VCP-DCV vSphere Security Practice Question
A security team requires that all vCenter Server administrative logins be validated against an external identity source, but they also want to retain the ability to log in with the local SSO administrator account during a directory service outage. An administrator has already added the Active Directory identity source to vCenter Single Sign-On. Which configuration should the administrator apply to meet both requirements?
⚠ Common exam trap
The trap here is assuming that adding an Active Directory identity source to vCenter Single Sign-On automatically disables or removes the local SSO administrator account.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add the Active Directory identity source, set it as the default identity source, and keep the local SSO administrator account available for emergency access.
The requirement has two parts: external validation for administrative logins and a usable local fallback. Setting the added Active Directory source as the default identity source directs SSO to validate against the directory by default, while the built-in SSO administrator account persists and can still authenticate locally. Disabling or removing the local account would break the fallback requirement, and leaving the local domain as default would not enforce external validation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the Active Directory identity source as the default identity source and grant the AD domain admins the Administrator role on the root folder.
Why it's wrong here
Making the directory the default identity source changes which domain is prepopulated at the SSO login prompt, but the local SSO administrator account continues to exist and can still be used. Granting the AD domain admins the Administrator role at the root folder does provide administrative access, yet it does not satisfy the requirement that all logins be validated externally, since the local SSO administrator bypasses that validation.
- ✗
Add the Active Directory identity source, then assign the AD security group the Global Permissions Administrator role, and leave the default identity source as the local SSO domain.
Why it's wrong here
Leaving the default identity source as the local SSO domain means the login prompt defaults to the local domain rather than the directory. The AD group does receive administrative permissions, and admins can still type the AD domain manually at login, but the environment is not configured to validate administrative logins against the external directory by default, so the first requirement is only partially met.
- ✓
Add the Active Directory identity source, set it as the default identity source, and keep the local SSO administrator account available for emergency access.
Why this is correct
Setting the directory as the default identity source makes vCenter Single Sign-On present that domain first and validate administrative logins against it, satisfying the external-validation requirement. The local SSO administrator account is not deleted by adding an identity source, so it remains usable for break-glass access if the directory becomes unreachable, which satisfies the second requirement without weakening normal operations.
- ✗
Set the identity source type to 'Active Directory over LDAP' and enable 'Use Windows session authentication'.
Why it's wrong here
Windows session authentication only allows clients that are already logged into a Windows domain to pass credentials to vCenter, so it complements AD but does not by itself enforce external validation for all logins. Changing the identity source type to LDAP does not preserve the local SSO administrator fallback, because that account remains governed by the default identity source setting, not by the added directory.
Go deeper
Related to this question
About these practice questions
One of 281 original VCP-DCV practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official VMware exam blueprint
This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.