to delegate authentication to an external identity provider that already enforces MFA. When vCenter SSO is configured to use that provider via SAML, MFA becomes mandatory for all logins. Other options either do not provide MFA or are not aligned with the existing SAML integration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure vCenter SSO to use Integrated Windows Authentication (IWA) and enable Kerberos pre-authentication.
Why it's wrong here
IWA with Kerberos provides single sign-on for Windows users but does not inherently enforce MFA. Kerberos pre-authentication is not a second factor; it is part of the Kerberos protocol. This option does not satisfy the MFA requirement for all administrators.
- ✓
Configure the identity provider to require MFA and set the vCenter SSO to use the external identity provider as the authentication source.
Why this is correct
When vCenter SSO is configured to use an external identity provider via SAML, authentication is delegated to that provider. If the identity provider enforces MFA, administrators must complete MFA to log in. This approach centralizes MFA enforcement and meets the requirement without additional vCenter configuration.
- ✗
Enable Smart Card Authentication in vCenter SSO and require administrators to use smart cards.
Why it's wrong here
Smart Card Authentication is a form of MFA, but it requires a smart card infrastructure and does not integrate with the existing external identity provider. The requirement is to enforce MFA for all administrators, and the existing SAML integration already provides a path to MFA via the identity provider.
- ✗
Set the vCenter SSO password policy to require complex passwords and frequent changes.
Why it's wrong here
Password complexity and rotation are not MFA; they only strengthen single-factor authentication. MFA requires at least two different factors, such as something you know and something you have. This option does not meet the MFA requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VCP-DCV question from scratch — 281 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official VMware exam blueprint
This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.