VCP-DCV vSphere Security Practice Question
A vSphere administrator needs to ensure that all virtual machine disks are encrypted at rest. The environment uses a KMS cluster with multiple KMIP-compliant servers. The administrator has already configured a storage policy with encryption enabled. However, newly created VMs on a particular datastore still show unencrypted disks. What is the most likely cause?
⚠ Common exam trap
It's easy for candidates to assume configuring a storage policy with encryption is sufficient, but they forget that the policy must be explicitly assigned to the VM or its home namespace for encryption to take effect.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The storage policy with encryption is not assigned to the VMs or their home namespace.
Even when a storage policy with encryption is configured, it must be explicitly assigned to the VMs or their home namespace (the VM's configuration and swap files). If the policy is not assigned, the VM will be created using the default datastore policy, which typically does not include encryption, resulting in unencrypted disks. The administrator must ensure the encryption-enabled policy is applied to the VM during creation or via a storage policy-based management (SPBM) assignment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The datastore is a vSAN datastore, which does not support VM-level encryption.
Why it's wrong here
vSAN datastores do support VM encryption; the actual cause lies in the storage policy not being applied to the VMs. It is tempting because vSAN encryption is a separate cluster-level feature, which is the correct choice when encrypting the datastore itself rather than individual VM disks.
- ✗
The KMS cluster must have at least two KMS servers to function correctly.
Why it's wrong here
A KMS cluster functions with a single server; multiple servers provide redundancy, not a prerequisite. It is tempting because KMS clustering genuinely improves availability, which would be the right consideration when designing for resilience rather than diagnosing unencrypted disks.
- ✗
The datastore is formatted with VMFS6, which does not support encryption.
Why it's wrong here
VMFS6 fully supports VM encryption; the format is not the blocker. It is tempting because older VMFS versions had encryption limitations, so version checks are a reasonable diagnostic step, but here the policy simply is not being applied to the VMs.
- ✓
The storage policy with encryption is not assigned to the VMs or their home namespace.
Why this is correct
Encryption is enforced through the VM storage policy, not the datastore itself. If that policy is not assigned to the VMs or their home namespace, their disks remain unencrypted despite the KMS cluster and policy existing.
Go deeper
Related to this question
About these practice questions
One of 281 original VCP-DCV practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.