Courseiva
vSphere Security →hardMultiple Select

VCP-DCV vSphere Security Practice Question

A vSphere administrator needs to ensure that vCenter Server can authenticate users against an Active Directory over LDAP identity source. The environment uses vCenter Server 7.0. Which two configurations are required to successfully add the identity source? (Choose two.)

⚠ Common exam trap

The trap here is assuming that a CA certificate is always required for LDAP, when it is only needed for LDAPS or StartTLS, which are not specified.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Provide the bind user's credentials with sufficient privileges to read the directory.

To add an Active Directory over LDAP identity source in vCenter Server 7.0, you must provide the base DN for searches and a bind user with read access. These allow vCenter Server to query the directory for authentication. IWA is a different identity source type, FIPS mode is unrelated, and a trusted CA certificate is only needed if using LDAPS, which is not specified here.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Upload a trusted root CA certificate for the LDAP server's SSL certificate.

    Why it's wrong here

    If the LDAP server uses LDAPS (LDAP over SSL), a trusted certificate may be needed to establish a secure connection. However, the question does not specify LDAPS; it says Active Directory over LDAP, which can use plain LDAP or StartTLS. While a CA certificate might be required for secure LDAP, it is not always mandatory for basic LDAP authentication. The two essential configurations are base DN and bind credentials.

  • ✓

    Provide the bind user's credentials with sufficient privileges to read the directory.

    Why this is correct

    vCenter Server uses a bind user to connect to the LDAP directory and search for users and groups. The bind user must have read access to the directory. Without valid credentials, the identity source cannot be queried. This is a required configuration for Active Directory over LDAP. The bind user can be a dedicated service account with minimal read-only privileges.

  • ✗

    Configure the identity source to use Integrated Windows Authentication (IWA).

    Why it's wrong here

    IWA is an alternative authentication method for Active Directory, but it is not required for Active Directory over LDAP. In fact, IWA is a separate identity source type. The question specifies Active Directory over LDAP, which uses LDAP bind. IWA would be used if you select Active Directory (Integrated Windows Authentication) as the source, but that is not the case here. Therefore, this is not required.

  • ✗

    Enable FIPS mode on vCenter Server before adding the identity source.

    Why it's wrong here

    FIPS mode enforces cryptographic standards but is not a prerequisite for adding an LDAP identity source. While FIPS mode can be enabled for compliance, it does not affect the ability to configure LDAP authentication. The identity source configuration requires correct server URL, base DN, and bind credentials, not FIPS. Enabling FIPS is independent and not required for this task.

  • ✓

    Specify the base distinguished name (DN) for user and group searches.

    Why this is correct

    The base DN defines the starting point in the LDAP directory for user and group searches. Without it, vCenter Server cannot locate users or groups. It is a mandatory field when adding an Active Directory over LDAP identity source. The base DN must be correct to ensure authentication works, and it is typically the domain root or an organizational unit.

About these practice questions

One of 281 original VCP-DCV practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official VMware exam blueprint

This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.