Courseiva

VMware Certified Professional Data Center Virtualization VCP-DCV (VCP-DCV) — Questions 1–75

281 questions total · 4pages · All types, answers revealed

Page 1 of 4

Page 2
1
MCQeasy

An administrator needs to expand a VMFS5 datastore that is currently 2 TB in size. The underlying LUN is 5 TB. What is the maximum size the datastore can be expanded to without involving additional LUNs?

A.64 TB
B.5 TB
C.4 TB
D.2 TB
AnswerB

VMFS5 removed the 2 TB extent limit, so a single extent can span the full underlying LUN. Expanding the datastore to the LUN's full 5 TB capacity requires no additional extents, directly satisfying the constraint of avoiding extra LUNs.

Why this answer

VMFS5 supports datastore sizes up to 64 TB, but the datastore cannot exceed the size of its underlying LUN. Since the LUN is 5 TB, the maximum the datastore can be expanded to without adding LUNs is 5 TB.

Exam trap

VCP-DCV often tests the difference between the maximum supported VMFS datastore size (64 TB) and the actual expandable size, which is limited by the underlying LUN — candidates frequently pick 64 TB without checking the LUN size.

How to eliminate wrong answers

Option A is wrong because 64 TB is the theoretical maximum VMFS5 datastore size, but it is constrained by the underlying LUN size, which is only 5 TB here. Option C is wrong because 4 TB is not a VMFS5 limit — VMFS5 supports larger than 2 TB with the appropriate block size and is not capped at 4 TB. Option D is wrong because 2 TB is the current size, not the maximum expandable size; the datastore can grow up to the LUN size of 5 TB.

2
MCQhard

Refer to the exhibit. An administrator attempts to apply this cluster image to an ESXi 8.0.1 cluster, but the image validation fails. What is the most likely cause?

A.The 'nmlx5-core' component version is incompatible with the selected ESXi base image.
B.The vendor addon 'VXLAN/5.6.0' is not compatible with ESXi 8.0.1.
C.The firmware section is empty.
D.The 'Intel-i40en' component is missing a critical bug fix.
AnswerB

VXLAN 5.6.0 is designed for ESXi 7.x and is not supported on ESXi 8.0.1.

Why this answer

The vendor addon 'VXLAN/5.6.0' is explicitly listed as incompatible with the ESXi 8.0.1 base image. In vSphere Lifecycle Management, a cluster image consists of an ESXi base image, optional vendor addons, and firmware/driver components. If a vendor addon version is not certified or supported for the selected base image version, image validation will fail.

The error indicates that the VXLAN addon version 5.6.0 does not meet compatibility requirements for ESXi 8.0.1.

Exam trap

The trap here is that candidates often assume validation failures are caused by missing firmware or driver bugs, but vLCM strictly enforces vendor addon compatibility with the base image, and an empty firmware section is permissible.

How to eliminate wrong answers

Option A is wrong because the 'nmlx5-core' component version is not inherently incompatible with the ESXi 8.0.1 base image; the error message specifically points to the vendor addon, not a core driver. Option C is wrong because an empty firmware section does not cause image validation failure; firmware is optional and can be added later via a hardware support manager (HSM) or left empty without blocking validation. Option D is wrong because the 'Intel-i40en' component missing a critical bug fix would not cause a validation failure; missing bug fixes are typically flagged as warnings or non-critical issues, not hard validation errors.

3
MCQeasy

An administrator wants to limit the amount of CPU resources a single VM can consume in a vSphere cluster. Which feature should be used?

A.CPU affinity
B.CPU reservation
C.Resource pools
D.CPU limit
AnswerD

A CPU limit caps the maximum CPU MHz a virtual machine may consume, directly restricting its resource usage. Shares only affect contention priority and reservations guarantee a minimum, so neither bounds peak consumption. The limit therefore satisfies the requirement to cap a single VM's CPU consumption.

Why this answer

A CPU limit sets an upper bound on the amount of physical CPU resources a VM can consume, expressed in MHz. When the VM reaches the limit, it is throttled even if the host has idle capacity. This directly addresses the requirement to cap a single VM's CPU consumption.

Exam trap

VCP-DCV often tests the confusion between reservations (minimum guarantee) and limits (maximum cap) — candidates frequently pick reservation when the question asks to restrict maximum consumption.

How to eliminate wrong answers

Option A is wrong because CPU affinity pins a VM to specific physical cores; it controls placement, not consumption ceiling, and can actually reduce performance by preventing scheduling flexibility. Option B is wrong because a CPU reservation guarantees a minimum MHz but does not cap maximum usage — the VM can still consume all available host CPU. Option C is wrong because resource pools aggregate and allocate CPU shares/limits across multiple VMs; while a pool can have a limit, the question asks about limiting a single VM, and pools are an organizational construct, not a per-VM cap.

4
MCQmedium

An administrator wants to use vLCM to manage firmware for a cluster of Dell PowerEdge servers. What is required?

A.Manual download of firmware ISOs
B.Dell OpenManage Enterprise
C.vSphere Update Manager baseline
D.vCenter Server with vLCM and hardware support manager (HSM)
AnswerD

vLCM manages firmware only through a hardware support manager (HSM) plugin, such as Dell's, registered with a vCenter Server. Without both vCenter and the vendor HSM, firmware compliance and remediation for PowerEdge hosts cannot run.

Why this answer

To use vLCM to manage firmware for a cluster of Dell PowerEdge servers, you need vCenter Server with vLCM and a hardware support manager (HSM). The HSM is a vSphere Installation Bundle (VIB) provided by the hardware vendor (in this case, Dell) that integrates with vLCM to provide firmware updates. Dell's HSM is typically delivered as part of the Dell OpenManage integration, but the core requirement is the HSM plugin registered with vLCM.

Exam trap

VCP-DCV often tests the misconception that vLCM can manage firmware without a vendor-provided hardware support manager, or that a standalone tool like OpenManage Enterprise is sufficient, when the HSM integration with vCenter is the actual requirement.

How to eliminate wrong answers

Option A is wrong because manual download of firmware ISOs is the traditional out-of-band method and is not how vLCM manages firmware; vLCM automates firmware updates via the HSM. Option B is wrong because while Dell OpenManage Enterprise may be part of the ecosystem, the specific requirement for vLCM firmware management is the hardware support manager (HSM) integrated with vCenter, not the standalone OpenManage Enterprise appliance. Option C is wrong because vSphere Update Manager baselines are for software updates, not firmware, and vLCM image-based management with an HSM is required for firmware.

5
Multi-Selecthard

An administrator is configuring a distributed switch with LACP. Which two statements are true regarding LACP support on vSphere distributed switches? (Choose two.)

Select 2 answers
A.LACP supports both active and passive modes.
B.LACP automatically distributes traffic based on IP hash.
C.LACP can be configured on standard vSwitches.
D.LACP requires a Link Aggregation Group (LAG) to be created on the distributed switch.
E.LACP is only supported for virtual machine traffic, not for management or vMotion.
AnswersA, D

LACP on a vSphere distributed switch supports both active and passive negotiation modes, letting the ESXi host initiate or await LACPDU exchange with the physical switch. This satisfies the stem's requirement for a true statement about LACP support.

Why this answer

Option A is correct because vSphere distributed switches support LACP in both active and passive modes, allowing the ESXi host to either initiate LACPDU negotiation (active) or respond to the physical switch's negotiation (passive). Option D is correct because LACP on a vSphere distributed switch requires creating a Link Aggregation Group (LAG), which is then bound to a distributed port group or uplink port group to aggregate multiple uplinks. Option B is incorrect because IP hash is a static NIC teaming load-balancing policy, not an LACP behavior; LACP uses a dynamic link aggregation hashing scheme.

Option C is incorrect because LACP is only supported on vSphere distributed switches, not on standard vSwitches. Option E is incorrect because LACP LAGs can carry management, vMotion, and VM traffic, not just virtual machine traffic.

Exam trap

VCP-DCV often tests the misconception that LACP works on standard vSwitches or that it uses IP hash automatically, when in fact it requires a distributed switch and a LAG.

6
MCQeasy

A vSphere administrator is configuring a vSphere Standard Switch (vSS) on an ESXi host. The host has two physical NICs, vmnic0 and vmnic1, connected to the same physical switch. The administrator wants to provide network redundancy for the VM network and ensure that if one uplink fails, traffic continues to flow. Which failover detection method should be used?

A.Beacon probing
B.Link status only
C.Route based on physical NIC load
D.Route based on IP hash
AnswerB

Link status only detects failures based on the physical link state of the uplink. If a cable is unplugged or the switch port goes down, the link status changes and failover occurs. This method is simple and works well when the physical switch is configured correctly, as it detects failures at the physical layer. It is the default and recommended for most scenarios where beacon probing is not needed.

Why this answer

For a vSphere Standard Switch, the failover detection method can be either link status only or beacon probing. Link status only is the simplest and most common method, detecting failures based on the physical link state. Beacon probing is used for more complex failure detection but is not required for basic redundancy.

The other options are teaming policies, not failover detection methods. Therefore, link status only is the correct choice.

Exam trap

The trap here is confusing teaming policies with failover detection methods; beacon probing is a detection method, but it is not necessary for simple link failure detection.

7
MCQeasy

What is the maximum number of paths that vSphere supports for a single storage device?

A.8
B.256
C.32
D.4
AnswerC

32 paths is the documented ceiling vSphere supports per single storage device, satisfying the stem's constraint on maximum path count. This limit applies across FC, iSCSI and SAS arrays, where the Pluggable Storage Architecture's path selection modules manage all available routes to a given LUN without exceeding that figure.

Why this answer

vSphere supports up to 32 paths per storage device. 4 paths is common for some arrays, 8 is typical but not the maximum, and 256 is too high.

8
MCQeasy

An administrator wants to ensure that no user can view or modify VMs in a particular folder except the folder owner. What is the proper method to achieve this?

A.Use the No Access permission on the folder for all other users.
B.Assign the folder owner with Administrator role on the folder.
C.Create a global role that denies access to all VMs except the folder owner.
D.On the folder, assign permissions to the folder owner with the desired role and ensure propagation is set to 'All children'.
AnswerD

Correct. Assigning the folder owner the desired role on the folder with propagation set to 'All children' ensures the owner has the necessary permissions on the folder and all VMs within it, while other users, lacking explicit permissions, cannot view or modify the VMs.

Why this answer

To restrict access so only the folder owner can view or modify VMs in a folder, you assign the owner the desired role on the folder and set propagation to 'All children'. This ensures the permission is inherited by all VMs and sub-objects within the folder, giving the owner the necessary rights while others without explicit permissions are denied by default.

Exam trap

VCP-DCV often tests the misconception that vSphere supports explicit deny permissions — candidates who pick 'No Access' or a 'deny role' misunderstand that vSphere permissions are purely additive and inherited, with no deny mechanism.

How to eliminate wrong answers

Option A is wrong because vSphere permissions are additive and there is no explicit 'deny' — assigning No Access to all other users is impractical and does not scale, and it does not grant the owner access. Option B is wrong because assigning the Administrator role grants full administrative rights, which is excessive and does not restrict others; the requirement is about scoping access to the owner, not elevating them to admin. Option C is wrong because vSphere does not support global deny roles — roles are collections of privileges, and permissions are granted, not denied, so a 'deny' role cannot be created.

9
Multi-Selectmedium

Which TWO statements accurately describe vSphere Lifecycle Manager (vLCM) image-based management features?

Select 2 answers
A.An image includes ESXi version, firmware/driver version, and additional components.
B.Only vendor-specific images from OEMs are supported.
C.A single vLCM image can be applied to a maximum of 10 hosts in a cluster.
D.Offline bundles can be imported to create a custom image for the cluster.
E.Multiple images can be assigned to different hosts within the same cluster.
AnswersA, D

An image is the declarative desired-state specification for a cluster, bundling the ESXi base version, firmware and driver add-ons, and additional components into one artefact. This satisfies the stem's requirement that image-based management unifies all software layers, rather than patching them separately.

Why this answer

Options A and D are correct. Image-based management in vLCM uses a single image per cluster, which includes ESXi version, firmware/driver versions, and additional components (A). Offline bundles can be imported to create custom images (D).

Option B is incorrect because you can use custom images, not only vendor-specific ones. Option C is incorrect because there is no limit of 10 hosts; a single image applies to all hosts in the cluster. Option E is incorrect because only one image can be assigned per cluster.

10
Drag & Dropmedium

Place the steps to create a resource pool in a cluster.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Creating a resource pool in a vSphere cluster involves first initiating the creation by right-clicking the cluster and selecting New Resource Pool, then providing a name, followed by configuring CPU and memory resources including shares, reservation, and limit, optionally enabling expandable reservation, and finally confirming by clicking OK. This sequence ensures all required parameters are set before finalizing the resource pool.

11
MCQhard

An administrator manages a vSAN cluster with 5 ESXi hosts in a single failure domain. The cluster uses vSAN version 8 and is configured with a single disk group per host. A storage policy is applied to a group of VMs with 'Number of failures to tolerate = 1' and 'Primary level of failures = Host'. One host experiences a catastrophic hardware failure and is now marked as 'Absent' in the vSAN cluster. The administrator checks the vSAN health and finds that the affected host's disk group is completely lost. One of the VMs from that group previously had two replicas on different hosts and a witness component on a third host. The VM is still powered on, and the administrator sees that one replica was on the failed host. The other replica and witness are on surviving hosts. What is the current state of this VM regarding data accessibility?

A.The VM is accessible but performance is degraded because the disk group on the failed host is gone.
B.The VM is inaccessible because the lost replica cannot be rebuilt without a replacement host.
C.The VM is inaccessible because the witness component is now the only copy and cannot be used for reads.
D.The VM is fully accessible because it still has one replica and the witness.
AnswerD

With failures-to-tolerate of 1, one surviving replica plus the witness maintains quorum and satisfies the policy, so the object remains accessible. The absent host's lost disk group does not break availability while the remaining replica and witness are reachable.

Why this answer

With 'Number of failures to tolerate = 1' and 'Primary level of failures = Host', vSAN ensures that a VM has at least one full replica and a witness when one host fails. The VM still has one replica and the witness on surviving hosts, so it remains fully accessible. The witness acts as a tiebreaker for quorum but does not store VM data; the remaining replica provides data access.

Exam trap

VCP-DCV often tests vSAN failure tolerance and component states, and candidates may incorrectly assume that loss of a replica makes the VM inaccessible, forgetting that the witness and remaining replica allow continued access.

How to eliminate wrong answers

Option A is wrong because the VM is not just accessible but fully accessible; performance degradation is not inherent when one replica is lost, as the remaining replica can serve reads and writes. Option B is wrong because the VM can be rebuilt later, but it is not inaccessible now; the remaining replica allows access. Option C is wrong because the witness is not a copy of data and cannot be used for reads, but the VM still has a full replica, so it is accessible.

12
MCQmedium

A vSphere cluster has DRS enabled with 'Partially automate' mode. A VM is consistently showing high CPU ready time. The administrator wants to ensure the VM is automatically migrated to a less loaded host. What must be done?

A.Enable EVC mode on the cluster
B.Set the VM's DRS automation level to 'Automatic'
C.Set the VM's DRS automation level to 'Manual'
D.Enable HA admission control
AnswerB

Partially automated DRS only generates migration recommendations; it never moves the VM itself. Setting the VM's automation level to Automatic lets DRS execute migrations, satisfying the requirement to relocate the VM away from the loaded host.

Why this answer

In a DRS cluster with 'Partially automate' mode, the cluster-wide automation level is overridden by per-VM settings. To ensure a VM is automatically migrated for load balancing, the VM's DRS automation level must be set to 'Automatic'. This allows DRS to perform migrations without manual intervention for that VM.

Exam trap

VCP-DCV often tests DRS automation levels, and candidates may confuse cluster-wide settings with per-VM overrides, or think that enabling EVC or HA affects DRS load balancing.

How to eliminate wrong answers

Option A is wrong because EVC mode is used for CPU compatibility across hosts, not for DRS automation. Option C is wrong because setting the VM to 'Manual' would require manual approval for migrations, which does not meet the requirement for automatic migration. Option D is wrong because HA admission control is related to ensuring resources for failover, not for DRS load balancing.

13
Matchingmedium

Match each vSphere component to its primary function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Centralized management of ESXi hosts and VMs

Hypervisor that runs VMs

Interface for managing vCenter and ESXi

Live migration of VMs without downtime

Automatic restart of VMs after host failure

Why these pairings

The correct matches: vCenter Server is the centralized management platform; ESXi is the hypervisor; vSphere vMotion enables live migration; vSphere HA provides high availability. Common confusions include mixing up management functions with migration or HA features.

14
MCQmedium

An administrator is configuring a new iSCSI storage array for a vSphere cluster. The array supports multiple iSCSI targets. What is the recommended best practice for multipathing to ensure high availability and load balancing?

A.Use the management VMkernel port for iSCSI traffic to simplify configuration.
B.Create multiple VMkernel ports for iSCSI, each bound to a separate physical NIC, and configure multiple iSCSI targets.
C.Configure a single physical NIC with multiple VLANs for iSCSI traffic.
D.Use a single VMkernel port for iSCSI and assign multiple IP addresses to it.
AnswerB

Multipathing requires multiple VMkernel ports, each bound to a distinct physical NIC, so vSphere can present separate paths to the array. Configuring multiple iSCSI targets across those paths enables both failover and load balancing, satisfying the high-availability constraint.

Why this answer

VMware best practices for iSCSI multipathing require multiple VMkernel ports, each bound to a separate physical NIC, and multiple iSCSI targets to provide both path redundancy and load balancing. This configuration leverages the Pluggable Storage Architecture (PSA) and native multipathing plugins (NMP) to distribute I/O across active paths while maintaining high availability through automatic path failover. Using separate VMkernel ports and NICs ensures that no single point of failure exists in the storage network.

Exam trap

The trap here is that candidates often confuse logical separation (VLANs or multiple IPs on one NIC) with true physical path redundancy, leading them to select options that appear to provide multipathing but actually create a single point of failure.

How to eliminate wrong answers

Option A is wrong because using the management VMkernel port for iSCSI traffic violates the principle of network isolation and can cause performance contention, as management and storage traffic share the same network stack and resources. Option C is wrong because configuring a single physical NIC with multiple VLANs for iSCSI traffic does not provide true multipathing; a single NIC failure would still cause complete storage connectivity loss, and VLANs alone do not create separate physical paths. Option D is wrong because a single VMkernel port with multiple IP addresses does not create independent paths; all traffic still traverses the same physical NIC and network stack, offering no redundancy or load balancing.

15
MCQmedium

An administrator wants to replicate a critical VM to a remote site with a Recovery Point Objective (RPO) of 15 minutes. Which vSphere feature should be used?

A.Storage vMotion
B.vSphere Replication
C.vSphere vMotion
D.Site Recovery Manager (SRM)
AnswerB

vSphere Replication performs asynchronous, hypervisor-based replication with configurable recovery points as low as five minutes, satisfying the 15-minute RPO constraint. Unlike array-based replication, it needs no shared storage or identical arrays at the remote site, so it works with any supported datastore and replicates at the VM level.

Why this answer

vSphere Replication is the correct feature because it provides asynchronous replication of VMs to a remote site with an RPO as low as 15 minutes. It operates at the VM level and is included with vSphere, making it suitable for this requirement without additional licensing for SRM.

Exam trap

VCP-DCV often tests the difference between vSphere Replication and Site Recovery Manager, where candidates may choose SRM for replication, but SRM is for orchestration and requires a replication mechanism.

How to eliminate wrong answers

Option A is wrong because Storage vMotion is used for live migration of VM storage within a site, not for replication to a remote site. Option C is wrong because vSphere vMotion is for live migration of VMs between hosts within a site, not for remote replication. Option D is wrong because Site Recovery Manager (SRM) is a disaster recovery orchestration solution that requires vSphere Replication or array-based replication, but SRM itself is not the replication mechanism; it manages recovery plans.

The question asks for the feature to replicate, so vSphere Replication is the direct answer.

16
MCQhard

A company is designing a vSphere environment for a critical database application. The storage array supports both Fibre Channel (FC) and iSCSI. The application requires low latency and high IOPS. Which storage protocol and path policy should be recommended?

A.FC with Fixed path policy.
B.FC with Most Recently Used (MRU) path policy.
C.iSCSI with Round Robin path policy.
D.FC with Round Robin path policy.
AnswerD

Fibre Channel provides dedicated, lossless transport with lower latency and higher sustained IOPS than iSCSI over Ethernet. Round Robin spreads I/O across all active paths, maximising throughput and balancing load, which satisfies the database's low-latency, high-IOPS requirement.

Why this answer

FC provides lower latency and higher IOPS than iSCSI due to dedicated hardware and lower protocol overhead, making it ideal for critical database workloads. The Round Robin path policy is recommended for FC with active-active storage arrays because it distributes I/O across all available paths, maximizing throughput and load balancing, which aligns with the requirement for high IOPS.

Exam trap

The trap here is that candidates often assume MRU is the default for FC or that Fixed is sufficient, but the VCP-DCV exam tests the understanding that Round Robin is the recommended path policy for active-active arrays to achieve load balancing and high IOPS, especially for performance-sensitive workloads like databases.

How to eliminate wrong answers

Option A is wrong because the Fixed path policy uses a single preferred path and only switches on failure, which does not optimize for high IOPS or load balancing across multiple paths. Option B is wrong because the Most Recently Used (MRU) path policy is designed for active-passive arrays and can cause path thrashing or suboptimal performance in active-active environments, failing to meet low-latency and high-IOPS needs. Option C is wrong because iSCSI typically incurs higher latency and CPU overhead compared to FC due to TCP/IP processing, making it less suitable for a critical database application requiring low latency and high IOPS.

17
MCQhard

Refer to the exhibit. An administrator configures a claim rule to use VMW_SATP_ALUA with VMW_PSP_RR and TPGS enabled. After applying the rule, the device shows one active and one standby path. However, the administrator notices that I/O is only sent to the active path. What is the most likely reason?

A.The PSP should be changed to VMW_PSP_MRU to use both paths.
B.The array is not properly configured to present both paths as active/optimized.
C.The claim rule should have used VMW_SATP_DEFAULT_AA instead.
D.The TPGS option should be disabled to force both paths active.
AnswerB

Round robin only distributes I/O across paths the array reports as active/optimised. If the array presents one path as standby rather than both active/optimised, the PSP sends I/O solely to the active path, matching the observed behaviour.

Why this answer

VMW_PSP_RR (Round Robin) with TPGS (Target Port Group Support) enabled only distributes I/O across paths that the array reports as Active/Optimized. If the array presents one path as Active/Optimized and the other as Standby, RR will still send I/O only to the optimized path because ALUA state dictates path usage. The array's target port group configuration must mark both paths as Active/Optimized for RR to load-balance across them.

Exam trap

VCP-DCV often tests the misconception that VMW_PSP_RR always load-balances across all visible paths; in reality, with ALUA and TPGS, RR only uses paths the array marks Active/Optimized, so array-side TPG configuration is the deciding factor.

How to eliminate wrong answers

Option A is wrong because VMW_PSP_MRU (Most Recently Used) does not load-balance across paths; it simply uses the most recently active path and only fails over on path loss, so it would not achieve dual-path I/O. Option C is wrong because VMW_SATP_DEFAULT_AA is for arrays that do not support ALUA and treat all paths as active/active; using it with an ALUA array would ignore the array's asymmetric access states and could cause path thrashing or I/O errors. Option D is wrong because disabling TPGS would prevent ESXi from honoring the array's ALUA target port group states, which is required for correct RR behavior with ALUA arrays; it would not force both paths active.

18
Multi-Selecthard

Which TWO statements about vCenter Single Sign-On (SSO) are true? (Choose two.)

Select 2 answers
A.It supports multiple identity sources such as Active Directory and LDAP
B.It uses Kerberos to authenticate users to vCenter Server
C.It stores user passwords in plaintext for faster authentication
D.It requires a Windows Active Directory domain to function
E.It uses SAML 2.0 tokens for authentication between vCenter services
AnswersA, E

vCenter SSO federates authentication by connecting to external identity sources, including Active Directory over LDAP or Integrated Windows Authentication, and native LDAP directories. This satisfies the stem's requirement for a true SSO statement, since SSO's core function is brokering credentials across vSphere components via configured identity sources rather than storing accounts locally.

Why this answer

Option A is correct because vCenter Single Sign-On supports multiple identity sources, including Active Directory (integrated Windows authentication), LDAP, and local SSO identity sources, allowing authentication against different user directories. Option E is correct because SSO issues SAML 2.0 tokens that are used to authenticate and authorize users across vCenter services and other vSphere components, enabling single sign-on without re-entering credentials. Option B is not correct because SSO does not rely on Kerberos as its authentication mechanism; it uses SAML tokens and can use various identity sources, though Kerberos may be involved in some Active Directory scenarios, it is not the defining authentication method.

Option C is not correct because SSO does not store user passwords in plaintext; credentials are handled securely and passwords are not stored in plaintext for authentication. Option D is not correct because SSO does not require a Windows Active Directory domain; it can function with local SSO users or other supported identity sources such as LDAP.

Exam trap

VCP-DCV often tests whether candidates know SSO is identity-source-agnostic (not AD-only) and that SAML 2.0 — not Kerberos — is the token protocol between vCenter services, so candidates who overgeneralize Kerberos pick the wrong option.

19
MCQmedium

An administrator is planning a storage upgrade for a vSphere cluster. The cluster currently uses VMware vSAN as the primary datastore. The administrator wants to add capacity to the vSAN datastore without adding additional hosts. Which action should the administrator take?

A.Replace existing disks in each host with larger capacity disks and claim them to the same disk group
B.Combine disks from different hosts into a single disk group
C.Add a new disk group on each host with additional capacity disks
D.Add a new VMFS datastore and use Storage vMotion to move VMs
AnswerC

Adding a new disk group with additional capacity disks on each existing host expands the vSAN datastore's usable capacity without provisioning new hosts. vSAN aggregates local disks across cluster members, so each host must contribute disks to increase overall datastore size.

Why this answer

Adding a new disk group on each host with additional capacity disks directly increases vSAN datastore capacity without requiring host replacement. This method allows you to add new capacity disks while preserving existing disk groups and data placement policies. Option A is incorrect because replacing existing disks with larger ones, while possible, typically requires data evacuation or is more disruptive, and it is not the recommended approach when disk slots are available.

Option B is invalid because disk groups are per-host; combining disks across hosts is not supported. Option D does not increase vSAN capacity and introduces a different datastore type.

Exam trap

The trap is that candidates might assume replacing disks (Option A) is the only method to increase capacity, overlooking that adding a new disk group (Option C) is a standard and often simpler approach that avoids data migration.

How to eliminate wrong answers

Option B is wrong because vSAN disk groups are per-host constructs; combining disks from different hosts into a single disk group is not supported by vSAN architecture, as each host maintains its own disk groups. Option C is wrong because adding a new disk group on each host with additional capacity disks would require available disk slots and may exceed the maximum number of disk groups per host (typically 5), but more importantly, it does not address the scenario where the administrator wants to add capacity without adding hosts—this option does add capacity but is not the only valid method; however, the question implies a simple capacity increase, and replacing disks is more straightforward and avoids potential disk group limits. Option D is wrong because adding a new VMFS datastore does not increase the vSAN datastore capacity; it creates a separate datastore that would require Storage vMotion to move VMs, which does not solve the requirement of adding capacity to the existing vSAN datastore.

20
Multi-Selecthard

Which two of the following are characteristics of the vSphere Enhanced vMotion Compatibility (EVC) feature? (Choose two.)

Select 2 answers
A.It is configured at the host level
B.It allows vMotion between hosts of different CPU generations within the same cluster
C.It enables memory overcommit by default
D.It masks CPU features to a baseline level across all hosts in the cluster
E.It requires all VMs to be powered off before enabling
AnswersB, D

EVC presents a uniform CPU feature set to guest VMs, so a VM running on one host generation can be migrated to another generation within the cluster without exposing unsupported instructions. This directly satisfies the requirement for vMotion compatibility across differing CPU generations.

Why this answer

Option B is correct because EVC's core purpose is to enable vMotion (and DRS) between ESXi hosts with different CPU generations by presenting a common, compatible CPU feature set within the same cluster. Option D is correct because EVC achieves this by masking (hiding) newer CPU features from VMs so that all hosts in the cluster expose a uniform baseline CPU feature set, allowing live migration across mixed hardware. Option A is incorrect because EVC is configured at the cluster level (via the cluster's EVC settings), not per individual host.

Option C is incorrect because memory overcommit is a separate memory-management behavior controlled by host/VM memory settings and reservations, not a default effect of EVC. Option E is incorrect because EVC can typically be enabled on a cluster without powering off all VMs, provided the hosts are compatible; it does not require all VMs to be powered off.

Exam trap

VCP-DCV often tests that EVC is cluster-level, not host-level, and that it masks CPU features, not enables memory overcommit, so candidates must distinguish between CPU compatibility and memory management features.

21
MCQmedium

A vSphere administrator is troubleshooting intermittent performance degradation on a production VM. The VM resides on a datastore backed by a storage array that is also serving several other clusters. The administrator needs to determine whether the latency is caused by the storage array or by the ESXi host's storage stack. Which esxtop metric should be compared to the array's reported latency to make this determination?

A.DAVG (device average latency) in the device view of esxtop
B.GAVG (guest average latency) in the virtual machine view of esxtop
C.QAVG (queue average latency) in the virtual machine view of esxtop
D.KAVG (kernel average latency) in the device view of esxtop
AnswerA

DAVG in the device view reports the average latency of I/O operations as measured by the ESXi host's storage stack. Comparing DAVG to the array's own reported latency helps isolate whether the delay originates in the host stack or at the array. A significant discrepancy suggests host-side queuing or path issues, while matching values point to the array.

Why this answer

The device view of esxtop provides DAVG, which is the average latency of I/O operations as seen by the ESXi host. By comparing DAVG with the storage array's own latency statistics, an administrator can determine whether the bottleneck is within the host's storage stack or the array itself. This is a standard method for isolating storage performance issues in vSphere.

Exam trap

The trap here is confusing the various latency metrics in esxtop (KAVG, DAVG, GAVG) and assuming that the guest-level latency is the best indicator of array performance.

22
MCQmedium

An administrator is configuring a distributed switch for a cluster of ESXi hosts. The requirements are: VLAN 100 for production, VLAN 200 for management, and a separate VLAN 300 for vMotion. The management network should be isolated from production traffic. What is the best practice for configuring these networks on the distributed switch?

A.Create three separate distributed port groups, each with the appropriate VLAN ID, and assign each VM kernel adapter or VM to the correct port group.
B.Create one distributed port group with VLAN 100, and use VLAN tagging on the VMs for management and vMotion.
C.Use standard switches for management and vMotion to avoid complexity.
D.Create one distributed port group with VLAN trunk (4095) and use port-based VLAN filtering on the VMs.
E.Create two port groups: one for production (VLAN 100) and one for management+vMotion (VLAN 200) because vMotion can share VLAN with management.
AnswerA

Three distributed port groups with VLAN IDs 100, 200 and 300 keep production, management and vMotion traffic logically separated at layer 2, isolating management from production while letting each VMkernel adapter or VM attach to its correct segment.

Why this answer

Best practice on a vSphere Distributed Switch is to create one distributed port group per VLAN/network function, each with its own VLAN ID, and attach the appropriate VMkernel adapters (management, vMotion) or VM vNICs to the correct port group. This provides clean traffic isolation, simplifies troubleshooting, and aligns with VMware's recommended design for separating management, vMotion, and production traffic.

Exam trap

VCP-DCV often tests the misconception that guest OS VLAN tagging or trunk port groups can substitute for properly segmented distributed port groups — candidates must remember VMkernel traffic cannot be VLAN-tagged at the guest level.

How to eliminate wrong answers

Option B is wrong because using a single port group with VLAN 100 and relying on guest-level VLAN tagging for management/vMotion is not possible for VMkernel traffic — VMkernel adapters cannot tag VLANs in the guest, and this would mix management traffic into the production VLAN. Option C is wrong because reverting to standard switches defeats the purpose of a distributed switch and adds management complexity, not reduces it. Option D is wrong because VLAN 4095 is a trunk port group that passes all VLANs untagged to the guest; using guest-based VLAN filtering is unsupported for VMkernel traffic and creates security/segmentation risks.

Option E is wrong because vMotion and management should be isolated per VMware best practice; sharing a VLAN is allowed but not recommended, and the question explicitly requires isolation of management from production.

23
MCQmedium

A vSphere cluster has 10 ESXi hosts configured with vSphere DRS. The administrator wants to ensure that a group of VMs running a latency-sensitive application are always placed on the same host. Which DRS rule should be created?

A.VM-to-Host affinity rule with a 'should run on hosts in group' constraint.
B.VM-VM affinity rule with a 'must run on the same host' constraint.
C.VM-VM affinity rule with a 'should run on the same host' constraint.
D.VM-VM anti-affinity rule with a 'separate VMs' constraint.
AnswerB

A VM-VM affinity rule with 'must run on the same host' pins the latency-sensitive VMs together, keeping inter-VM traffic on-host and avoiding inter-host network hops. DRS still balances other workloads, but never separates members of this rule.

Why this answer

A VM-VM affinity rule with the 'must run on the same host' constraint is the only DRS rule type that guarantees the specified VMs are co-located on a single ESXi host. This is exactly what a latency-sensitive application requiring inter-VM communication on the same physical host needs, since it eliminates network hops between hosts. The 'must' (required) constraint makes DRS treat the rule as mandatory, preventing any placement that would separate the VMs.

Exam trap

VCP-DCV often tests the distinction between 'must' (required) and 'should' (preferential) DRS rules, and between VM-VM affinity versus VM-to-Host affinity — candidates must match the constraint type to the requirement.

How to eliminate wrong answers

Option A is wrong because a VM-to-Host affinity rule binds VMs to a host group, not to each other — it does not guarantee the VMs share a single host, only that they run within the specified host group. Option C is wrong because a 'should run on the same host' VM-VM affinity rule is a soft/preferential rule; DRS may violate it during balancing or when resources are constrained, so it cannot guarantee co-location for a latency-sensitive workload. Option D is wrong because a VM-VM anti-affinity rule does the opposite — it forces VMs apart onto different hosts, which would break the latency requirement.

24
MCQhard

A company runs a three-tier application on vSphere 7.0. The web tier uses VLAN 100, app tier VLAN 200, and database tier VLAN 300. Each tier is on a separate port group on a vSphere distributed switch. The environment uses Network I/O Control (NIOC) with shares set to: Web (50), App (30), Database (20). The physical uplinks are two 10 GbE NICs in a team. Recently, the database team reports slow performance during peak hours. The network team checks the physical switches and finds no congestion. The ESXi host shows the two uplinks are heavily utilized with many dropped packets on the database port group. The administrator suspects that the database traffic is being starved by other traffic. Which action should the administrator take to resolve the issue? A. Increase the number of physical uplinks to four 10 GbE NICs. B. Change the NIOC shares to Web (10), App (30), Database (60). C. Create a separate vSphere standard switch for the database tier. D. Enable SR-IOV on the physical NICs and assign virtual functions to database VMs.

A.Create a separate vSphere standard switch for the database tier.
B.Enable SR-IOV on the physical NICs and assign virtual functions to database VMs.
C.Increase the number of physical uplinks to four 10 GbE NICs.
D.Change the NIOC shares to Web (10), App (30), Database (60).
AnswerD

NIOC shares allocate relative bandwidth only under contention, and the database's share of 20 is the lowest, so its traffic is starved on the saturated uplinks. Raising database shares to 60 gives that tier proportionally more bandwidth, directly addressing the constraint.

Why this answer

The database traffic is being starved due to low NIOC shares relative to the web and app tiers. By increasing the database shares to 60 and reducing web to 10, the database port group will receive a higher proportion of the available bandwidth during congestion, alleviating the dropped packets and slow performance. NIOC shares are relative and only take effect when there is contention, so adjusting them directly addresses the starvation without requiring additional hardware.

Exam trap

The trap here is that candidates often assume adding more physical uplinks or isolating traffic on a separate switch will solve performance issues, but they overlook that NIOC shares directly control bandwidth allocation during congestion, and adjusting them is the most efficient and cost-effective solution.

How to eliminate wrong answers

Option A is wrong because increasing the number of physical uplinks to four 10 GbE NICs does not address the root cause of traffic starvation; it only adds more bandwidth, which may not help if the existing bandwidth is not being fairly allocated due to NIOC share settings. Option B is wrong because enabling SR-IOV on the physical NICs and assigning virtual functions to database VMs bypasses the vSphere network stack, but it does not resolve the contention on the shared uplinks; it could introduce complexity and is not a direct fix for NIOC share misconfiguration. Option C is wrong because creating a separate vSphere standard switch for the database tier would isolate the traffic but would still share the same physical uplinks unless dedicated uplinks are assigned, which is not mentioned; it also does not leverage NIOC's traffic shaping capabilities and may lead to underutilization of resources.

25
MCQeasy

A company manages a vSphere cluster of 200 ESXi hosts using vSphere Lifecycle Manager baselines (baseline-based remediation). They decide to migrate to vLCM image-based management. The administrator selects one host as a reference host, generates a cluster image from it, and attempts to apply the image to the entire cluster. Most hosts remediate successfully, but 20 hosts fail with the error: "Image deployment failed: Error retrieving VIBs from repository." The failed hosts are all from a different hardware vendor than the reference host but are on the vSphere HCL. The administrator confirms that the repository URL is reachable from the failed hosts and that there are no network connectivity issues. What should the administrator do first to resolve the issue?

A.Check the vLCM cluster image for any components specific to the reference host's hardware that are not present in the failed hosts.
B.Reboot the failed hosts and retry the remediation.
C.Verify that the failed hosts have sufficient disk space in the /scratch partition.
D.Manually upload the required VIBs to the local depot on each failed host.
AnswerA

The image likely includes hardware-specific VIBs from the reference host that are incompatible or missing for the other hardware models; removing unnecessary components resolves the issue.

Why this answer

The error 'Error retrieving VIBs from repository' when applying a cluster image generated from a reference host indicates that the image contains hardware-specific VIBs (e.g., drivers, CIM providers) that are present on the reference host but not compatible with the failed hosts from a different hardware vendor. vLCM cluster images are derived from the reference host's software specification, including any vendor-specific components, and when applied to hosts lacking that hardware, the VIB retrieval fails because the repository does not contain matching VIBs for those hosts. The first step is to check the cluster image for such components and remove or replace them with hardware-independent versions to ensure compatibility across the heterogeneous cluster.

Exam trap

The trap here is that candidates often assume network or repository issues are the cause, but the error specifically points to VIB retrieval failure due to incompatible hardware-specific components in the image, not connectivity problems.

How to eliminate wrong answers

Option B is wrong because rebooting the hosts does not address the root cause of missing or incompatible VIBs in the image; it would only retry the same failing operation. Option C is wrong because insufficient disk space in /scratch would typically cause a different error (e.g., 'Insufficient disk space'), not a VIB retrieval failure from a repository, and the administrator already confirmed network connectivity. Option D is wrong because manually uploading VIBs to a local depot is unnecessary and bypasses vLCM's centralized image management; the correct approach is to modify the cluster image to remove hardware-specific components, not to manually stage VIBs on each host.

26
MCQmedium

An administrator is configuring role-based access control in a vSphere 8 environment with a single vCenter Server. A user must be able to create and delete virtual machines in a specific cluster, but must not be able to modify the cluster's HA or DRS settings. Permissions should be assigned at the cluster level and must not propagate to other clusters. Which approach should the administrator take?

A.Assign the built-in Administrator role to the user on the cluster so that VM creation and deletion are permitted, and rely on the cluster boundary to prevent changes to other clusters.
B.Create a custom role that includes the Virtual machine > Inventory > Create and Remove permissions plus the Host > Configuration > HA and DRS permissions, and assign it to the user on the cluster.
C.Create a custom role with the Virtual machine > Inventory > Create and Remove permissions, and assign it to the user on the vCenter Server root folder with propagation enabled.
D.Create a custom role with only the Virtual machine > Inventory > Create and Remove permissions, and assign it to the user on the cluster without selecting the propagate option.
AnswerD

A custom role containing only the Virtual machine > Inventory > Create and Remove permissions allows the user to create and delete VMs without granting host configuration privileges. Assigning the role at the cluster level without propagation scopes the permission to that cluster and prevents it from being inherited by other clusters or by objects within them, which matches the requirement precisely. This follows least privilege while meeting the operational need.

Why this answer

Least privilege requires a custom role with only the Virtual machine > Inventory > Create and Remove privileges, because those are the operations the user needs. Assigning the role at the cluster level without propagation confines the permission to that cluster, so other clusters are unaffected. Including HA and DRS privileges or using the built-in Administrator role would grant excessive rights, and assigning at the root folder with propagation would spread the permission too broadly.

Exam trap

The trap here is assuming that assigning a role at the cluster level automatically prevents changes to cluster configuration, when the role's privileges, not the assignment scope, determine what actions are allowed.

27
MCQhard

An administrator is troubleshooting a virtual machine that experiences intermittent performance issues. The VM is configured with 8 vCPUs and 32 GB memory. The administrator runs esxtop and sees that the %RDY for the VM is consistently above 20%. What does this indicate?

A.The VM is contending for CPU resources due to overallocation of vCPUs.
B.The VM's virtual disks are experiencing high latency.
C.The VM is experiencing memory ballooning.
D.The VM is using its CPU resources efficiently.
AnswerA

%RDY above 20% means the VM's virtual CPUs wait in the scheduler queue before receiving physical CPU time. With 8 vCPUs, the VM needs eight free logical cores simultaneously, so an overcommitted host causes ready time to climb, confirming CPU contention from vCPU overallocation.

Why this answer

High %RDY indicates that the VM is ready to run but is waiting for CPU resources, meaning the CPU scheduler cannot allocate physical cores quickly enough. This is typically caused by over-allocation of vCPUs relative to available physical cores, leading to contention. Option A correctly identifies this condition.

Option B is incorrect because high %RDY is not related to disk latency; disk latency is measured by other metrics like DAVG/GAVG. Option C is incorrect because memory ballooning is a memory management technique, not directly indicated by %RDY. Option D is incorrect because high %RDY signifies inefficient CPU scheduling, not efficient utilization.

28
Drag & Dropmedium

Arrange the steps to create a new virtual machine in vSphere Client.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The standard workflow: initiate creation, choose type, name/place, select compute, then storage and settings.

29
MCQmedium

Refer to the exhibit. An administrator tries to enable vSAN on a host and receives this error. What is the most likely cause?

A.The vSAN cluster has insufficient hosts (needs at least 2).
B.The host does not have any disks installed.
C.The host has disks but they are not claimed for vSAN or not configured in a disk group.
D.The host's disks are all SSD and vSAN requires HDD for capacity tier.
AnswerC

vSAN requires local disks to be claimed and assigned to a disk group before it can be enabled. Unclaimed or ungrouped disks leave no storage capacity for the vSAN datastore, so the enable operation fails until the administrator creates a disk group.

Why this answer

vSAN requires at least one disk group consisting of one or more capacity disks (and optionally a cache disk). The error indicates that no disk group is present or the disks are not properly claimed.

30
MCQhard

A company has a vSphere cluster with 10 ESXi hosts managed by vLCM. They use a custom image that includes a third-party network driver. After updating the image to include a new version of the driver, remediation fails on all hosts with the error: 'The software specification contains a VIB that is not compatible with the host platform.' What is the most likely cause?

A.The new driver VIB is not compatible with the ESXi version in the image.
B.The vLCM image depot is corrupted.
C.The hosts have incompatible firmware.
D.The custom image is not signed by VMware.
AnswerA

The VIB compatibility error means the driver targets a different ESXi platform than the image's base version. vLCM validates each VIB against the host's ESXi build, so a driver built for another release fails remediation before installation.

Why this answer

The error 'The software specification contains a VIB that is not compatible with the host platform' indicates that the VIB (vSphere Installation Bundle) in the custom image is not designed to run on the ESXi version specified in the image. vLCM validates VIB compatibility against the ESXi base image version, and a third-party driver VIB must be built for that exact ESXi build. Since the new driver version is incompatible with the ESXi version, remediation fails on all hosts.

Exam trap

The trap here is that candidates often assume the error is about signing or corruption, but vLCM specifically checks VIB-to-platform compatibility at the VIB metadata level, not the image's signature or depot integrity.

How to eliminate wrong answers

Option B is wrong because a corrupted vLCM image depot would typically cause download or checksum errors, not a specific VIB compatibility message. Option C is wrong because incompatible firmware would generate hardware-related errors (e.g., driver/firmware mismatch), not a VIB platform compatibility error. Option D is wrong because vLCM does not require custom images to be signed by VMware; it only validates VIB acceptance levels (e.g., VMwareCertified, PartnerSupported) and host acceptance levels, not a VMware signature on the entire image.

31
MCQhard

Refer to the exhibit. An administrator notices that two uplinks are down on the VDS. Which step should be taken first to restore redundancy?

A.Check the physical switch ports and cables for uplink2 and uplink3.
B.Increase the MTU to 9000 to improve performance.
C.Disable LACP on the VDS to allow single-uplink operation.
D.Remove the down uplinks from the VDS.
AnswerA

Physical connectivity issues are the most common cause of down uplinks.

32
MCQmedium

A vSphere administrator is troubleshooting connectivity issues for a virtual machine that is unable to communicate with other VMs on the same VLAN. The VM is connected to a distributed port group on a vSphere Distributed Switch (vDS). The administrator verifies that the VM's IP configuration is correct and that the port group is configured with the correct VLAN ID. However, the VM can only communicate with other VMs on the same ESXi host. What is the most likely cause?

A.The vDS is not configured with a VLAN trunking policy.
B.The VM's network adapter is configured with the wrong MAC address.
C.The distributed port group has forging transmits set to reject.
D.The physical switch ports connecting the ESXi hosts are not configured as trunk ports for the VLAN.
AnswerD

A distributed port group carries its VLAN tag to the physical switch, which must trunk that VLAN to reach VMs on other hosts. Without trunking, frames stay confined to the local host's uplink, matching the symptom of same-host-only communication despite correct VM and port group settings.

Why this answer

If the VM can communicate with other VMs on the same ESXi host but not with VMs on other hosts in the same VLAN, the issue is almost certainly that the physical switch ports connecting the ESXi hosts are not configured as trunk ports carrying that VLAN. The vDS and port group are correctly configured, so the failure is at the physical uplink layer where VLAN tags must be allowed to pass between hosts.

Exam trap

VCP-DCV often tests whether candidates blame the vDS configuration when the real fault is upstream on the physical switch — remember that intra-host success with inter-host failure points to the physical uplink/trunk, not the virtual switch.

How to eliminate wrong answers

Option A is wrong because a vDS does not require a global 'VLAN trunking policy' to be enabled for a single-VLAN port group to work — VLAN tagging is set per port group, and the symptom is host-to-host, not trunk-related. Option B is wrong because a wrong MAC address would typically cause the VM to fail all communication, not selectively fail only cross-host traffic. Option C is wrong because 'forging transmits set to reject' blocks MAC address spoofing, not normal VM-to-VM traffic on the same VLAN.

33
MCQeasy

A vSphere administrator needs to ensure that a critical VM restarts automatically if the ESXi host fails. Which feature should be configured?

A.vSphere vMotion
B.vSphere HA
C.vSphere DRS
D.vSphere Fault Tolerance
AnswerB

vSphere HA continuously monitors ESXi hosts and restarts their VMs on surviving hosts in the cluster after a host failure. This directly satisfies the requirement for automatic VM restart, which DRS alone does not provide.

Why this answer

vSphere HA (High Availability) is specifically designed to automatically restart VMs on another host in the cluster if the original ESXi host fails. It monitors host and VM health and provides rapid recovery without manual intervention. This directly meets the requirement for automatic restart after host failure.

Exam trap

VCP-DCV often tests the distinction between HA (restart after failure) and FT (continuous availability), catching candidates who pick FT for simple restart requirements or confuse DRS with HA.

How to eliminate wrong answers

Option A is wrong because vMotion is a live migration technology that moves running VMs between hosts manually or via DRS, but it does not automatically restart VMs after a host failure. Option C is wrong because DRS (Distributed Resource Scheduler) balances workloads across hosts for performance, not for failure recovery. Option D is wrong because Fault Tolerance provides continuous availability by running a shadow copy of the VM on another host, but it is not a restart mechanism and has strict limits (e.g., single vCPU).

34
MCQhard

A financial institution operates a vSphere 7.0 environment with three vCenter Servers in linked mode, each managing separate clusters. The company uses vSAN encryption with an external KMS appliance from a third-party vendor. The KMS appliance has a certificate that expires every two years. The storage administrator recently renewed the KMS certificate as per the vendor's instructions. After the renewal, the vCenter Server's 'Key Management Servers' view shows the KMS status as 'Unhealthy'. The administrator attempts to decrypt a test virtual machine, but the operation fails with an error: 'No key providers are available'. The KMS appliance is reachable from the vCenter Server, and the new certificate is installed on the KMS. The administrator has confirmed that the KMS IP address and port are correctly configured in vCenter. What is the most likely cause of the failure?

A.The vSAN encryption keys were lost during the certificate renewal
B.The KMS cluster in vCenter needs to be recreated
C.The new KMS certificate has not been imported into the vCenter Server trust store
D.The vCenter Server services need to be restarted
AnswerC

vCenter validates the KMS server's certificate against its trust store. Renewing the certificate creates a new certificate chain, so the old trusted entry no longer matches, leaving the KMS Unhealthy and no key providers available. Importing the renewed certificate restores trust.

Why this answer

The most likely cause is that the new KMS certificate was not imported into the vCenter Server trust store. Even though the KMS appliance is reachable and the new certificate is installed on the KMS, vCenter Server must trust the KMS certificate to establish a secure connection. Without the certificate in the trust store, vCenter considers the KMS unhealthy, leading to the 'No key providers are available' error.

The vSAN encryption keys are not lost during certificate renewal—they remain stored on the KMS. Recreating the KMS cluster is unnecessary because the configuration is still valid, and restarting vCenter services would not resolve the trust issue.

35
MCQeasy

An administrator needs to provide redundancy for VM traffic across multiple physical NICs on a vSphere Standard Switch. Which NIC teaming policy should be used to ensure fault tolerance without load balancing?

A.Route based on IP hash
B.Route based on originating virtual port
C.Use explicit failover order (Active/Standby)
D.Route based on source MAC hash
AnswerC

Explicit failover order with Active/Standby keeps one NIC passing traffic and holds the others as standby, providing fault tolerance without distributing load. Other policies such as route based on originating port ID actively load balance, which the requirement excludes.

Why this answer

The 'Use explicit failover order (Active/Standby)' policy designates one or more NICs as active and the rest as standby, providing pure fault tolerance without any load balancing. When the active NIC fails, traffic automatically fails over to the standby NIC, ensuring redundancy without distributing traffic across multiple uplinks.

Exam trap

The trap here is that candidates often confuse 'fault tolerance without load balancing' with load-balancing policies like IP hash or source MAC hash, mistakenly thinking any teaming policy provides redundancy, but only the explicit failover order ensures a single active path with no traffic distribution.

How to eliminate wrong answers

Option A is wrong because 'Route based on IP hash' uses a hash of source and destination IP addresses to distribute traffic across multiple active NICs, which provides load balancing but not pure fault tolerance without load balancing. Option B is wrong because 'Route based on originating virtual port' distributes traffic based on the virtual switch port ID, which also load-balances across active NICs and does not guarantee a single active path for fault tolerance. Option D is wrong because 'Route based on source MAC hash' uses the source MAC address to distribute traffic across multiple active NICs, again providing load balancing rather than the required fault tolerance without load balancing.

36
MCQeasy

A small business is deploying a new vSphere environment with three ESXi hosts and a vCenter Server Appliance. They need to ensure that if one ESXi host fails, the VMs on that host are restarted on the remaining hosts. They also want to minimize downtime and avoid manual intervention. Which vSphere feature should they configure?

A.vSphere High Availability (HA)
B.vSphere Fault Tolerance (FT)
C.vSphere Replication
D.vSphere Distributed Resource Scheduler (DRS)
AnswerA

vSphere HA monitors ESXi hosts and restarts VMs on other hosts in the cluster if a host fails. It provides automatic failover with minimal downtime, exactly matching the requirement. It does not require manual intervention and works across the cluster to ensure VM availability.

Why this answer

vSphere HA is designed to automatically restart VMs on remaining hosts when an ESXi host fails. It detects host failures and performs failover without manual intervention, ensuring minimal downtime. DRS, FT, and Replication serve different purposes and do not provide automatic restart on host failure.

Exam trap

The trap here is confusing DRS, which balances workloads, with HA, which restarts VMs after host failure.

37
MCQhard

A large financial institution runs a vSphere 7.0 environment with 100 ESXi hosts and 2,000 VMs. The security team has identified that several VMs are vulnerable to a critical side-channel attack that requires disabling hyperthreading on the ESXi hosts. The administrator needs to implement a solution that minimizes performance impact while ensuring compliance. The environment uses DRS clusters with varying workloads: some VMs are CPU-intensive (financial modeling) and others are memory-bound (database servers). The administrator cannot afford to take hosts offline for maintenance during business hours. The change must be implemented within 48 hours. Which course of action should the administrator take?

A.Use a vSphere DRS rule to disable hyperthreading for all VMs in the cluster, avoiding the need to modify host BIOS.
B.Place each host in maintenance mode individually, disable hyperthreading in the host BIOS, reboot the host, and then move to the next host. Rebalance VMs after all hosts are updated.
C.Delay the change and schedule a maintenance window for the next month when business impact is lower.
D.Disable hyperthreading on all hosts simultaneously using a vSphere Cluster feature, then reboot all hosts at once during off-peak hours.
AnswerB

Hyperthreading is a BIOS setting, so disabling it requires a host reboot. Sequentially placing each host in maintenance mode lets DRS evacuate VMs to remaining hosts, avoiding downtime, then rebalancing after all 100 hosts are updated within the 48-hour window.

Why this answer

Disabling hyperthreading to mitigate side-channel attacks (e.g., L1TF or MDS) requires a host BIOS change, which necessitates a reboot. The only supported method in vSphere 7.0 is to place each host into maintenance mode, change the BIOS setting, reboot, and then repeat for all hosts. This approach minimizes performance impact by allowing VMs to be migrated via vMotion and avoids simultaneous downtime, meeting the 48-hour requirement without taking all hosts offline during business hours.

Exam trap

The trap here is that candidates mistakenly believe hyperthreading can be disabled via a vSphere software setting (like a DRS rule or cluster feature) without a host reboot, when in reality it requires a physical BIOS change and reboot per host.

How to eliminate wrong answers

Option A is wrong because vSphere DRS rules cannot disable hyperthreading at the VM or host level; hyperthreading is a hardware feature controlled only via BIOS or host-level CPU configuration, and DRS rules only influence VM placement and resource allocation. Option C is wrong because delaying the change for a month violates the explicit requirement to implement the fix within 48 hours, and the security vulnerability demands immediate remediation. Option D is wrong because there is no vSphere Cluster feature to disable hyperthreading across all hosts simultaneously; disabling hyperthreading requires a BIOS change and reboot per host, and rebooting all hosts at once would cause total cluster downtime, violating the constraint of no business-hour outages.

38
MCQeasy

Which switch type requires a separate vCenter Server to manage its configuration?

A.Virtual Edge Gateway Switch
B.vSphere Distributed Switch
C.vSphere Standard Switch
D.vSphere Edge Switch
AnswerB

A vSphere Distributed Switch is configured and managed through vCenter Server, satisfying the stem's separate-management constraint. Its control plane resides in vCenter, which pushes configuration to host proxies; a vSphere Standard Switch is configured per host with no vCenter dependency.

Why this answer

The vSphere Distributed Switch (VDS) requires a separate vCenter Server to manage its configuration because the VDS is a centralized virtual switch that spans multiple ESXi hosts, and its configuration is stored in the vCenter Server database rather than on individual hosts. Without vCenter, the VDS cannot be created, configured, or managed, as the ESXi hosts rely on vCenter to synchronize the distributed port group settings and network policies across the cluster.

Exam trap

The trap here is that candidates often confuse the vSphere Standard Switch (VSS) with the vSphere Distributed Switch (VDS), assuming both can be managed without vCenter, but the VDS explicitly requires vCenter for any configuration changes, while the VSS can be managed directly on the ESXi host.

How to eliminate wrong answers

Option A is wrong because a Virtual Edge Gateway Switch is not a standard VMware vSphere switch type; it is a component of VMware NSX (specifically the NSX Edge Gateway) used for north-south traffic routing and firewall services, and it does not require a separate vCenter Server for its configuration—it is managed through the NSX Manager, which itself integrates with vCenter. Option C is wrong because the vSphere Standard Switch (VSS) is a host-level virtual switch that is configured locally on each ESXi host using the vSphere Client directly connected to the host or via vCenter, but it does not require a separate vCenter Server to manage its configuration; each VSS is independent and its settings are stored on the individual ESXi host. Option D is wrong because a vSphere Edge Switch is not a recognized VMware product or switch type; the correct term is the NSX Edge virtual router or the VDS, and there is no standalone 'vSphere Edge Switch' that requires vCenter.

39
MCQmedium

During a cluster upgrade using vLCM, the pre-check reports that Quick Boot is disabled. How does this affect the upgrade?

A.Quick Boot speeds up reboot
B.No effect
C.Hosts will reboot normally
D.Upgrade will fail
AnswerC

Quick Boot being disabled means the host performs a full BIOS/UEFI POST during reboot rather than skipping hardware initialisation. The vLCM pre-check flags this only as a warning, not a blocker, so remediation proceeds and each host restarts through its normal boot path, satisfying the cluster upgrade without additional configuration.

Why this answer

Quick Boot is a vSphere feature that speeds up host reboots by skipping certain hardware initialization steps, but it is not required for an upgrade. If the vLCM pre-check reports Quick Boot is disabled, the upgrade can still proceed; hosts will simply perform a normal reboot, which takes longer. The pre-check is informational, not a blocker.

Exam trap

The trap is assuming a pre-check warning about Quick Boot is a hard failure; candidates may pick 'upgrade will fail' when in fact it only affects reboot speed and the upgrade proceeds normally.

How to eliminate wrong answers

Option A is wrong because while Quick Boot does speed up reboot, the question asks how its absence affects the upgrade, not what it does. Option B is wrong because there is an effect: the reboot will be a normal, slower reboot rather than a quick one. Option D is wrong because a disabled Quick Boot does not cause the upgrade to fail; it only changes reboot behavior.

40
MCQhard

A vSphere cluster using vSAN is experiencing high latency for some VMs. The administrator checks the vSAN skyline health and finds that all disk groups are healthy. Which additional step should the administrator take to diagnose the issue?

A.Verify that the vSAN network is configured with jumbo frames.
B.Enable vSAN encryption to improve performance.
C.Increase the number of disk groups on each host.
D.Check the vSAN performance service for object latency breakdown.
AnswerD

The vSAN performance service provides per-object latency breakdowns, satisfying the stem's need to diagnose latency when disk groups are healthy. It isolates whether VM, disk group or backend component latency causes the issue, which skyline health alone cannot reveal.

Why this answer

The vSAN Performance Service provides granular, real-time and historical metrics for vSAN objects, including latency breakdowns at the VM, disk group, and physical disk levels. Since the skyline health check shows all disk groups as healthy, the next logical step is to use the Performance Service to pinpoint whether the high latency is due to congestion on a specific object, such as a VM virtual disk or a particular disk group component, rather than a hardware failure.

Exam trap

The trap here is that candidates assume a healthy skyline health check means there is no underlying performance issue, but vSAN skyline health primarily checks for hardware failures and configuration compliance, not performance bottlenecks, so they must use the Performance Service for latency analysis.

How to eliminate wrong answers

Option A is wrong because jumbo frames (MTU 9000) can improve network throughput but are not a diagnostic step; they are a configuration optimization that may reduce CPU overhead but do not directly reveal the source of latency. Option B is wrong because vSAN encryption adds CPU overhead and can increase latency, not improve performance; it is a security feature, not a performance tuning tool. Option C is wrong because increasing the number of disk groups per host can improve performance by distributing I/O, but it is a capacity planning or reconfiguration action, not a diagnostic step to identify the root cause of existing high latency.

41
Multi-Selectmedium

An administrator is configuring role-based access control in vCenter Server 7.0. A new security policy requires that users can only view the inventory and cannot perform any changes. The administrator creates a custom role with only read-only privileges. Which two actions must the administrator take to ensure the role is effective for a group of users? (Choose two.)

Select 2 answers
A.Grant the users the 'Administrator' role at the root folder to ensure they can see all objects.
B.Ensure the users are members of an Active Directory group that is added to vCenter Single Sign-On as a group.
C.Set the users' login to use a read-only mode in the vSphere Client.
D.Assign the role to the users on the root folder with 'Propagate to children' enabled.
E.Assign the role to the users on each individual VM and host object.
AnswersB, D

For the role to apply to a group of users, the group must be recognized by vCenter Single Sign-On. Adding the Active Directory group as a vSphere SSO group allows permissions to be assigned to that group. Then, assigning the role to the group at the root folder with propagation grants all members the desired access. Without SSO group configuration, the group cannot be used in permission assignments.

Why this answer

To grant a group of users read-only access to the entire vCenter inventory, the administrator must first ensure the group is known to vCenter Single Sign-On, typically by adding the Active Directory group as an SSO group. Then, the read-only role should be assigned to that group at the root folder with 'Propagate to children' enabled. This ensures all group members inherit view-only permissions on all current and future objects.

Individual assignments or overly permissive roles do not meet the requirement efficiently or securely.

Exam trap

The trap here is forgetting that vCenter permissions require the group to be recognized by SSO before it can be assigned a role, and assuming that assigning at the root without propagation is sufficient.

42
MCQeasy

An administrator is designing a new vSphere environment and wants to minimize manual effort for patching and upgrade. Which lifecycle management approach should they choose for vSphere 8 clusters?

A.Use vSphere baselines for granular control.
B.Enable vLCM for all clusters.
C.Use vSphere Update Manager for standalone hosts.
D.Use vLCM only for large clusters with more than 32 hosts.
AnswerB

vLCM applies desired-state images across the cluster, remediating hosts automatically to match the baseline, which directly satisfies the requirement to minimise manual patching and upgrade effort. Unlike baselines that merely report drift, vSphere Lifecycle Manager enforces convergence, so vSphere 8 clusters stay compliant without per-host intervention.

Why this answer

vSphere Lifecycle Manager (vLCM) with desired-state image management is the recommended approach in vSphere 8 for minimizing manual patching and upgrades. Enabling vLCM for all clusters lets administrators define a single image (base ESXi version plus firmware and drivers) and remediate hosts to match it, automating compliance across the cluster. This reduces manual effort compared to legacy baselines.

Exam trap

The trap is choosing legacy baselines or Update Manager out of familiarity — the exam tests that vLCM with desired-state images is the modern, recommended approach for minimizing manual patching across all vSphere 8 clusters, not just large ones.

How to eliminate wrong answers

Option A is wrong because vSphere baselines are the legacy Update Manager approach that requires more manual baseline/group management and does not provide the desired-state image model of vLCM. Option C is wrong because vSphere Update Manager is the older component superseded by vLCM, and using it for standalone hosts does not address cluster-wide lifecycle automation. Option D is wrong because vLCM is not limited to clusters with more than 32 hosts; it is recommended for all clusters regardless of size, and restricting it to large clusters misses the automation benefit.

43
MCQeasy

An administrator sees this health check output. What should be done to verify VLAN 100 connectivity?

A.Create a VMkernel adapter on VLAN 100 and ping a gateway.
B.Enable VLAN pruning on the physical switch.
C.Configure a port group for VLAN 100 and connect a VM.
D.Restart the management agents.
AnswerA

Placing a VMkernel adapter on VLAN 100 and pinging its gateway tests Layer 2 tag propagation and Layer 3 reachability end to end. This directly verifies whether VLAN 100 traffic passes the physical switch, which a health check alone cannot confirm.

Why this answer

To verify VLAN 100 connectivity at the ESXi host level, the administrator must create a VMkernel adapter tagged with VLAN 100 on the distributed or standard switch and then ping a gateway or another host in that VLAN. This tests the host's own L2/L3 path for that VLAN without involving a guest VM. It directly validates that the physical switch trunk, VLAN tagging, and uplink configuration are correct.

Exam trap

VCP-DCV often tests whether candidates know to verify host-level VLAN connectivity with a VMkernel adapter rather than a VM, confusing guest-level testing with host-level validation.

How to eliminate wrong answers

Option B is wrong because enabling VLAN pruning on the physical switch is a configuration change, not a verification step, and pruning could actually break VLAN 100 rather than confirm connectivity. Option C is wrong because connecting a VM to a VLAN 100 port group tests guest connectivity, not the host's own VLAN path, and adds variables (guest OS, NIC driver) that obscure the host-level check. Option D is wrong because restarting management agents does not test VLAN 100 connectivity and is a disruptive action unrelated to L2 reachability verification.

44
MCQeasy

A vSphere administrator is deploying a new cluster of 5 ESXi hosts, each with 128 GB of RAM, and plans to run 50 VMs with 4 GB of RAM each. The administrator wants to ensure that the cluster can sustain the failure of one host without significantly impacting performance. Which configuration should the administrator implement to meet this requirement?

A.Configure vSphere HA with the 'Dedicated failover hosts' admission control policy and designate one host as failover.
B.Configure vSphere HA with the 'Cluster resource percentage' admission control policy and set it to 20%.
C.Configure vSphere HA with the default admission control policy.
D.Enable vSphere DRS and set the automation level to Fully Automated.
AnswerB

The cluster has 5 hosts, so losing one host means losing 20% of the cluster's resources. Setting the admission control policy to reserve 20% of cluster resources ensures that enough capacity remains to run all VMs after a single host failure. This policy allows HA to admit VMs only if the remaining resources can accommodate them, thus maintaining performance. It is the most appropriate setting for this scenario.

Why this answer

The cluster has 5 hosts, so a single host failure removes 20% of total resources. Configuring vSphere HA with a cluster resource percentage admission control policy set to 20% ensures that HA reserves enough capacity to restart all VMs on the remaining hosts without overcommitting resources. This maintains performance after a failure.

Other policies either do not guarantee sufficient capacity or reduce normal operating capacity.

Exam trap

The trap here is assuming that any HA admission control policy will suffice, when the percentage must match the actual resource loss (20% for one of five hosts) to avoid overcommitment after failover.

45
MCQhard

During a vLCM health check, an administrator sees that the health status for a cluster is 'Error' with the message: 'Unable to connect to the depot service at https://depot.vmware.com'. The cluster is configured to use the online depot. What is the most likely cause?

A.DNS resolution is failing for the vCenter server.
B.The vCenter server's certificate is expired.
C.A firewall is blocking outbound HTTPS access to the internet.
D.The cluster image has an invalid URL.
AnswerC

Blocked outbound TCP 443 traffic prevents the vLCM depot sync from reaching depot.vmware.com, so the online depot health check fails with a connection error. Since the cluster is configured to use the online depot, no local source exists to fall back on, making firewall filtering of HTTPS the most likely cause.

Why this answer

The most likely cause is that a firewall is blocking outbound HTTPS access to the internet, preventing vCenter from reaching the VMware depot at https://depot.vmware.com. The error message explicitly indicates a connection failure to the depot service, and since the cluster uses the online depot, outbound connectivity is required. Firewall rules blocking port 443 are a common cause in secured environments.

Exam trap

VCP-DCV often tests the difference between connectivity issues and certificate or DNS problems; candidates may jump to certificate expiry because it's a common vCenter issue, but the specific error message points to a network block.

How to eliminate wrong answers

Option A is wrong because DNS resolution failure would typically produce a different error, such as 'Unable to resolve hostname', not a connection error to a specific URL; also, DNS is less likely to be the issue if other services are working. Option B is wrong because an expired vCenter certificate would cause trust or authentication errors, not a failure to connect to an external depot. Option D is wrong because an invalid URL in the cluster image would result in a different error, such as 'Invalid depot URL' or 'Image not found', rather than a connection failure.

46
MCQeasy

A vSphere administrator is asked to choose a lifecycle management approach for a new cluster of 100 hosts. The cluster will use vSAN and will be updated frequently. The administrator wants to minimize manual intervention and ensure consistency. Which approach should be recommended?

A.Manually update each host with the latest ESXi ISO.
B.Use vSphere Update Manager with baseline groups for updates.
C.Use vSphere Lifecycle Manager with baseline-based management.
D.Use vSphere Lifecycle Manager with image-based management.
AnswerD

Image-based management in vSphere Lifecycle Manager defines a desired-state software image per cluster, so all 100 hosts converge to one specification, including firmware and drivers. This satisfies the frequent-update and consistency constraints, and vSAN clusters are validated against the image, minimising manual intervention across hosts.

Why this answer

vSphere Lifecycle Manager (vLCM) with image-based management uses a declarative desired-state model where the entire cluster is managed from a single software image that includes ESXi base image, drivers, and firmware. This is the recommended approach for vSAN clusters because it ensures consistency across all hosts and integrates with vSAN's hardware compatibility checks, minimizing manual intervention.

Exam trap

The trap is assuming that baseline-based management is still the recommended approach — many candidates pick VUM or vLCM baselines out of familiarity, but image-based vLCM is the modern, declarative method required for consistent vSAN firmware/driver management.

How to eliminate wrong answers

Option A is wrong because manually updating 100 hosts with ISOs is error-prone, time-consuming, and does not ensure consistency or firmware/driver alignment. Option B is wrong because vSphere Update Manager (VUM) with baselines is the legacy approach and does not manage firmware or drivers as part of a unified image, and VUM has been deprecated in favor of vLCM. Option C is wrong because vLCM baseline-based management still uses the older baseline model and does not provide the declarative image-based consistency that vSAN clusters benefit from.

47
MCQeasy

A vSphere administrator is deploying a new cluster of hosts that will run virtual desktop workloads. The administrator wants to reduce memory overcommitment pressure while keeping consolidation ratios reasonable. Which vSphere feature allows the host to reclaim memory by sharing identical memory pages across virtual machines?

A.Hypervisor swap
B.Memory compression
C.Transparent Page Sharing (TPS)
D.Memory ballooning
AnswerC

Transparent Page Sharing identifies identical memory pages across VMs and maps them to a single physical page, reducing the host's memory footprint without guest involvement. In this VDI scenario, many desktops share the same OS and application binaries, so TPS can reclaim significant memory and ease overcommitment pressure while preserving consolidation ratios.

Why this answer

Transparent Page Sharing deduplicates identical memory pages across virtual machines, shrinking the host's memory footprint. For VDI clusters running many similar desktops, this directly reduces overcommitment pressure and supports higher consolidation ratios. The other mechanisms reclaim memory through guest pressure, swapping, or compression rather than sharing identical pages.

Exam trap

The trap here is confusing memory reclamation techniques that pressure the guest or swap to disk with page deduplication that shares identical pages.

48
MCQhard

An administrator notices that a VM with high I/O demands is experiencing performance issues because other VMs on the same datastore are consuming too many I/O operations. Which feature can be used to guarantee a minimum I/O share to this VM?

A.Multipathing policy
B.VM storage policy
C.Storage DRS
D.Storage I/O Control shares
AnswerD

Storage I/O Control shares guarantee a minimum I/O allocation to a virtual machine when the datastore becomes congested, directly addressing contention from other VMs. Shares are applied proportionally during contention, reserving throughput for the high-demand VM.

Why this answer

Storage I/O Control shares allow you to guarantee a minimum I/O share to a VM by assigning shares to its virtual disks. When contention occurs, ESXi enforces these shares to ensure the VM gets its fair share of I/O resources.

Exam trap

VCP-DCV often tests the confusion between Storage DRS (which balances load) and SIOC (which guarantees shares), leading candidates to choose Storage DRS for I/O prioritization.

How to eliminate wrong answers

Option A is wrong because multipathing policy determines how I/O is routed to storage, not how I/O is prioritized among VMs. Option B is wrong because VM storage policy defines storage requirements like RAID or encryption, not I/O prioritization. Option C is wrong because Storage DRS balances storage capacity and I/O load across datastores, but does not guarantee minimum I/O shares to individual VMs.

49
MCQhard

An administrator attempts to export a vLCM image but gets an error: 'Export image operation is not supported for this image'. What could be the reason?

A.The vLCM database is corrupt.
B.The image contains a custom component.
C.The image is too large.
D.The vCenter version does not support export.
AnswerB

vLCM image export is blocked when the image includes a custom component, because such components cannot be represented in the exportable image specification. Removing the custom component or using a base image allows export to succeed.

Why this answer

vLCM image export is only supported for images composed entirely of components available in the VMware depot (base image plus standard add-ons). When an image includes a custom component — for example, an OEM or third-party VIB added outside the standard depot — vCenter cannot serialize that image for export, so it returns 'Export image operation is not supported for this image'. Removing the custom component or rebuilding the image from depot-only components resolves the error.

Exam trap

VCP-DCV often tests whether candidates blame infrastructure-level causes (corruption, size, version) for an error that is actually caused by the content of the image itself — specifically a non-depot custom component.

How to eliminate wrong answers

Option A is wrong because a corrupt vLCM database would produce broad, systemic failures across image management, not a targeted 'not supported for this image' message tied to a specific image. Option C is wrong because image size is not a gating factor for export; vLCM does not reject exports based on size thresholds. Option D is wrong because export is a supported vLCM feature in the relevant vCenter versions — the error is image-specific, not version-specific.

50
Multi-Selecteasy

An organization wants to use vLCM for lifecycle management. Which three components can be managed using vLCM images? (Choose THREE)

Select 3 answers
A.ESXi version
B.vCenter Server version
C.Add-ons like drivers
D.Firmware for supported hardware
E.VMware Tools
AnswersA, C, D

ESXi version is a core component of a vLCM image, satisfying the requirement to manage host firmware and software as a single desired-state baseline. Images bundle the ESXi base image with vendor add-ons, so the hypervisor version itself is directly declared and remediated through the cluster image, not managed separately.

Why this answer

Option A (ESXi version) is correct because a vLCM image is fundamentally a declarative specification of the ESXi base image, which defines the exact ESXi version and build to be installed on hosts. Option C (Add-ons like drivers) is correct because vLCM images include add-on components such as async drivers, vendor add-ons, and components that are layered on top of the base ESXi image. Option D (Firmware for supported hardware) is correct because vLCM integrates with Hardware Support Managers (HSMs) from OEMs to include firmware and driver updates for supported servers in the image, enabling firmware compliance alongside software.

Option B (vCenter Server version) is not managed by vLCM images; vCenter Server is upgraded separately via VAMI or the CLI installer. Option E (VMware Tools) is not part of a vLCM image; it is managed per-VM through vSphere Lifecycle Manager baselines or VM hardware settings, not as an image component.

Exam trap

VCP-DCV often tests the boundary of vLCM scope — candidates confuse host-image components (ESXi, add-ons, firmware) with adjacent lifecycle items like vCenter, VMware Tools, or vSAN disk firmware, which are managed separately.

51
MCQmedium

An administrator has configured a vSphere Distributed Switch (VDS) with Network I/O Control. They need to guarantee bandwidth for a specific set of virtual machines. Which method should be used?

A.Create a port group with a custom network resource pool.
B.Enable SR-IOV on the physical NICs.
C.Set the virtual machine's network adapter to use a specific VLAN.
D.Configure Traffic Shaping on the distributed switch.
AnswerA

Network I/O Control guarantees bandwidth through network resource pools, which are assigned to distributed port groups. Creating a port group with a custom resource pool reserves shares, limits or reservations for the specific VMs placed on it.

Why this answer

Create a port group with a custom network resource pool. Network I/O Control allows administrators to create network resource pools to guarantee bandwidth for specific virtual machines or port groups. By creating a custom network resource pool and assigning it to a port group, you can reserve a certain amount of bandwidth.

Option B is incorrect because SR-IOV provides direct hardware passthrough but does not manage bandwidth guarantees; it can actually bypass Network I/O Control. Option C is incorrect because setting a VLAN tag does not guarantee bandwidth; it only separates traffic. Option D is incorrect because traffic shaping is used to limit bandwidth (throttle outgoing traffic) but does not guarantee a minimum bandwidth; it only caps it.

52
MCQeasy

A vSphere administrator is using vSphere Lifecycle Manager to manage a cluster. The cluster's desired image includes a specific ESXi base image and several components. After adding a new host to the cluster, the administrator notices that the host is non-compliant. What is the most efficient way to bring the host into compliance with the cluster's desired image?

A.Use vSphere Update Manager to create a baseline and remediate the host.
B.Manually install the same ESXi version and components on the host using an ISO image.
C.Remove the host from the cluster and re-add it after installing the correct image.
D.Use vSphere Lifecycle Manager to remediate the host.
AnswerD

vLCM can remediate individual hosts or entire clusters to bring them into compliance with the desired image. Remediation automatically installs the required ESXi version and components, ensuring the host matches the cluster's image. This is the most efficient and consistent method, as it leverages vLCM's automation and validation. Therefore, using vLCM to remediate the host is the correct approach.

Why this answer

vSphere Lifecycle Manager is designed to automate host remediation to match the cluster's desired image. Remediating the host will apply the correct ESXi base image and components, ensuring compliance. This is the most efficient and consistent method, avoiding manual errors and downtime associated with other approaches.

Exam trap

The trap here is confusing vLCM with the legacy vSphere Update Manager baseline approach, leading to the selection of baseline remediation instead of image-based remediation.

53
MCQeasy

A company plans to upgrade the ESXi hosts in their vSphere cluster from version 7.0 Update 3 to 8.0 Update 1 using vSphere Lifecycle Manager (vLCM). The cluster currently uses baseline-based management. What is the recommended approach to prepare for this upgrade?

A.Migrate the cluster to image-based management.
B.Manually upgrade each host using an ISO file.
C.Create a new baseline group and attach it to the cluster.
D.Use vMotion to migrate all VMs to another cluster before upgrading.
AnswerA

vLCM image-based management is the prerequisite for declarative firmware and driver add-on upgrades to ESXi 8.0 Update 1; baselines cannot manage firmware. Migrating the cluster first lets a single desired-state image drive the whole upgrade.

Why this answer

vSphere Lifecycle Manager (vLCM) image-based management is the recommended approach for upgrading to vSphere 8.0 Update 1 because it provides a declarative, desired-state model for the entire cluster, including firmware and drivers via Hardware Support Manager. Baseline-based management is legacy and does not support the full vLCM feature set in 8.0. Migrating the cluster to image-based management before the upgrade ensures a clean, supported path.

Exam trap

VCP-DCV often tests the distinction between baseline-based and image-based management — candidates must know that image-based is the recommended model for vSphere 8 and that baselines are legacy.

How to eliminate wrong answers

Option B is wrong because manually upgrading each host with an ISO bypasses vLCM entirely, is error-prone, and does not leverage the cluster-aware orchestration vLCM provides. Option C is wrong because creating a new baseline group keeps the cluster on baseline-based management, which is the legacy model being deprecated in favor of image-based management in vSphere 8. Option D is wrong because vMotion to another cluster is a workload evacuation step, not an upgrade preparation step — it does not address the management model change required.

54
MCQmedium

A company has a vLCM-managed cluster with a desired image that includes ESXi 8.0 U1 and multiple VIBs. After remediating, one host fails with an error: 'Failed to retrieve VIBs from depot'. What is the most likely cause?

A.The cluster has a baseline attached that conflicts with the desired image.
B.The image validation failed due to incompatible VIBs.
C.The host firmware is not compatible with the selected VIBs.
D.The vCenter Server does not have internet access to the VMware depot.
AnswerD

The error indicates vLCM cannot pull VIB payloads from the depot. If the vCenter Server lacks internet access to the VMware depot and no local depot or proxy is configured, retrieval fails during remediation, matching the stem's post-remediation host error.

Why this answer

The error 'Failed to retrieve VIBs from depot' indicates that vCenter Server cannot reach the depot from which the VIBs are sourced. In a vLCM-managed cluster using a desired image, the image specification includes VIBs that may be hosted on the VMware online depot or a local depot. If vCenter Server lacks internet access to the VMware depot, it cannot download the required VIBs, causing the remediation to fail.

This is the most likely cause because the error is specifically about retrieval, not validation or compatibility.

Exam trap

The trap here is that candidates often confuse a depot retrieval failure with image validation or compatibility issues, but the error message explicitly points to a network or depot accessibility problem, not a VIB-level conflict.

How to eliminate wrong answers

Option A is wrong because vLCM-managed clusters use desired images, not baselines; if a baseline were attached, it would conflict at the cluster level, but the error message points to depot retrieval, not a baseline conflict. Option B is wrong because image validation errors (e.g., incompatible VIBs) would produce a different error, such as 'Image compliance check failed' or 'VIB dependency error', not a depot retrieval failure. Option C is wrong because host firmware incompatibility would manifest as a hardware compatibility error during remediation, not a failure to retrieve VIBs from a depot.

55
Multi-Selectmedium

Which four types of traffic can be assigned to a separate VMkernel adapter on an ESXi host?

Select 4 answers
A.Management traffic
B.vMotion
C.vSAN
D.Virtual machine network traffic
E.Fault Tolerance logging
AnswersA, B, C, E

Management traffic is one of the four traffic types that can be placed on a dedicated VMkernel adapter, alongside vMotion, vSAN and fault tolerance. Isolating it on its own VMkernel interface separates host administration from other network flows.

Why this answer

Management traffic (A) is a valid VMkernel service that can be enabled on a dedicated VMkernel adapter to isolate host management from other traffic. vMotion (B) is also a VMkernel service that can be assigned to its own VMkernel adapter to separate live migration traffic. vSAN (C) is a VMkernel service that can be enabled on a dedicated VMkernel adapter for vSAN storage communication. Fault Tolerance logging (E) is a VMkernel service that can be assigned to a separate VMkernel adapter for FT metadata traffic. Virtual machine network traffic (D) is not a VMkernel service; it is handled by standard or distributed virtual switches and port groups, not by a VMkernel adapter.

Exam trap

VCP-DCV often tests the confusion between VMkernel services and VM port group traffic — candidates incorrectly include 'virtual machine network traffic' as a VMkernel service.

56
MCQeasy

Which storage feature in vSphere allows a VM to be migrated from one datastore to another without any downtime?

A.vMotion
B.Distributed Resource Scheduler (DRS)
C.Storage DRS
D.Storage vMotion
AnswerD

Storage vMotion relocates a virtual machine's files between datastores while the VM remains powered on and running, satisfying the no-downtime constraint. Compute vMotion moves the VM between hosts instead, and neither cold nor suspended migration avoids an outage.

Why this answer

Storage vMotion is the correct answer because it enables live migration of a virtual machine's virtual disk files from one datastore to another with zero downtime. It uses a mirrored copy mechanism where the source and destination datastores are synchronized before the VM is switched to the destination, ensuring continuous VM availability.

Exam trap

The trap here is confusing vMotion (host migration) with Storage vMotion (datastore migration), as both are live migration technologies but operate on entirely different resources.

How to eliminate wrong answers

Option A is wrong because vMotion migrates a running VM between ESXi hosts, not between datastores; it moves the VM's memory and CPU state, not its storage. Option B is wrong because Distributed Resource Scheduler (DRS) balances compute resources across hosts by recommending or initiating vMotion migrations, but it does not handle storage migrations. Option C is wrong because Storage DRS provides initial placement and ongoing load balancing of VMs across datastores, but it relies on Storage vMotion to perform the actual migration; Storage DRS itself does not execute the migration.

57
MCQmedium

An administrator manages a vSphere 8 cluster with vSphere Lifecycle Manager (vLCM) using a single image. The cluster contains hosts from two different server vendors. The administrator attempts to add a firmware add-on to the image but receives an error that the add-on is not compatible with all hosts. What is the most likely cause?

A.The hosts are not in maintenance mode, so vLCM cannot validate the firmware add-on.
B.The cluster uses a single image, but the firmware add-on is only supported on one of the server vendor models.
C.The firmware add-on requires vSphere Lifecycle Manager to be in 'baseline' mode instead of 'image' mode.
D.The firmware add-on is not included in the vLCM depot and must be downloaded from the vendor's website.
AnswerB

A single vLCM image requires all hosts to be compatible with every component, including firmware add-ons. If the add-on only supports one vendor's hardware, vLCM will flag it as incompatible with the other hosts, preventing the image from being applied uniformly.

Why this answer

vLCM images must be compatible with every host in the cluster. Firmware add-ons are hardware-specific; if they do not support all server models present, the image cannot be uniformly applied. The correct answer identifies the vendor-specific limitation as the cause of the incompatibility.

Exam trap

The trap here is assuming that any firmware add-on can be applied cluster-wide without checking per-host hardware compatibility.

58
MCQhard

An administrator is using vSphere Lifecycle Manager to manage a cluster with a single image. The cluster has a hardware support manager (HSM) configured. During remediation, the task fails on one host with the error: 'Host firmware update failed: Unable to contact BMC.' What is the most likely cause of this error?

A.The HSM is not registered correctly in vCenter Server.
B.The host's BMC network settings are misconfigured or the BMC is unreachable.
C.The host is not compatible with the firmware add-on in the desired image.
D.The host's BMC firmware is outdated and does not support the update method used by the HSM.
AnswerB

The error 'Unable to contact BMC' directly indicates that the HSM cannot reach the BMC. This could be due to incorrect IP configuration, network isolation, or BMC being down. Since it affects one host, it's likely a host-specific BMC connectivity issue. Checking BMC network settings and reachability is the correct troubleshooting step.

Why this answer

The error 'Unable to contact BMC' indicates a communication failure between the Hardware Support Manager and the host's baseboard management controller. This is typically caused by network misconfiguration, incorrect credentials, or the BMC being offline. Since it affects a single host, it's a host-specific issue.

Verifying BMC network settings and connectivity resolves the problem.

Exam trap

The trap here is interpreting the error as a compatibility or HSM registration issue, when it specifically points to BMC connectivity for that host.

59
MCQeasy

A VM configured with 4 vCPUs shows high co-stop time in performance metrics. What does co-stop time indicate and which action should be taken to improve performance?

A.Reduce the number of vCPUs to match workload requirements
B.Add more vCPUs to the VM
C.Enable hyperthreading on the host
D.Increase the VM's memory reservation
AnswerA

Co-stop measures time a vCPU spends ready but unable to run because its co-scheduled siblings are descheduled, typically from over-sized SMP virtual machines. Reducing vCPUs to match actual workload demand lowers scheduling skew and co-stop, improving throughput.

Why this answer

Co-stop time is time when the VM is ready to run but waiting for all vCPUs to be scheduled simultaneously. Reducing the number of vCPUs can alleviate this.

60
MCQeasy

A vSphere administrator wants to restrict direct console access to an ESXi host to authorized administrators only, without interrupting running virtual machines. Which feature should the administrator enable?

A.Lockdown mode
B.Enable DRS
C.Configure a host profile
D.Disable SSH service
AnswerA

Lockdown mode restricts the ESXi DCUI and SSH to users in the Exception Users list, enforced through host permissions. It applies immediately without rebooting or evacuating VMs, satisfying the constraint of restricting console access while leaving running virtual machines untouched.

Why this answer

Lockdown mode restricts direct console access to an ESXi host to only users with administrator privileges, while allowing running VMs to continue unaffected. It enforces that all management access must go through vCenter Server, enhancing security without disrupting workloads.

Exam trap

VCP-DCV often tests the difference between lockdown mode and other access controls like SSH disabling, and candidates may think disabling SSH is sufficient for console restriction.

How to eliminate wrong answers

Option B is wrong because DRS (Distributed Resource Scheduler) is for load balancing and resource allocation across hosts, not for restricting console access. Option C is wrong because a host profile is a configuration template for host settings, not an access control mechanism. Option D is wrong because disabling SSH only blocks SSH access, but does not restrict direct console access via the DCUI (Direct Console User Interface) or other methods; lockdown mode is specifically designed for that purpose.

61
MCQhard

Refer to the exhibit. What is the most likely reason the second path is in standby state?

A.The host has not successfully authenticated to the storage on that path.
B.The path is not properly zoned to the storage.
C.The storage array reports that path as non-optimized.
D.The multipathing policy is set to Fixed (VMW_PSP_FIXED).
AnswerC

When an array presents one path as non-optimized, the PSA selects the optimized path as active and places the non-optimized path in standby. This asymmetric logical unit access behaviour explains the standby state without any path failure.

Why this answer

In an ALUA (Asymmetric Logical Unit Access) environment, a storage array designates each path as either optimized (active) or non-optimized (standby). When the array reports a path as non-optimized, ESXi places that path in a standby state and routes I/O through the optimized path. This is the expected behavior for arrays that support ALUA and is the most likely reason the second path shows as standby.

Exam trap

VCP-DCV often tests the distinction between path states (active, standby, dead) and the reasons behind them, and candidates commonly confuse standby with dead or assume it indicates a configuration error rather than an ALUA optimization.

How to eliminate wrong answers

Option A is wrong because authentication failures would typically result in the path being marked as dead or offline, not standby; authentication is handled at the fabric or array level and does not cause a standby state. Option B is wrong because improper zoning would cause the path to be down or not discovered at all, not in a standby state. Option D is wrong because the Fixed policy does not place paths in standby; it uses a single preferred path and leaves others as active but unused, not in standby.

Standby is specifically an ALUA concept.

62
MCQmedium

A retail company's vSphere 8 environment uses vCenter Single Sign-On (SSO) with an external identity provider via SAML. The security team wants to enforce multi-factor authentication (MFA) for all administrators logging into vCenter Server. Which SSO configuration should the administrator implement?

A.Configure vCenter SSO to use Integrated Windows Authentication (IWA) and enable Kerberos pre-authentication.
B.Configure the identity provider to require MFA and set the vCenter SSO to use the external identity provider as the authentication source.
C.Enable Smart Card Authentication in vCenter SSO and require administrators to use smart cards.
D.Set the vCenter SSO password policy to require complex passwords and frequent changes.
AnswerB

When vCenter SSO is configured to use an external identity provider via SAML, authentication is delegated to that provider. If the identity provider enforces MFA, administrators must complete MFA to log in. This approach centralizes MFA enforcement and meets the requirement without additional vCenter configuration.

Why this answer

To enforce MFA for vCenter administrators, the most effective method is to delegate authentication to an external identity provider that already enforces MFA. When vCenter SSO is configured to use that provider via SAML, MFA becomes mandatory for all logins. Other options either do not provide MFA or are not aligned with the existing SAML integration.

Exam trap

The trap here is thinking that enabling password policies or smart cards alone fulfills MFA, when MFA specifically requires multiple authentication factors, often best enforced by the external identity provider.

63
MCQhard

An administrator is using vSphere Lifecycle Manager (vLCM) to manage a cluster with an image. During remediation, the task fails with the error: 'Cannot remediate host because it is not compliant with the image.' The administrator checks the image and sees that it includes a firmware add-on. The hosts are from different hardware vendors. What is the most likely cause of the failure?

A.The firmware add-on is not compatible with all host models in the cluster.
B.The hosts do not have enough free disk space to stage the firmware update.
C.The ESXi base image version is too old for the firmware add-on.
D.The vLCM depot is not synchronized with the latest firmware packages.
AnswerA

Firmware add-ons are vendor-specific and model-specific. If the cluster contains hosts from different hardware vendors or models, a single firmware add-on may not support all of them. vLCM will flag hosts that cannot apply the firmware add-on as non-compliant. This is the most likely cause of the remediation failure.

Why this answer

Firmware add-ons in vLCM are specific to hardware vendors and models. When a cluster contains hosts from different vendors, a single firmware add-on cannot apply to all hosts. vLCM will mark hosts that are incompatible with the add-on as non-compliant, causing remediation to fail. The administrator should either use separate clusters per hardware type or remove the firmware add-on and manage firmware separately.

Exam trap

The trap here is assuming that any firmware add-on can be applied to any host, but firmware add-ons are hardware-specific and require homogeneous hardware within the cluster.

64
MCQeasy

Based on the exhibit, if a host in the cluster has a network card that is not on the vSphere Compatibility Guide, what will happen during remediation?

A.The host will automatically update its drivers to become compatible.
B.A warning will be generated but remediation proceeds.
C.The remediation will fail for that host.
D.The host will be skipped with a warning.
AnswerC

vSphere Lifecycle Manager validates every host's hardware against the vSphere Compatibility Guide before applying an image. A network card absent from that guide fails the hardware compatibility check, so remediation aborts on that host rather than proceeding.

Why this answer

During remediation (e.g., vSphere Lifecycle Manager or Update Manager), if a host has a network card not on the vSphere Compatibility Guide, the remediation will fail for that host. vSphere validates hardware compatibility before applying updates; an incompatible device causes the host to be placed in a failed state for that remediation task.

Exam trap

VCP-DCV often tests the difference between a warning and a failure during remediation; candidates may assume the host is skipped or that drivers auto-update, but incompatible hardware causes an outright failure.

How to eliminate wrong answers

Option A is wrong because drivers are not automatically updated to achieve compatibility; hardware must be listed on the Compatibility Guide, and remediation does not install unsupported drivers. Option B is wrong because it is not merely a warning; the remediation fails for that host. Option D is wrong because the host is not simply skipped with a warning; the remediation attempt fails, and the host remains non-compliant.

65
MCQhard

A vSphere administrator is designing a network for a cluster of ESXi hosts. Each host has four 10GbE uplinks. The cluster will host mission-critical VMs that require maximum throughput and redundancy. The administrator plans to use Network I/O Control (NIOC) and a vSphere Distributed Switch (vDS). Which configuration best ensures consistent network performance for all VMs?

A.Configure a single vDS with all four uplinks, enable NIOC, and set shares and reservations for each traffic type.
B.Configure a single vDS with all four uplinks and enable NetFlow for monitoring.
C.Create two separate vDS, each with two uplinks, and separate VM traffic from VMkernel traffic.
D.Configure a single vDS with all four uplinks and use Route based on IP hash teaming.
AnswerA

A single vDS pooling all four uplinks with NIOC shares and reservations guarantees bandwidth allocation per traffic type, satisfying the consistent-performance and redundancy requirement. Reservations protect mission-critical VM throughput during contention across the 10GbE uplinks.

Why this answer

NIOC enables per-traffic-type resource management using shares, reservations, and limits, ensuring that mission-critical VMs receive consistent network throughput even under contention. Combining all four uplinks into a single vDS maximizes aggregate bandwidth and provides redundancy through teaming policies, while NIOC prioritizes traffic flows to prevent VMkernel or management traffic from starving VM traffic.

Exam trap

The trap here is that candidates often confuse load-balancing algorithms (like IP hash) with QoS mechanisms, assuming that distributing traffic across uplinks alone guarantees performance, when in fact NIOC's per-traffic-type resource controls are required to enforce consistent throughput for all VMs.

How to eliminate wrong answers

Option B is wrong because NetFlow is a monitoring and traffic analysis tool, not a QoS or performance guarantee mechanism; it does not allocate bandwidth or enforce fairness among traffic types. Option C is wrong because splitting uplinks across two separate vDS reduces the total available bandwidth per vDS and prevents NIOC from managing all traffic centrally, leading to potential underutilization and inconsistent performance. Option D is wrong because Route based on IP hash provides load balancing but does not offer per-traffic-type resource controls like shares and reservations, so it cannot guarantee consistent performance for all VMs under contention.

66
MCQmedium

An administrator is using vSphere Lifecycle Manager (vLCM) to manage a vSphere 8 cluster. The cluster's desired image includes a specific ESXi base image and an OEM add-on. During remediation, the administrator wants to minimize the impact on running workloads. Which vLCM feature should be configured to control the number of hosts remediated in parallel?

A.vSphere High Availability (HA) admission control
B.Remediation parallelization
C.Host remediation timeout
D.Distributed Resource Scheduler (DRS) automation level
AnswerB

vLCM allows administrators to set the maximum number of hosts that can be remediated concurrently. This setting, often called remediation parallelization, helps control the impact on cluster capacity and ensures that enough resources remain available for running workloads during the update process.

Why this answer

Remediation parallelization in vLCM lets administrators specify the maximum number of hosts that can be remediated simultaneously. This directly controls the impact on cluster capacity and workload performance during updates. The other options are related to resource management but do not set the concurrency level for remediation.

Exam trap

The trap here is confusing DRS or HA settings with the vLCM-specific parallelization control that actually limits concurrent host remediation.

67
MCQhard

Refer to the exhibit. The administrator notices rx_dropped packets on vmnic0 but no errors. What is the most likely cause of the dropped packets?

A.There is a VLAN mismatch causing packets to be dropped.
B.The virtual switch port has insufficient buffer space.
C.The physical NIC's receive ring buffer is overflowing due to high traffic.
D.The physical switch is dropping packets due to congestion.
AnswerC

rx_dropped increments when the physical NIC's receive ring buffer has no free descriptors to accept incoming frames, so packets are discarded before reaching the vSwitch. The absence of errors confirms the drops stem from buffer exhaustion under high traffic, not link faults.

Why this answer

rx_dropped packets on a vmnic indicate that the physical NIC's receive ring buffer is overflowing, typically due to a burst of traffic that exceeds the buffer's capacity. This causes packets to be dropped before they can be processed by the network stack. The absence of errors suggests the drops are due to buffer exhaustion, not corruption or misconfiguration.

Exam trap

VCP-DCV often tests the confusion between physical NIC drops and virtual switch drops, leading candidates to incorrectly blame VLAN mismatches or virtual switch buffer issues instead of the physical NIC's ring buffer.

How to eliminate wrong answers

Option A is wrong because a VLAN mismatch would typically cause packets to be dropped at the virtual switch level, not necessarily increment rx_dropped on the physical NIC, and would often be accompanied by other errors. Option B is wrong because virtual switch port buffer space is not a common cause of rx_dropped on the physical NIC; the physical NIC's ring buffer is the primary suspect. Option D is wrong because drops on the physical switch would not be reflected in the ESXi host's vmnic statistics; rx_dropped is a local counter.

68
MCQmedium

An administrator is configuring a vSphere Distributed Switch (vDS) with multiple uplinks. The administrator wants to ensure that a single virtual machine's traffic uses only one physical uplink at a time to avoid out-of-order packet delivery. Which vDS teaming policy should the administrator select?

A.Route based on originating virtual port ID
B.Use explicit failover order
C.Route based on IP hash
D.Route based on physical NIC load
AnswerA

Route based on originating virtual port ID assigns each virtual machine's virtual port to a specific uplink. All traffic from that VM uses the same uplink, ensuring in-order delivery. This policy is the default and is suitable for most workloads that do not require more than one uplink's bandwidth.

Why this answer

Route based on originating virtual port ID pins each virtual machine's traffic to a single uplink, ensuring that packets from that VM are not spread across multiple uplinks and thus avoiding out-of-order delivery. IP hash and physical NIC load can distribute a VM's flows across uplinks, and explicit failover order does not provide per-VM distribution.

Exam trap

The trap here is assuming that IP hash or physical NIC load is better for performance, but they can cause out-of-order delivery for a single VM.

69
MCQmedium

A vSphere cluster has multiple storage arrays with different capabilities. The administrator wants to automatically place VMs on datastores that match their storage policy. What is required?

A.VASA provider
B.Storage DRS only
C.Storage I/O Control
D.VM storage policy and Storage DRS
AnswerD

Storage DRS automates initial placement and ongoing balancing of VM files across datastores in a datastore cluster, while VM storage policies define the per-VM requirements. Together they let vSphere match each VM to a datastore satisfying its policy, which is precisely the automatic placement behaviour the administrator requires.

Why this answer

Storage DRS automates initial placement and ongoing balancing of VMs across datastores in a datastore cluster, but it only honors storage requirements when a VM storage policy is assigned. The VM storage policy expresses capabilities such as RAID level, replication, or tier (e.g., gold/silver/bronze), and Storage DRS uses those policy requirements to select a compatible datastore. Therefore both a VM storage policy and Storage DRS are required to automatically place VMs on datastores matching their policy.

Exam trap

VCP-DCV often tests the distinction between capability discovery (VASA), policy definition (VM storage policy), and automated placement (Storage DRS) — candidates frequently pick 'Storage DRS only' and forget that policy enforcement requires an assigned VM storage policy.

How to eliminate wrong answers

Option A is wrong because a VASA provider only exposes array capabilities to vCenter so policies can be created and compliance checked; by itself it does not perform automated placement. Option B is wrong because Storage DRS alone balances by space and I/O metrics but cannot enforce policy-based placement without an assigned VM storage policy. Option C is wrong because Storage I/O Control (SIOC) only manages I/O shares and limits during contention; it has nothing to do with placing VMs on policy-compliant datastores.

70
MCQmedium

Refer to the exhibit. What does this error indicate?

A.The path is misconfigured.
B.The storage device is not connected.
C.The target LUN is not available.
D.The host's HBA is faulty.
AnswerC

The error arises because the ESXi host cannot reach the specified LUN, so the datastore cannot be mounted or accessed. This typically stems from zoning, masking or array-side presentation problems rather than host configuration, confirming the target LUN is unavailable to the host.

Why this answer

In VMware vSphere, an error indicating the target LUN is unavailable typically appears when an ESXi host cannot access a presented storage device — for example, the LUN has been unpresented from the storage array, masked incorrectly in the SAN fabric, or the datastore is in an 'inaccessible' state. The exhibit error (commonly 'The target LUN is not available' or a similar vSphere Client message) points to the LUN no longer being visible to the host, not to a path or HBA fault.

Exam trap

VCP-DCV often tests the distinction between path-level failures (misconfigured path, dead path) and device-level failures (LUN unavailable, PDL) — candidates must recognize that a target LUN unavailable error is a device presentation issue, not a path or HBA issue.

How to eliminate wrong answers

Option A is wrong because a misconfigured path would produce a 'path down' or 'dead path' status in the storage adapter view, not a target LUN unavailable error — paths can be down while the LUN remains accessible via other paths. Option B is wrong because a disconnected storage device would typically manifest as all paths down and the device disappearing entirely, often with a 'device is offline' or 'permanently inaccessible' state rather than a target LUN unavailable message. Option D is wrong because a faulty HBA would affect all LUNs presented through that adapter and would surface as adapter-level errors (e.g., link down, hardware failure), not a single LUN unavailability.

71
Drag & Dropmedium

Sequence the steps to configure a VM to use a static IP address via vSphere's customization specification.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence ensures that the VM receives the static IP configuration during the first boot after customization. Initiating the customization opens the wizard, selecting or creating a spec defines the settings, configuring IP within the spec sets the static address, applying saves the configuration, and powering on triggers the OS customization process.

72
MCQeasy

A company has a vSphere cluster of eight ESXi hosts managed by a single vCenter Server. They need to apply a critical security patch to the ESXi hosts with minimal downtime. Which method should the administrator use?

A.Use vMotion to migrate all VMs to one host, apply patch, then move back.
B.Use vSphere vMotion to migrate VMs, then apply patch using CLI on each host.
C.Put each host in maintenance mode and apply the patch via Update Manager.
D.Schedule a host reboot during maintenance window and apply patch via ISO boot.
AnswerC

Rolling maintenance mode with Update Manager patches each host sequentially, satisfying the minimal-downtime constraint: DRS evacuates VMs to remaining hosts before remediation, then the host rejoins the cluster. With eight hosts, sufficient capacity absorbs the workload, so no VM outage occurs during the critical security patch.

Why this answer

VSphere Update Manager (VUM) automates the patching process by placing each host into maintenance mode, migrating VMs via vMotion to other hosts, applying the patch, and then bringing the host back online—all with minimal downtime. This is the recommended method for applying critical security patches to multiple ESXi hosts in a cluster managed by a single vCenter Server.

Exam trap

The trap here is that candidates may think manual vMotion and CLI patching (Option B) is acceptable, but they overlook that Update Manager provides automated, cluster-aware patching with minimal downtime, which is the standard best practice in vSphere environments.

How to eliminate wrong answers

Option A is wrong because manually migrating all VMs to a single host creates a single point of failure and does not leverage the cluster's distributed resources; it also requires manual intervention for each host, which is inefficient and error-prone. Option B is wrong because using vSphere vMotion to migrate VMs and then applying the patch via CLI on each host is not automated and requires the administrator to manually handle maintenance mode and patching, increasing the risk of downtime and misconfiguration. Option D is wrong because scheduling a host reboot during a maintenance window and applying the patch via ISO boot is a disruptive, offline method that causes significant downtime for each host, and it does not use vMotion to migrate VMs, defeating the purpose of minimal downtime.

73
MCQmedium

A vSphere administrator notices that a database VM's storage transactions complete quickly, but the application still reports sluggish response. In esxtop, the administrator sees the DAVG/cmd value for the VM's datastore consistently below 10 ms, yet the KAVG/cmd value for the same device is averaging 35 ms. Which conclusion is MOST accurate?

A.The guest operating system's file system is fragmenting I/O, which inflates KAVG while leaving device latency untouched.
B.The path selection policy is load-balancing correctly, so the elevated KAVG is expected and requires no investigation.
C.The storage array is delivering the requested data quickly, but the vSphere VMkernel is queuing commands before they reach the device, adding latency inside the host.
D.The storage array is oversubscribed and cannot service commands fast enough, so the array is the sole cause of the application slowdown.
AnswerC

KAVG/cmd measures the time a command spends in the VMkernel queue before being issued to the device, while DAVG/cmd measures device service time. A low DAVG with a high KAVG means the array responds quickly once asked, but the host-side queue is the bottleneck, so this reading correctly identifies VMkernel queuing as the source of added latency.

Why this answer

KAVG/cmd reflects time commands wait in the VMkernel queue, whereas DAVG/cmd reflects time at the storage device. When device latency is low but queue latency is high, the bottleneck is host-side queuing rather than the array. Investigating queue depth, path throttling, and host storage stack settings is the appropriate next step for this database VM.

Exam trap

The trap here is assuming that any storage latency report points to the array, when KAVG versus DAVG actually separates host queue time from device time.

74
Multi-Selectmedium

Which TWO of the following are valid methods to restrict access to the ESXi host's Direct Console User Interface (DCUI) to authorized administrators only?

Select 2 answers
A.Disable SSH access on the host to prevent remote DCUI access.
B.Enable lockdown mode and add only authorized administrators to the Exception Users list.
C.Remove the root user from the DCUI local users list.
D.Set the advanced option 'DCUI.Access' to a list of authorized users.
E.Configure Active Directory integration and use group policy to disable DCUI.
AnswersB, D

Lockdown mode blocks all users except those on the Exception Users list from accessing the DCUI, satisfying the requirement to permit only authorised administrators. Adding administrators to that list grants them the explicit exemption needed, while all other accounts are denied by default.

Why this answer

Option B is correct because enabling lockdown mode restricts direct host access (including the DCUI) so that only users on the Exception Users list—authorized administrators—can log in to the DCUI and other local management interfaces. Option D is correct because the advanced setting 'DCUI.Access' explicitly defines which local users are permitted to access the Direct Console User Interface, so setting it to a list of authorized users restricts DCUI access to exactly those accounts. Option A is not correct because SSH is a separate remote shell service and disabling it has no effect on DCUI access, which is a local console interface.

Option C is not correct because the root user cannot simply be removed from the DCUI local users list in the manner described; DCUI access is controlled via lockdown mode and DCUI.Access, not by deleting root from a list. Option E is not correct because Active Directory integration and group policy do not provide a supported mechanism to disable the DCUI on an ESXi host.

Exam trap

VCP-DCV often tests the confusion between SSH/ESXi Shell access and DCUI access — candidates assume disabling SSH locks the console, but the DCUI is a separate interface controlled by lockdown mode and DCUI.Access.

75
Multi-Selecthard

A vSphere administrator is scaling a cluster that runs a latency-sensitive trading application. The application VMs must consistently receive CPU time with minimal scheduling delay, while other workloads on the same hosts must still run. Which TWO configurations should the administrator apply to the trading VMs to reduce CPU scheduling delay? (Choose two.)

Select 2 answers
A.Assign a high CPU shares value to the trading VMs relative to other VMs.
B.Set a CPU reservation on each trading VM that guarantees a minimum amount of MHz.
C.Move the trading VMs into a resource pool with a lower CPU share value than the default.
D.Set a CPU limit on the trading VMs to cap their maximum usage.
E.Disable hyperthreading on the hosts to ensure each vCPU maps to a full physical core.
AnswersA, B

CPU shares determine the relative priority of a VM when the host is contended. Giving trading VMs a high shares value means that during contention they receive a larger proportion of available CPU time, reducing queuing delay. Shares work only under contention, which matches the scaling scenario where multiple workloads compete for cores.

Why this answer

CPU reservations guarantee minimum MHz and CPU shares establish relative priority during contention; together they reduce ready time for latency-sensitive VMs. Limits and lower shares restrict or deprioritize workloads, and disabling hyperthreading reduces schedulable capacity. Applying reservations and elevated shares targets the scheduling delay directly.

Exam trap

The trap here is treating a CPU limit as a way to guarantee performance, when a limit actually caps usage and can introduce throttling.

Page 1 of 4

Page 2

All pages