Courseiva
vSphere SecuritymediumMultiple ChoiceObjective-mapped

VCP-DCV vSphere Security Practice Question

A vCenter Server's SSL certificate has expired, causing all ESXi hosts to display a certificate warning and some management tasks to fail. The administrator needs to restore secure communication with minimal disruption. Which action should the administrator take?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Replace the vCenter Server certificate and then reconnect each ESXi host to vCenter.

Replacing the vCenter Server certificate and then reconnecting each ESXi host restores trust and secure communication. Option A is wrong because rebooting the vCenter Server appliance does not regenerate the SSL certificate automatically; the certificate remains expired. Option C is wrong because replacing certificates on each ESXi host individually does not address the expired vCenter certificate and is inefficient. Option D is wrong because vSphere Auto Deploy is used for provisioning hosts, not for replacing vCenter certificates.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Reboot the vCenter Server appliance to regenerate the certificate automatically.

    Why it's wrong here

    Rebooting the vCenter Server appliance does not regenerate the SSL certificate automatically. The certificate remains expired, so this action does not restore secure communication.

  • Replace the vCenter Server certificate and then reconnect each ESXi host to vCenter.

    Why this is correct

    Replacing the vCenter Server certificate is the correct first step. After replacement, each ESXi host must be reconnected to vCenter to establish trust with the new certificate.

  • Replace the SSL certificate on each ESXi host individually using the vSphere Web Client.

    Why it's wrong here

    Replacing the SSL certificate on each ESXi host individually does not address the fact that the vCenter Server certificate itself is expired. The root issue is the vCenter certificate, not the host certificates.

  • Use vSphere Auto Deploy to push new certificates to all hosts simultaneously.

    Why it's wrong here

    vSphere Auto Deploy is used for automated provisioning and deployment of ESXi hosts, not for managing vCenter Server certificates. Even if used, the vCenter certificate must still be replaced.

About these practice questions

This VCP-DCV question is part of Courseiva's 498-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.