Courseiva
vSphere Security →mediumMultiple Choice

VCP-DCV vSphere Security Practice Question

A security team requires that all vCenter Server administrative logins be validated against an external identity source, but they also want to retain the ability to log in with the local SSO administrator account during a directory service outage. An administrator has already added the Active Directory identity source to vCenter Single Sign-On. Which configuration should the administrator apply to meet both requirements?

⚠ Common exam trap

The trap here is assuming that adding an Active Directory identity source to vCenter Single Sign-On automatically disables or removes the local SSO administrator account.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add the Active Directory identity source, set it as the default identity source, and keep the local SSO administrator account available for emergency access.

The requirement has two parts: external validation for administrative logins and a usable local fallback. Setting the added Active Directory source as the default identity source directs SSO to validate against the directory by default, while the built-in SSO administrator account persists and can still authenticate locally. Disabling or removing the local account would break the fallback requirement, and leaving the local domain as default would not enforce external validation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the Active Directory identity source as the default identity source and grant the AD domain admins the Administrator role on the root folder.

    Why it's wrong here

    Making the directory the default identity source changes which domain is prepopulated at the SSO login prompt, but the local SSO administrator account continues to exist and can still be used. Granting the AD domain admins the Administrator role at the root folder does provide administrative access, yet it does not satisfy the requirement that all logins be validated externally, since the local SSO administrator bypasses that validation.

  • ✗

    Add the Active Directory identity source, then assign the AD security group the Global Permissions Administrator role, and leave the default identity source as the local SSO domain.

    Why it's wrong here

    Leaving the default identity source as the local SSO domain means the login prompt defaults to the local domain rather than the directory. The AD group does receive administrative permissions, and admins can still type the AD domain manually at login, but the environment is not configured to validate administrative logins against the external directory by default, so the first requirement is only partially met.

  • ✓

    Add the Active Directory identity source, set it as the default identity source, and keep the local SSO administrator account available for emergency access.

    Why this is correct

    Setting the directory as the default identity source makes vCenter Single Sign-On present that domain first and validate administrative logins against it, satisfying the external-validation requirement. The local SSO administrator account is not deleted by adding an identity source, so it remains usable for break-glass access if the directory becomes unreachable, which satisfies the second requirement without weakening normal operations.

  • ✗

    Set the identity source type to 'Active Directory over LDAP' and enable 'Use Windows session authentication'.

    Why it's wrong here

    Windows session authentication only allows clients that are already logged into a Windows domain to pass credentials to vCenter, so it complements AD but does not by itself enforce external validation for all logins. Changing the identity source type to LDAP does not preserve the local SSO administrator fallback, because that account remains governed by the default identity source setting, not by the added directory.

About these practice questions

One of 281 original VCP-DCV practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official VMware exam blueprint

This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.