Courseiva
vSphere Security →easyMultiple Choice

VCP-DCV vSphere Security Practice Question

A vSphere administrator wants to prevent users in a custom role from powering off virtual machines that have Fault Tolerance enabled. Which privilege must be removed from the custom role?

⚠ Common exam trap

VCP-DCV often tests the exact privilege name for a given operation, and candidates may confuse similar-sounding privileges like Suspend, Reset, or PowerOn with PowerOff, leading to incorrect answers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VirtualMachine.Interrupt.PowerOff

The privilege VirtualMachine.Interrupt.PowerOff directly controls the ability to power off a virtual machine, including those with Fault Tolerance enabled. Removing this privilege from a custom role prevents users from performing a power-off operation on any VM, including FT-protected ones. Other privileges like Suspend, Reset, or PowerOn do not govern the power-off action, so they are irrelevant to this requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VirtualMachine.State.Suspend

    Why it's wrong here

    VirtualMachine.State.Suspend controls suspending a VM, a distinct state operation from powering off, so the power-off privilege remains granted. It is tempting because suspend also halts a running VM, but Fault Tolerance protection is terminated by power-off, not by suspend.

  • ✓

    VirtualMachine.Interrupt.PowerOff

    Why this is correct

    Removing VirtualMachine.Interrupt.PowerOff directly blocks the power-off action on any VM the role applies to, including Fault Tolerance–enabled ones. Fault Tolerance itself imposes no separate privilege gate, so the standard power-off privilege is the sole control satisfying the stem's constraint.

  • ✗

    VirtualMachine.Interrupt.Reset

    Why it's wrong here

    VirtualMachine.Interrupt.Reset controls resetting a VM, which restarts rather than powers it off, so the power-off privilege stays granted. It is tempting because reset also disrupts a running VM, but the stem requires blocking power-off specifically, which Reset does not govern.

  • ✗

    VirtualMachine.Interrupt.PowerOn

    Why it's wrong here

    VirtualMachine.Interrupt.PowerOn governs powering a VM on, not off, so removing it leaves power-off rights intact. It is tempting because it sits in the Interrupt privilege group alongside the correct power-off privilege, but it does not control the action the administrator must block.

About these practice questions

Courseiva writes every VCP-DCV question from scratch — 281 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official VMware exam blueprint

This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.