VCP-DCV Configure and Manage vSphere Storage Practice Question
A vSphere environment uses an iSCSI storage array with multiple targets. The administrator configures CHAP authentication but some hosts fail to connect. The working hosts are configured with mutual CHAP, while the failing hosts use only one-way CHAP. What is the most likely reason for the failures?
⚠ Common exam trap
Many candidates assume CHAP configuration is binary (enabled or disabled) and overlook the distinction between one-way and mutual CHAP, leading them to incorrectly select a missing secret or target name issue.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The storage array requires mutual CHAP, but the failing hosts are configured for one-way CHAP.
Mutual CHAP requires the target to authenticate the initiator and the initiator to authenticate the target. If the storage array is configured to require mutual CHAP, hosts using only one-way CHAP will fail to complete the authentication handshake. The working hosts are configured with mutual CHAP, confirming the array enforces mutual authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The CHAP secret is not set on the failing hosts.
Why it's wrong here
An unset secret would fail authentication entirely, but the failing hosts do present one-way CHAP credentials while working hosts use mutual CHAP, so the direction mismatch explains the split. Setting a secret is the right fix when a host has no credentials configured at all, not when CHAP mode differs.
- ✓
The storage array requires mutual CHAP, but the failing hosts are configured for one-way CHAP.
Why this is correct
Mutual CHAP requires authentication in both directions: the host authenticates to the target and the target authenticates to the host. The working hosts supply both sets of credentials, whereas one-way CHAP sends only the initiator's credentials, so the array's reverse challenge fails.
- ✗
The iSCSI target name is incorrect on the failing hosts.
Why it's wrong here
A wrong target name would prevent connection regardless of CHAP mode, yet these hosts authenticate one-way while working hosts use mutual CHAP, so the mismatch is the authentication direction the array demands. Target naming is genuinely worth checking when discovery fails, but it does not explain a pattern tied to CHAP mode.
- ✗
The storage array is configured to use only one-way CHAP.
Why it's wrong here
If the array accepted only one-way CHAP, the mutual-CHAP hosts would fail, not the one-way ones; the stem shows the reverse. One-way CHAP is legitimately configured when only the initiator authenticates, so it would be correct if the array required initiator-only authentication rather than bidirectional verification.
Go deeper
Related to this question
About these practice questions
Courseiva writes every VCP-DCV question from scratch — 281 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.