VCP-DCV Configure and Manage vSphere Networking Practice Question
A vSphere administrator is troubleshooting connectivity issues for a virtual machine that is unable to communicate with other VMs on the same VLAN. The VM is connected to a distributed port group on a vSphere Distributed Switch (vDS). The administrator verifies that the VM's IP configuration is correct and that the port group is configured with the correct VLAN ID. However, the VM can only communicate with other VMs on the same ESXi host. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The physical switch ports connecting the ESXi hosts are not configured as trunk ports for the VLAN.
The VM can communicate only with other VMs on the same ESXi host because VLAN-tagged frames cannot pass through the physical switch ports to other hosts. For VMs on the same VLAN to communicate across hosts, the physical switch ports connecting the ESXi hosts must be configured as trunk ports that allow the relevant VLAN. Option A is incorrect because the vDS does not require a separate VLAN trunking policy; the port group VLAN ID handles tagging. Option B is incorrect because the MAC address is automatically assigned and would not cause host-only communication. Option C is incorrect because the 'forging transmits' security policy controls MAC address changes, not basic connectivity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The vDS is not configured with a VLAN trunking policy.
Why it's wrong here
VLAN trunking policy is not required; the port group VLAN ID performs VLAN tagging. This would not limit communication to a single host.
- ✗
The VM's network adapter is configured with the wrong MAC address.
Why it's wrong here
The VM's MAC address is typically automatically generated and correct. Wrong MAC would likely prevent all communication, not just cross-host.
- ✗
The distributed port group has forging transmits set to reject.
Why it's wrong here
Forging transmits controls whether the virtual switch accepts frames with a different source MAC. It does not affect basic connectivity across hosts.
- ✓
The physical switch ports connecting the ESXi hosts are not configured as trunk ports for the VLAN.
Why this is correct
If physical switch ports are not trunking the VLAN, frames tagged with that VLAN will be dropped, preventing cross-host communication while intra-host communication (no physical switch) works.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This VCP-DCV question is part of Courseiva's 498-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.