Courseiva

VMware Certified Professional Data Center Virtualization VCP-DCV (VCP-DCV) — Questions 76–150

281 questions total · 4pages · All types, answers revealed

Page 1

Page 2 of 4

Page 3
76
MCQmedium

A vSphere administrator notices that one ESXi host in a DRS-enabled cluster is consistently running at 95% CPU utilization while other hosts average 40%. Which action should the administrator take to determine the cause?

A.Increase the DRS migration threshold from 3 to 5.
B.Place the host into maintenance mode to isolate the problem.
C.Set the DRS automation level to Fully Automated.
D.Review the host's performance charts in vCenter for CPU contention metrics.
AnswerD

vCenter performance charts expose CPU contention metrics such as ready time and co-stop for the host, revealing whether the 95% utilisation stems from overcommitted vCPUs, resource pool limits or unbalanced DRS rules. This data identifies the cause before any remediation.

Why this answer

The correct first step in diagnosing a performance imbalance is to gather data before changing configuration. Reviewing the host's performance charts in vCenter provides CPU contention metrics such as CPU usage, ready time, and co-stop, which reveal whether the host is genuinely overloaded or if VMs are contending for resources. This evidence-based approach identifies the root cause before any DRS tuning is attempted.

Exam trap

VCP-DCV often tests the misconception that changing DRS settings (threshold or automation level) is a diagnostic action, when in fact DRS tuning is a remediation step that should only follow performance analysis.

How to eliminate wrong answers

Option A is wrong because raising the DRS migration threshold from 3 to 5 makes DRS more aggressive about migrating VMs, but it does not diagnose why the host is at 95% CPU and could worsen the situation by moving workloads blindly. Option B is wrong because placing the host into maintenance mode evacuates all VMs and disrupts production without identifying the cause of the high utilization. Option C is wrong because setting DRS to Fully Automated only changes how recommendations are applied, not why the imbalance exists, and it does not provide any diagnostic data.

77
MCQmedium

A company requires all vMotion traffic to be encrypted. The vSphere administrator enables vMotion encryption at the cluster level. What else must be configured to ensure vMotion operations are encrypted?

A.Allocate at least 4 GB of additional memory for cryptographic operations.
B.Upgrade all ESXi hosts to version 7.0 or later.
C.Enable VM Encryption also.
D.Ensure all VMs have virtual hardware version 11 or later.
AnswerD

Virtual hardware version 11 or later is required to support encrypted vMotion.

Why this answer

For vMotion encryption to work, the virtual machine must have hardware version 11 or later. This requirement is documented for vSphere 6.5 and later, which support vMotion encryption. Option A is incorrect because there is no requirement to allocate additional memory for vMotion encryption; cryptographic operations for vMotion are handled by the host's CPU.

Option B is incorrect because vMotion encryption is supported on ESXi 6.5 and later, not specifically version 7.0 or later. Option C is incorrect because VM Encryption is a separate feature that encrypts the VM's files at rest, not vMotion traffic. Therefore, ensuring VMs have virtual hardware version 11 or later is necessary for encrypted vMotion.

78
MCQeasy

A vSphere administrator needs to migrate a virtual machine from one ESXi host to another while the virtual machine remains powered on. The virtual machine has a single vNIC connected to a standard switch port group named 'Production'. The destination host is in the same cluster and has a standard switch with a port group named 'Production' but with different VLAN settings. What will happen if the administrator attempts a vMotion migration?

A.The vMotion migration will fail because the VLAN settings are different.
B.The vMotion migration will succeed, and the virtual machine will use the VLAN settings of the destination port group.
C.The vMotion migration will fail because the port group names do not match exactly.
D.The vMotion migration will succeed, and the virtual machine will continue to use the VLAN settings of the source port group.
AnswerB

vMotion requires that a port group with the same name exists on the destination host. The virtual machine's vNIC will be connected to that port group, and it will inherit the VLAN settings configured on that destination port group. Therefore, if the VLAN settings differ, the virtual machine will use the destination's VLAN settings after migration. This can cause connectivity issues if not planned for.

Why this answer

During a vMotion migration, the virtual machine's network adapter is reconnected to a port group on the destination host that has the same name as the source port group. The VLAN settings of the destination port group are applied, not the source. This means that if VLAN settings differ, the virtual machine will use the destination's VLAN after migration.

The migration itself will succeed as long as the port group name exists, regardless of VLAN differences.

Exam trap

The trap here is assuming that vMotion preserves the source VLAN settings or that it fails if VLANs differ, when in reality it adopts the destination port group's VLAN settings.

79
MCQmedium

A vSphere administrator manages a cluster of eight ESXi hosts with vSphere Lifecycle Manager. The cluster's desired image specifies a firmware add-on that must be applied to all hosts. During remediation, the administrator notices that the firmware update is not being applied to any host. The hosts are otherwise compliant with the ESXi base image and other components. What is the most likely reason for the firmware not being applied?

A.The firmware add-on is included in the image but the hosts do not have the required vSphere Installation Bundles (VIBs) installed.
B.The ESXi hosts are in maintenance mode, preventing firmware updates from being applied.
C.The hardware support manager (HSM) is not configured or is unable to communicate with the firmware management interface.
D.The firmware add-on is not compatible with the current ESXi version and was skipped.
AnswerC

vLCM relies on a hardware support manager to apply firmware updates. If the HSM is not registered, is misconfigured, or cannot reach the out-of-band management interface (e.g., iDRAC, iLO), firmware updates will not be applied. The hosts may still be compliant with software components because those are handled by vLCM directly. Thus, the missing HSM configuration or connectivity is the most likely cause.

Why this answer

Firmware updates in vLCM are applied via a hardware support manager, which communicates with the server's out-of-band management controller. If the HSM is not properly configured or lacks network connectivity, firmware updates will not occur even if the software components are compliant. This is a common oversight when setting up vLCM with firmware add-ons.

Exam trap

The trap here is assuming that firmware updates are delivered as VIBs and thus part of the regular image compliance, rather than requiring a separate hardware support manager.

80
MCQhard

A vSphere administrator manages a vLCM cluster with a desired image. The administrator needs to update the ESXi base image to a newer version. The cluster contains hosts with different CPU generations. What should the administrator verify before updating the base image?

A.That all hosts have the same amount of memory installed.
B.That the cluster has vSphere DRS enabled in fully automated mode.
C.That all hosts are using the same storage adapter model.
D.That the newer ESXi version supports all CPU generations present in the cluster.
AnswerD

ESXi versions have specific CPU compatibility requirements. If the newer base image does not support an older CPU generation, hosts with that CPU cannot be upgraded and will become non-compliant. Verifying CPU support ensures a successful remediation across all hosts in the cluster.

Why this answer

Before updating the ESXi base image, the administrator must ensure the newer version supports all CPU generations in the cluster. ESXi releases have specific CPU compatibility requirements, and unsupported CPUs will block remediation. Verifying this prevents failed upgrades and ensures all hosts can run the new base image.

Exam trap

The trap here is focusing on uniform hardware like memory or storage adapters, when the actual compatibility concern for a base image update is CPU generation support.

81
MCQmedium

An administrator is using vSphere Lifecycle Manager (vLCM) to manage a cluster with an image. The administrator wants to add a custom VIB from a third-party vendor to the image. What must be done first?

A.Create a baseline containing the VIB and attach it to the cluster alongside the image.
B.Use vSphere Client to upload the VIB to each host's /tmp directory and reboot.
C.Import the VIB into the vLCM depot and add it as a component to the image.
D.Install the VIB manually on each host using esxcli, then remediate the cluster.
AnswerC

Custom VIBs must be added to the vLCM depot before they can be included in an image. The administrator imports the VIB into the depot, then adds it as a component to the desired image. This ensures the VIB is available for remediation and compliance checks. This is the correct first step to include third-party software in an image.

Why this answer

To include a custom VIB in a vLCM image, the VIB must first be imported into the vLCM depot. Once in the depot, it can be added as a component to the image. This ensures that the VIB is part of the desired state and will be applied during remediation.

Manual installation or baselines are not appropriate when the cluster is image-managed.

Exam trap

The trap here is thinking that manually installing a VIB or using a baseline is sufficient, but vLCM images require components to be in the depot to be part of the image.

82
MCQhard

A vSphere administrator is designing a cluster that must survive the loss of a single ESXi host without losing any VM data. The design uses vSAN as the primary datastore. Which storage policy setting must be configured to provide this level of protection?

A.Failures to tolerate set to 1
B.Number of disk stripes per object set to 1
C.Failures to tolerate set to 0
D.Object space reservation set to 100 percent
AnswerA

Setting failures to tolerate to 1 means vSAN maintains one additional copy of data beyond the primary, allowing the cluster to survive a single host failure without data loss. For a three-host cluster this typically results in RAID-1 mirroring with two copies and a witness. This directly satisfies the requirement to survive one host loss.

Why this answer

To survive the loss of one host, the vSAN storage policy must specify failures to tolerate of 1. This causes vSAN to maintain a redundant copy of each object, so if a host fails the remaining copy remains accessible. Striping, reservation, and a failures-to-tolerate value of 0 do not provide host-failure redundancy.

Exam trap

The trap here is confusing performance-oriented policy settings such as striping with availability settings such as failures to tolerate.

83
MCQmedium

An administrator is troubleshooting a VM that reports poor application responsiveness. In esxtop on the ESXi host, the VM shows a CPU ready time (READY) of 12 percent, and the host has more vCPUs assigned to running VMs than physical cores. Which factor is the PRIMARY contributor to this ready time?

A.The VM is waiting for a physical CPU to become available because the host is overcommitted and the scheduler cannot place it immediately.
B.The physical CPU cores are running below their rated clock speed, so each vCPU takes longer to execute.
C.The VM's memory reservation is too low, causing the vCPU to stall while pages are faulted from disk.
D.The guest operating system is running too many background services, which inflates the ready time reported by esxtop.
AnswerA

CPU ready time measures the time a VM is ready to run but is waiting for a physical core. When vCPUs exceed physical cores, the scheduler must time-slice, so VMs wait in the run queue. A READY value around 12 percent for a latency-sensitive workload directly reflects this contention and is the primary contributor here.

Why this answer

CPU ready time reflects how long a vCPU waits for a physical core. With more vCPUs assigned than physical cores, the ESXi scheduler must time-slice, producing ready time. Reducing vCPU counts, adding hosts, or using shares and reservations to prioritize the latency-sensitive VM are the appropriate remedies for this contention.

Exam trap

The trap here is attributing ready time to guest activity or memory pressure instead of recognizing it as host-level CPU scheduling contention.

84
MCQhard

An organization has multiple vSphere clusters with different hardware models. They want a single lifecycle management strategy that minimizes administrative overhead while ensuring all hosts are up-to-date with ESXi and firmware. Which approach should they take?

A.Create one baseline group per cluster and attach it.
B.Use host profiles to enforce firmware settings.
C.Use a single cluster image for all clusters.
D.Create separate cluster images per hardware model and apply to respective clusters.
AnswerD

Cluster images are hardware-model-specific, so a single image cannot span differing models. Creating one image per model lets each cluster track its own ESXi and firmware baseline, satisfying the requirement for a unified lifecycle strategy without manual per-host remediation.

Why this answer

vLCM cluster images are hardware-model-specific because they bundle the ESXi base image plus OEM firmware and driver add-ons validated for a particular server model. With multiple hardware models, the correct strategy is one image per model, applied to the clusters containing that model. This keeps each image's firmware/driver add-on aligned with the hardware while still centralizing lifecycle management through vLCM.

Exam trap

VCP-DCV often tests the confusion between VUM baselines (patch-only) and vLCM images (full desired state including firmware) — candidates who pick baselines miss the firmware requirement.

How to eliminate wrong answers

Option A is wrong because baseline groups are the legacy VUM (vSphere Update Manager) approach — they manage patches/VIBs but do not deliver firmware or a full desired-state image, so they do not meet the 'ESXi and firmware' requirement. Option B is wrong because host profiles enforce configuration (settings) compliance, not firmware or ESXi version updates. Option C is wrong because a single image cannot contain firmware/driver add-ons for multiple different hardware models — the OEM add-on is model-specific, so one image would fail compatibility on at least one model.

85
Multi-Selectmedium

Which THREE are valid components of a vLCM single image? (Choose three.)

Select 3 answers
A.Virtual machine hardware versions
B.Additional VIBs and components
C.ESXi version and build number
D.vCenter Server version
E.Firmware and driver versions
AnswersB, C, E

A vLCM single image is composed of the base ESXi image plus additional VIBs and components layered onto it. This component layer lets administrators add third-party drivers or vendor agents while retaining one managed specification.

Why this answer

In vSphere Lifecycle Manager (vLCM), a single image is a declarative, cluster-level software specification that includes the ESXi base image (the ESXi version and build number, option C), additional VIBs and components layered on top of that base image (option B), and the firmware and driver add-ons delivered through hardware support managers (option E). Option C is correct because the base image defines the exact ESXi version and build the hosts will run. Option B is correct because components and additional VIBs are explicitly part of the image payload beyond the base ESXi image.

Option E is correct because firmware and driver versions are managed as part of the image via firmware add-ons and hardware support managers. Option A is not part of a vLCM image, since VM hardware versions are per-VM settings unrelated to host image management. Option D is not part of a vLCM image, because vCenter Server version is managed separately from the ESXi cluster image.

Exam trap

The trap here is that candidates often confuse the components of a vLCM single image with other vSphere lifecycle management concepts, such as VM hardware versions or vCenter Server version, which are not part of the ESXi host image specification.

86
Multi-Selectmedium

Which three factors influence the behavior of Network I/O Control (NIOC) when allocating bandwidth to different traffic types? (Choose three.)

Select 3 answers
A.The total physical bandwidth
B.Reservation per traffic type
C.Shares per traffic type
D.Limit per traffic type
E.The number of physical uplinks
AnswersB, C, D

Reservations guarantee a minimum bandwidth share for each traffic type, so NIOC honours them before distributing any remaining capacity. This directly satisfies the stem's allocation behaviour: a traffic type with a reservation cannot be starved by busier flows, even when shares and limits would otherwise favour competing traffic.

Why this answer

Network I/O Control (NIOC) allocates bandwidth on a vSphere Standard or Distributed Switch based on three per-traffic-type settings: Reservation (B), which guarantees a minimum bandwidth in Mbps or Gbps that the traffic type can always use; Shares (C), which determine the relative priority for distributing any remaining bandwidth when the link is contended (e.g., High=100, Normal=50, Low=25 per active uplink); and Limit (D), which caps the maximum bandwidth the traffic type may consume. These three parameters together define how NIOC divides and prioritizes bandwidth among traffic types such as vMotion, iSCSI, and VM traffic. The total physical bandwidth (A) is not a configurable NIOC factor — it is the underlying capacity that reservations, shares, and limits act upon, and NIOC itself does not let you set it.

The number of physical uplinks (E) affects aggregate capacity and teaming behavior, but NIOC allocation is driven by the per-traffic-type reservation, shares, and limit values, not by the uplink count.

Exam trap

VCP-DCV often tests NIOC parameters by mixing in physical capacity factors (total bandwidth, number of uplinks), so candidates who confuse aggregate capacity with per-traffic-type allocation parameters pick the wrong options.

87
MCQmedium

A vSphere administrator is planning to upgrade a vSphere 7.0 U2 cluster to vSphere 8.0 U1. The cluster is managed by a vCenter Server 7.0 U2. The administrator wants to use vSphere Lifecycle Manager (vLCM) to manage the upgrade. What must the administrator do first?

A.Enable vLCM on the cluster and set the desired image to ESXi 8.0 U1.
B.Upgrade vCenter Server to version 8.0 U1.
C.Upgrade one ESXi host to 8.0 U1 manually to test compatibility.
D.Create a baseline for ESXi 8.0 U1 in vLCM.
AnswerB

vLCM image management requires the managing vCenter Server to run the same or newer version than the target ESXi release. Upgrading vCenter Server to 8.0 U1 first satisfies that dependency, enabling the cluster upgrade to 8.0 U1.

Why this answer

vLCM relies on the vCenter Server to orchestrate and push images to ESXi hosts. Since the vCenter Server version must be equal to or higher than the target ESXi version, upgrading vCenter Server to 8.0 U1 first is a prerequisite. Without this, vLCM cannot manage the ESXi 8.0 U1 image because the older vCenter lacks the necessary APIs and compatibility.

Exam trap

The trap here is that candidates often assume vLCM can be configured independently of vCenter version, or they confuse vLCM's image-based approach with the older baseline-based method, leading them to select options that involve baselines or direct host upgrades.

How to eliminate wrong answers

Option A is wrong because enabling vLCM and setting the desired image to ESXi 8.0 U1 is not possible until vCenter Server is upgraded; vLCM cannot manage an ESXi version newer than the vCenter version. Option C is wrong because manually upgrading a host to 8.0 U1 before upgrading vCenter would break management connectivity, as vCenter 7.0 U2 cannot manage ESXi 8.0 U1 hosts. Option D is wrong because vLCM uses images, not baselines; baselines are a feature of the older Update Manager (UM) workflow, not vLCM.

88
MCQhard

An administrator notices that a critical VM running a database has a high CPU ready time average (over 20%) on a host with 2 physical CPUs (16 cores each). The host is running 6 VMs, each with 8 vCPUs. What is the most likely cause of the high ready time?

A.Hyper-Threading should be disabled to reduce scheduling overhead.
B.The host has too many vCPUs relative to physical cores; reduce vCPU count on some VMs.
C.The VMs are not configured with NUMA awareness.
D.Memory overcommitment is causing excessive swapping.
AnswerB

Over-commitment of vCPUs causes high CPU ready time: 6 VMs × 8 vCPUs = 48 vCPUs on 32 physical cores, so the scheduler forces VMs to wait for physical cores. Reducing vCPU counts on the non-database VMs lowers contention, directly addressing the ready-time constraint.

Why this answer

The host has 32 physical cores (2 CPUs × 16 cores) but the 6 VMs each with 8 vCPUs total 48 vCPUs, resulting in a vCPU-to-core ratio of 1.5:1. A CPU ready time average over 20% indicates severe contention for physical cores, as the hypervisor cannot schedule all vCPUs simultaneously. Reducing the vCPU count on some VMs would lower the ratio and alleviate the scheduling bottleneck.

Exam trap

The trap here is that candidates may confuse CPU ready time with memory pressure (Option D) or assume Hyper-Threading is the culprit (Option A), when the core issue is simply an over-provisioned vCPU-to-core ratio.

How to eliminate wrong answers

Option A is wrong because disabling Hyper-Threading would reduce the number of logical processors from 32 to 16 (assuming HT is enabled), worsening the vCPU-to-core ratio and increasing ready time, not reducing it. Option C is wrong because NUMA awareness affects memory locality and latency, not CPU scheduling contention; high ready time is a CPU scheduler issue, not a memory topology issue. Option D is wrong because memory overcommitment causes swapping or ballooning, which manifests as high memory latency or guest OS swapping, not as high CPU ready time; ready time is a measure of vCPU waiting for physical CPU cycles.

89
MCQeasy

A company wants to integrate vCenter Server with an external identity source to allow users to authenticate using their corporate credentials. The administrator must ensure that authentication traffic is encrypted. Which solution should the administrator implement?

A.Local OS authentication on vCenter Server
B.Active Directory over NTLM
C.Active Directory over LDAPS
D.Active Directory over LDAP
AnswerC

LDAPS wraps LDAP authentication traffic in TLS, encrypting credentials and queries between vCenter Server and the directory. Binding to Active Directory over plain LDAP would leave authentication traffic unencrypted, so LDAPS satisfies the stated encryption requirement for the external identity source.

Why this answer

Active Directory over LDAPS uses LDAP over SSL/TLS, which encrypts authentication traffic between vCenter Server and the AD domain controller. This meets the requirement for encrypted authentication. LDAPS typically uses port 636 and requires proper certificates on the domain controllers.

This is the correct solution for integrating vCenter with an external identity source while ensuring encryption.

Exam trap

VCP-DCV often tests the difference between LDAP and LDAPS; candidates may pick LDAP thinking it's sufficient, but the exam requires encryption, so LDAPS is the correct choice.

How to eliminate wrong answers

Option A is wrong because local OS authentication uses local accounts on the vCenter Server appliance, not corporate credentials, and does not integrate with an external identity source. Option B is wrong because Active Directory over NTLM does not encrypt authentication traffic by default; NTLM can be encrypted with signing/sealing, but it is not the standard secure LDAP method and is generally less secure. Option D is wrong because Active Directory over LDAP (without SSL) sends credentials in plaintext, which does not meet the encryption requirement.

90
MCQeasy

A small business runs three ESXi hosts in a single vSphere cluster. The administrator wants centralized management, alarm-based monitoring, and a single inventory view without deploying additional appliances. Which vSphere component provides this functionality?

A.VMware ESXi host client
B.VMware vRealize Operations Manager
C.VMware vSphere Client (HTML5)
D.VMware vCenter Server
AnswerD

vCenter Server is the centralized management platform for vSphere. It provides the single inventory view, role-based access control, alarms, and orchestration services such as vMotion and DRS. In a three-host cluster, vCenter is required to enable cluster features and to monitor host and VM health from one console, exactly matching the administrator's stated requirements.

Why this answer

vCenter Server is the management plane of vSphere, providing a single inventory, alarms, roles, and cluster services. The ESXi host client manages one host only, the vSphere Client is just the UI, and vRealize Operations is an add-on analytics product. For centralized management of multiple hosts, vCenter Server is the required component.

Exam trap

The trap here is confusing the vSphere Client, which is only a user interface, with vCenter Server, which is the actual management service that provides inventory, alarms, and cluster features.

91
MCQhard

A vSphere administrator is managing a vLCM cluster with a desired image that includes a custom partner add-on. During remediation, one host fails with the error: 'Failed to apply image. Cannot find VIB required by add-on.' The administrator verifies that the add-on is present in the image and that the host is compatible. What is the most likely cause of this error?

A.The custom add-on is not signed by VMware and is therefore rejected during remediation.
B.The host's software depot is not synchronized with the vCenter Server depot, causing the VIB to be unavailable.
C.The host's ESXi version is too new for the custom add-on to be installed.
D.The custom add-on depends on a VIB that is not included in the desired image or is not available in the depot.
AnswerD

Custom add-ons may have dependencies on other VIBs. If those dependency VIBs are not part of the desired image or are not present in the configured depot, vLCM cannot resolve them during remediation, resulting in the error. The administrator should verify the add-on's dependencies and ensure all required VIBs are included in the image or available in the depot.

Why this answer

Custom add-ons often have dependencies on other VIBs. If those dependency VIBs are not included in the desired image or are not available in the depot used by vLCM, remediation will fail with an error about missing VIBs. The administrator must ensure all required VIBs are included in the image or available in the depot.

Exam trap

The trap here is assuming that the add-on itself is self-contained and that any missing VIB error indicates a problem with the add-on rather than its dependencies.

92
MCQmedium

An administrator sees that a vLCM remediation task for a host has failed with the error: 'The VIB is incompatible with the host's base image.' The host is using a custom image that includes a third-party driver. What is the most likely cause?

A.The third-party driver should be removed from the image.
B.The VIB version is not compatible with the ESXi version in the image.
C.The VIB is missing from the cluster image.
D.The administrator should ignore the error and proceed.
AnswerB

A VIB built against a different ESXi base version cannot be added to the image, since vLCM validates each VIB against the base image's ESXi build. The third-party driver's version targets an incompatible ESXi release.

Why this answer

The error 'The VIB is incompatible with the host's base image' specifically indicates that the VIB's compatibility metadata does not match the ESXi base image version. vLCM validates each VIB against the base image's ESXi version and will reject any VIB whose acceptance level or version constraints are not satisfied. Since the host uses a custom image with a third-party driver, the most likely cause is that the driver VIB was built for a different ESXi version than the one in the image.

Exam trap

VCP-DCV often tests the misconception that any VIB can be added to any image, but vLCM enforces strict version compatibility between VIBs and the base image.

How to eliminate wrong answers

Option A is wrong because removing the third-party driver would eliminate the custom functionality and is not the root cause; the error is about version incompatibility, not the presence of the driver. Option C is wrong because if the VIB were missing from the cluster image, the remediation would not attempt to install it and would not produce this specific incompatibility error. Option D is wrong because ignoring the error would leave the host in a non-compliant state and could cause instability or failure of the third-party driver.

93
MCQmedium

A VM on a vSphere Distributed Switch is experiencing intermittent connectivity drops. The administrator checks the vDS health check and sees no errors. The physical switch logs show no issues. The VM is on a port group with VLAN 200. The administrator runs a ping from the VM to the gateway and notices packet loss. What should the administrator investigate next?

A.Verify the VMkernel port configuration
B.Check the VM's firewall settings
C.Check DNS resolution for the gateway
D.Review the NIC teaming failover order and ensure active uplinks are up.
AnswerD

Intermittent loss with clean health checks and switch logs points to uplink pathing. If the active uplink in the teaming failover order is down, traffic drops until failover, matching the observed packet loss on VLAN 200.

Why this answer

Intermittent connectivity drops on a VM connected to a vDS, despite no errors on the vDS health check or physical switch logs, often point to a NIC teaming misconfiguration. If the active uplinks are not properly set or one uplink is down, the VM traffic may fail over to a standby or unused uplink, causing packet loss. Verifying the teaming failover order and ensuring all active uplinks are operational directly addresses this common cause of intermittent drops.

Exam trap

The trap here is that candidates often assume intermittent connectivity must be a VM firewall or DNS issue, overlooking the NIC teaming failover order as a primary cause of packet loss on a vDS when physical and vDS health checks show no errors.

How to eliminate wrong answers

Option A is wrong because VMkernel port configuration is used for management traffic, vMotion, or storage, not for VM data traffic on a port group; investigating it would not resolve VM connectivity drops. Option B is wrong because the VM's firewall settings (e.g., Windows Firewall) would typically block all traffic or allow it consistently, not cause intermittent packet loss to a gateway; the issue is at the network layer, not the host firewall. Option C is wrong because DNS resolution is used for name-to-IP mapping, not for direct IP connectivity; the administrator is pinging the gateway IP, so DNS is irrelevant to packet loss.

94
Multi-Selecteasy

Which two actions must the administrator take to ensure network connectivity for VMs on a new distributed switch?

Select 2 answers
A.Configure a VMkernel interface on the distributed switch
B.Add the ESXi hosts to the distributed switch
C.Set the MTU to 9000
D.Create a port group and assign a VLAN
E.Enable Network I/O Control
AnswersB, D

Adding ESXi hosts to the distributed switch is mandatory because a vSphere Distributed Switch spans multiple hosts, and each host must be a member before its physical uplinks (vmnic) can be attached to dvUplinks. Without host membership, VMs cannot reach the dvPortGroup, so connectivity fails.

Why this answer

To provide network connectivity for VMs on a new vSphere Distributed Switch, the administrator must first add the ESXi hosts to the distributed switch (option B), because a vDS only manages networking on hosts that are members of it; without host membership, no physical uplinks or VM traffic can traverse the switch. The administrator must also create a port group and assign a VLAN (option D), since VM vNICs connect to distributed port groups, and the VLAN ID on that port group determines the Layer 2 broadcast domain for the VMs. Configuring a VMkernel interface (option A) is only required for host management, vMotion, iSCSI, or vSAN traffic, not for general VM connectivity.

Setting MTU to 9000 (option C) is an optional jumbo-frame tuning, and enabling Network I/O Control (option E) is an optional traffic-shaping/QoS feature; neither is required for basic VM network connectivity.

Exam trap

VCP-DCV often tests the confusion between host-level and VM-level networking requirements, tricking candidates into selecting VMkernel interfaces or optional features like MTU or NIOC instead of the mandatory host addition and port group creation.

95
Multi-Selectmedium

Which TWO capabilities are exclusive to vSphere with Tanzu compared to standard vSphere clusters?

Select 2 answers
A.DRS and HA
B.Tanzu Kubernetes Grid Service
C.Native Kubernetes control plane
D.vMotion
E.vSAN storage policies
AnswersB, C

Tanzu Kubernetes Grid Service provisions conformant Kubernetes clusters directly on vSphere, a capability absent from standard vSphere clusters. It satisfies the exclusivity constraint by delivering self-service cluster lifecycle management through the Supervisor, rather than merely running traditional VMs.

Why this answer

Options B and C are correct. vSphere with Tanzu provides a native Kubernetes control plane and the Tanzu Kubernetes Grid Service for managing Kubernetes workloads, which are not available in standard vSphere clusters. A (DRS and HA) and D (vMotion) are general vSphere features, not exclusive to vSphere with Tanzu. E (vSAN storage policies) is a vSAN capability, not exclusive to vSphere with Tanzu.

96
MCQmedium

A vSphere administrator needs to ensure that all virtual machine disks are encrypted at rest. The environment uses a KMS cluster with multiple KMIP-compliant servers. The administrator has already configured a storage policy with encryption enabled. However, newly created VMs on a particular datastore still show unencrypted disks. What is the most likely cause?

A.The datastore is a vSAN datastore, which does not support VM-level encryption.
B.The KMS cluster must have at least two KMS servers to function correctly.
C.The datastore is formatted with VMFS6, which does not support encryption.
D.The storage policy with encryption is not assigned to the VMs or their home namespace.
AnswerD

Encryption is enforced through the VM storage policy, not the datastore itself. If that policy is not assigned to the VMs or their home namespace, their disks remain unencrypted despite the KMS cluster and policy existing.

Why this answer

Even when a storage policy with encryption is configured, it must be explicitly assigned to the VMs or their home namespace (the VM's configuration and swap files). If the policy is not assigned, the VM will be created using the default datastore policy, which typically does not include encryption, resulting in unencrypted disks. The administrator must ensure the encryption-enabled policy is applied to the VM during creation or via a storage policy-based management (SPBM) assignment.

Exam trap

The trap here is that candidates assume configuring a storage policy with encryption is sufficient, but they forget that the policy must be explicitly assigned to the VM or its home namespace for encryption to take effect.

How to eliminate wrong answers

Option A is wrong because vSAN datastores fully support VM-level encryption (encryption at rest) when a KMS is configured and the appropriate storage policy is applied; vSAN does not preclude encryption. Option B is wrong because a KMS cluster can function with a single KMS server, though multiple servers are recommended for high availability; the question states a KMS cluster is already configured, so this is not the cause of unencrypted disks. Option C is wrong because VMFS6 fully supports VM-level encryption; encryption is a feature of the vSphere platform and the storage policy, not the VMFS version.

97
MCQeasy

An administrator is configuring a vSphere Standard Switch on an ESXi host. The switch has two physical NICs (vmnic0 and vmnic1) and several virtual machine port groups. The administrator wants to ensure that if vmnic0 fails, all virtual machine traffic automatically fails over to vmnic1 without manual intervention. Which setting should the administrator verify?

A.The failover detection method is set to beacon probing.
B.The virtual machine port groups are assigned to different VLANs.
C.Both physical NICs are set as active uplinks in the teaming and failover policy.
D.The switch is configured with a single uplink and the second NIC is assigned to a different standard switch.
AnswerC

When both physical NICs are active uplinks, the teaming policy allows traffic to use either NIC. If one NIC fails, the other continues to carry traffic, providing automatic failover. This is the simplest and most common configuration for redundancy. The administrator should ensure that both NICs are listed as active and that the load balancing policy is appropriate.

Why this answer

For automatic failover on a vSphere Standard Switch, the physical NICs must be configured as active uplinks in the same team. When one NIC fails, the other active NIC takes over the traffic. This is the fundamental redundancy mechanism.

Other settings like beacon probing are optional and not required for basic failover.

Exam trap

The trap here is overcomplicating the failover requirement by focusing on advanced detection methods instead of the basic active uplink configuration.

98
MCQhard

Refer to the exhibit. An administrator increased the MaxQueueDepth parameter for an NFS 4.1 datastore. Which effect does this change have on performance?

A.It reduces latency by limiting the number of queued I/Os.
B.It limits the maximum size of read and write operations.
C.It increases throughput by allowing more concurrent I/O operations.
D.It has no effect because NFS 4.1 does not support queue depth adjustments.
AnswerC

MaxQueueDepth defines how many outstanding I/O requests an NFS 4.1 datastore can hold. Raising it lets the host issue more concurrent operations before queuing blocks, so the array sustains higher throughput under load. Latency per operation is unaffected; only parallelism and queue capacity increase.

Why this answer

MaxQueueDepth on an NFS 4.1 datastore controls the maximum number of outstanding I/O operations that can be queued to the NFS server. Increasing this value allows more concurrent I/O requests to be in flight, which can improve throughput by keeping the storage pipeline fuller and reducing idle time waiting for responses. This is especially beneficial for workloads with many parallel I/O streams, as it enables better utilization of network and storage resources.

Exam trap

VCP-DCV often tests the misconception that increasing queue depth always reduces latency, when in fact it primarily aims to increase throughput and can sometimes increase latency if the storage backend cannot handle the additional concurrency.

How to eliminate wrong answers

Option A is wrong because increasing MaxQueueDepth does not reduce latency by limiting queued I/Os; it actually allows more queued I/Os, which can increase latency under certain conditions but aims to improve throughput. Option B is wrong because MaxQueueDepth does not control the size of read/write operations; that is governed by other parameters like rsize/wsize. Option D is wrong because NFS 4.1 does support queue depth adjustments via MaxQueueDepth, and it does have an effect on performance.

99
Drag & Dropmedium

Arrange the steps to convert a virtual machine to a template.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

To convert a VM to a template in vSphere, you must first power off the VM, then right-click it and select Convert to Template, confirm the operation, wait for the task to finish, and finally verify the template in the inventory. This ensures the VM is not in use and the conversion process is properly executed.

100
MCQhard

After upgrading the physical switches, the LAG (Link Aggregation Group) on a VDS does not come up. The VDS LAG configuration shows LACP active mode. The physical switch ports are configured with LACP active mode as well. What is the most likely cause?

A.The physical switch uses a different LACP system priority
B.The physical switch ports are not in a port-channel
C.The ESXi hosts have different LAG IDs
D.The VDS LAG hashing algorithm is set to IP hash
AnswerB

LACP active mode on both sides requires the physical switch ports to be members of a port-channel; without that, LACP PDUs are exchanged but no aggregation forms, so the VDS LAG stays down. The stem's constraint is that both ends already run LACP active, leaving the missing switch-side port-channel as the cause.

Why this answer

For a VDS LAG in LACP active mode to come up, the physical switch ports must be configured as a port-channel (LAG) with LACP enabled. If the switch ports are left as individual access ports without a port-channel, the ESXi host's LACP PDUs are not matched to a LAG on the switch side, and the LAG never forms. This is the most common cause after a switch upgrade where the port-channel configuration was not reapplied.

Exam trap

VCP-DCV often tests the assumption that matching LACP modes is sufficient, when the real requirement is that the physical switch ports must be members of a port-channel/LAG.

How to eliminate wrong answers

Option A is wrong because differing LACP system priority values do not prevent a LAG from forming; system priority is used to elect the LACP actor and only matters in multi-chassis or tie-breaking scenarios, not for basic LAG formation. Option C is wrong because LAG IDs are local to each ESXi host and do not need to match across hosts; each host forms its own LAG with the switch independently. Option D is wrong because the hashing algorithm (IP hash vs. others) affects load balancing, not whether the LAG comes up; a LAG can form with any hashing algorithm.

101
MCQeasy

A VM cannot connect to the network after being migrated to a different host in the cluster. The VM's network adapter is connected to a standard switch port group that exists on the source host but not on the destination host. What is the most likely cause?

A.The standard switch is not configured on the destination host.
B.The VM's MAC address is not allowed on the destination port group.
C.The VLAN ID on the port group does not match.
D.The ESXi host's firewall is blocking the VM's traffic.
AnswerA

A vSphere Standard Switch is host-local, so its port groups exist only on hosts where it was created. Because the destination host lacks that standard switch, the VM's adapter has no matching port group to connect to, breaking network connectivity after migration.

Why this answer

A standard vSwitch and its port groups are host-local objects — they are not shared across ESXi hosts in a cluster. If the VM's port group exists only on the source host, the destination host has no matching port group, so the VM's network adapter cannot connect after migration. This is the classic cause of post-migration network loss with standard switches.

Exam trap

VCP-DCV often tests the host-local nature of standard vSwitches versus the cluster-wide scope of distributed switches, baiting candidates into VLAN or firewall answers.

How to eliminate wrong answers

Option B is wrong because MAC address restrictions are a security policy feature (e.g., on a distributed switch or port security), not the default behavior, and would not be triggered simply by migration. Option C is wrong because a VLAN mismatch would still allow the port group to exist and the VM to connect — it would cause connectivity issues but not a 'port group not found' condition. Option D is wrong because the ESXi firewall governs host management traffic, not VM guest traffic on a vSwitch, so it would not block the VM's network adapter.

102
MCQeasy

A vSphere administrator wants to prevent users in a custom role from powering off virtual machines that have Fault Tolerance enabled. Which privilege must be removed from the custom role?

A.VirtualMachine.State.Suspend
B.VirtualMachine.Interrupt.PowerOff
C.VirtualMachine.Interrupt.Reset
D.VirtualMachine.Interrupt.PowerOn
AnswerB

Removing VirtualMachine.Interrupt.PowerOff directly blocks the power-off action on any VM the role applies to, including Fault Tolerance–enabled ones. Fault Tolerance itself imposes no separate privilege gate, so the standard power-off privilege is the sole control satisfying the stem's constraint.

Why this answer

The privilege VirtualMachine.Interrupt.PowerOff directly controls the ability to power off a virtual machine, including those with Fault Tolerance enabled. Removing this privilege from a custom role prevents users from performing a power-off operation on any VM, including FT-protected ones. Other privileges like Suspend, Reset, or PowerOn do not govern the power-off action, so they are irrelevant to this requirement.

Exam trap

VCP-DCV often tests the exact privilege name for a given operation, and candidates may confuse similar-sounding privileges like Suspend, Reset, or PowerOn with PowerOff, leading to incorrect answers.

How to eliminate wrong answers

Option A is wrong because VirtualMachine.State.Suspend controls suspending a VM, not powering it off; suspending an FT VM is a different operation and does not satisfy the requirement. Option C is wrong because VirtualMachine.Interrupt.Reset controls resetting a VM, which is a restart operation, not a power-off. Option D is wrong because VirtualMachine.Interrupt.PowerOn controls powering on a VM, which is the opposite of powering off and does not prevent the undesired action.

103
MCQeasy

An administrator is reviewing the network configuration of a standard switch. The exhibit shows the current settings for a port group. Which change would improve load distribution for VM traffic?

A.Change the VLAN ID to 100.
B.Enable failover on the port group.
C.Change the load balancing policy to Route based on IP hash.
D.Set one NIC as active and the other as standby.
AnswerC

Route based on IP hash distributes traffic across physical uplinks by hashing source and destination IP addresses, spreading VM flows over multiple NICs. The default port-based policy pins each VM to one uplink, so this change directly improves load distribution for the port group's traffic.

Why this answer

Route based on IP hash uses a hash of source and destination IP addresses to determine which uplink to use for each traffic flow, ensuring that all packets in a given flow use the same uplink while distributing different flows across multiple uplinks. This improves load distribution for VM traffic compared to the default Route based on the originating virtual port, which only considers the vNIC port ID and can lead to uneven distribution when multiple VMs share the same port group.

Exam trap

The trap here is that candidates often confuse 'failover' with 'load balancing' and assume enabling failover (Option B) will distribute traffic, but failover only provides redundancy, not active load sharing, while Route based on IP hash (Option C) is the correct method for distributing VM traffic across multiple uplinks.

How to eliminate wrong answers

Option A is wrong because changing the VLAN ID to 100 would alter the VLAN tagging for the port group, which does not affect load balancing or distribution of VM traffic across uplinks. Option B is wrong because failover is already implicitly enabled on a standard switch with multiple uplinks; enabling failover is not a configurable toggle and does not improve load distribution—it only ensures redundancy. Option D is wrong because setting one NIC as active and the other as standby would disable load balancing entirely, forcing all traffic through the active NIC and leaving the standby NIC unused until a failure occurs, which reduces rather than improves load distribution.

104
MCQeasy

A customer wants to ensure that all hosts in a cluster run the same ESXi version and firmware. Which vSphere feature should they use?

A.vSphere Update Manager (VUM)
B.vSphere Lifecycle Manager (vLCM)
C.Host Profiles
D.vSphere Replication
AnswerB

vSphere Lifecycle Manager manages hosts through a desired-state image containing both ESXi base version and firmware add-ons, so remediating the cluster converges every host to identical software and firmware. Traditional baselines handle patches and upgrades but cannot enforce firmware consistency across hosts.

Why this answer

vSphere Lifecycle Manager (vLCM) manages a cluster against a single desired image that includes both the ESXi base image and firmware/add-ons, ensuring all hosts converge to the same ESXi version and firmware. This desired-state model is exactly what the customer needs to guarantee uniformity across the cluster.

Exam trap

VCP-DCV often tests the distinction between vLCM (image-based, includes firmware) and VUM (baseline-based, ESXi patches only), and the misconception that Host Profiles manage ESXi versions or firmware.

How to eliminate wrong answers

Option A is wrong because vSphere Update Manager (VUM) is the legacy baseline-based patching tool; it manages ESXi patches and some add-ons but does not manage firmware as part of a unified image, so it cannot guarantee identical firmware across hosts. Option C is wrong because Host Profiles enforce configuration consistency (networking, security, storage settings) but do not manage ESXi version or firmware updates. Option D is wrong because vSphere Replication is a disaster-recovery feature for replicating VMs between sites, unrelated to host version/firmware consistency.

105
MCQmedium

An administrator configures a VDS with two uplinks and sets the load balancing policy to 'Route based on IP hash'. What additional configuration is required on the physical switches to ensure proper traffic distribution?

A.Use individual ports with no aggregation.
B.Set port security to allow multiple MAC addresses.
C.Enable Link Aggregation Control Protocol (LACP).
D.Configure a static EtherChannel.
AnswerD

IP hash hashes each flow to one uplink based on source and destination IP, so the physical switch ports must be bundled into a static EtherChannel. Without that link aggregation, the switch treats the uplinks as separate links and may drop or misdirect traffic.

Why this answer

'Route based on IP hash' on a vSphere Distributed Switch requires the physical switch ports to be configured as a static EtherChannel (or equivalent LAG). IP hash uses a hash of source and destination IPs to select an uplink, and the physical switch must treat the uplinks as a single logical link so return traffic flows correctly.

Exam trap

VCP-DCV often tests the distinction between static EtherChannel (for IP hash) and LACP (for dynamic LAG), causing candidates to pick LACP when the question specifies IP hash without LACP.

How to eliminate wrong answers

Option A is wrong because individual, non-aggregated ports would cause the physical switch to see the same MAC on multiple ports, leading to MAC flapping and dropped frames. Option B is wrong because port security allowing multiple MACs does not create the required link aggregation and does not solve the hashing/return-path problem. Option C is wrong because LACP is used with 'Route based on IP hash' only when the VDS is configured for LACP; the classic IP hash setup uses a static EtherChannel, not dynamic LACP.

106
MCQmedium

A healthcare provider's vSphere 8 environment must encrypt all VM files at rest. The security team requires that encryption keys be stored on a hardware security module (HSM) and that the vCenter Server never hold the keys in its database. An administrator configures a Key Provider and enables VM encryption. Which component is responsible for storing the encryption keys?

A.The vCenter Server's VMware Postgres database.
B.The Key Management Server (KMS) configured as a standard key provider.
C.The ESXi host's ramdisk, which persists across reboots.
D.A vSphere Trust Authority attestation service running on the ESXi host.
AnswerB

A standard key provider, such as a KMS, stores encryption keys externally on an HSM or key server, not in the vCenter Server database. When VM encryption is enabled, ESXi hosts request keys from the KMS via the vCenter Server, but the keys are never persisted in vCenter. This meets the requirement that keys reside on an HSM.

Why this answer

VM encryption requires a key provider to store keys externally. A standard key provider, typically a KMS with an HSM, holds the keys outside vCenter and ESXi. vCenter brokers key requests but does not store keys. The ESXi ramdisk is volatile, and Trust Authority handles attestation, not key storage.

Thus, the KMS is the correct component.

Exam trap

The trap here is assuming that vCenter Server stores encryption keys because it manages the encryption process, when in fact keys are held externally by the KMS.

107
MCQmedium

A vSphere administrator needs to increase the size of a VMFS6 datastore that is running low on free space. The underlying LUN has 500 GB of unallocated space. The administrator expands the LUN on the storage array and then rescans the storage adapter. What should the administrator do next to grow the datastore?

A.Use the vSphere Client to increase the datastore capacity.
B.Use the vSphere Client to create a new datastore on the free space and then extend the original datastore.
C.Use the ESXi Shell and run the vmkfstools command to expand the datastore.
D.Use the ESXi Shell and run the partedUtil command to resize the partition.
AnswerA

After expanding the LUN and rescanning, the vSphere Client will show the additional free space on the device. The administrator can then use the 'Increase Datastore Capacity' wizard to expand the VMFS6 datastore into the newly available space. This is the supported method and ensures the file system is grown correctly.

Why this answer

After expanding the LUN and rescanning, the additional space appears as free on the device. The vSphere Client's 'Increase Datastore Capacity' wizard allows you to expand the VMFS6 datastore into that free space. This is the supported and safe method, ensuring the file system is properly grown and the datastore remains consistent.

Exam trap

The trap here is thinking that command-line tools like vmkfstools or partedUtil are needed to expand a VMFS datastore, when the vSphere Client provides a simple wizard.

108
MCQmedium

A vSphere administrator needs to provide a development team with a self-service portal to deploy VMs from a catalog, with role-based access control and quotas. The environment currently uses vCenter Server 8.0 and ESXi 8.0 hosts. Which VMware solution should be used?

A.vSphere with Tanzu
B.VMware Cloud Foundation
C.VMware Aria Operations
D.VMware Aria Automation
AnswerD

VMware Aria Automation (formerly vRealize Automation) provides a self-service portal, catalog, role-based access control, and quotas for deploying VMs and other resources. It integrates with vCenter Server to provision and manage infrastructure. This is the designated solution for self-service multi-cloud automation in the VMware portfolio.

Why this answer

VMware Aria Automation is the VMware solution that provides a self-service portal, catalog, RBAC, and quotas for VM provisioning. Aria Operations is for monitoring, vSphere with Tanzu is for containers, and Cloud Foundation is a broader platform that includes Aria Automation but is not the specific answer.

Exam trap

The trap here is confusing Aria Automation with Aria Operations, or assuming vSphere with Tanzu can provision VMs.

109
MCQhard

An administrator notices that a virtual machine on an NFS datastore is experiencing intermittent performance degradation. The ESXi hosts are connected to the NFS server via a 10 GbE network. The administrator uses esxtop and sees high average latency on the storage device, but the NFS server reports low latency. What is the most likely cause?

A.Jumbo frames are enabled on the ESXi hosts but not on the NFS server
B.Network congestion is causing TCP retransmissions
C.The NFS server is performing data deduplication on the datastore
D.The NFS datastore is mounted with read-only permissions
AnswerB

High latency reported by esxtop on the ESXi side, while the NFS server reports low latency, points to the network path rather than the array. TCP retransmissions from congestion inflate storage latency as packets are resent and responses delayed.

Why this answer

The most likely cause is network congestion causing TCP retransmissions. When the ESXi host sees high average latency on the NFS datastore but the NFS server reports low latency, it indicates that the delay is occurring in the network path between the host and the server, not on the server itself. TCP retransmissions due to network congestion would cause the host to experience higher latency than the server, matching the symptoms.

Exam trap

VCP-DCV often tests the ability to differentiate between storage-side and network-side latency, causing candidates to blame the NFS server or jumbo frame misconfiguration when the evidence points to network congestion.

How to eliminate wrong answers

Option A is wrong because a mismatch in jumbo frame configuration (enabled on ESXi but not on the NFS server) would typically cause connectivity failures or severe performance degradation due to fragmentation, but it would not produce the specific pattern of high host-side latency with low server-side latency; it would more likely cause packet drops or MTU issues. Option C is wrong because NFS server-side deduplication would increase latency on the server, which would be reflected in the server's reported latency; since the server reports low latency, deduplication is not the cause. Option D is wrong because a read-only mount would cause write failures, not intermittent performance degradation; the question describes performance degradation, not write errors.

110
MCQhard

Refer to the exhibit. An administrator notices that the ESXi host is listening on both IPv4 and IPv6 for HTTPS. However, IPv6 traffic is not being forwarded to the host. Which configuration change is most likely needed?

A.Configure a default gateway for the IPv6 stack on the host.
B.Disable IPv6 and use only IPv4.
C.Remove the IPv4 HTTPS listener to force IPv6.
D.Enable IPv6 on the vSphere Distributed Switch.
AnswerA

Without a default IPv6 gateway, the host can receive IPv6 traffic on its local subnet but cannot route replies beyond it, so forwarded IPv6 packets fail. Configuring the gateway satisfies the stem's requirement that IPv6 traffic reach the host across subnets, restoring bidirectional HTTPS connectivity.

Why this answer

If the ESXi host is listening on IPv6 for HTTPS but IPv6 traffic isn't being forwarded to it, the host likely lacks a default gateway for its IPv6 stack. Without an IPv6 default gateway, the host can communicate on-link but cannot route replies to off-subnet IPv6 clients, so forwarded traffic never returns. Configuring an IPv6 default gateway on the host resolves the routing gap.

Exam trap

The trap is focusing on the listener/service state ('it's listening on IPv6, so IPv6 must be enabled') and overlooking that a bound listener without an IPv6 default gateway cannot route replies to off-subnet clients — candidates often pick switch-level or disable-IPv6 options instead of the host routing fix.

How to eliminate wrong answers

Option B is wrong because disabling IPv6 and using only IPv4 doesn't fix the requirement to forward IPv6 traffic — it abandons IPv6 entirely rather than enabling it. Option C is wrong because removing the IPv4 HTTPS listener doesn't make IPv6 work; the host would still lack an IPv6 default gateway and the problem would persist (and you'd lose IPv4 management). Option D is wrong because enabling IPv6 on the vSphere Distributed Switch is a switch-level setting; the symptom is host-level routing (listener present, traffic not forwarded), and the DVS already carries the traffic — the missing piece is the host's IPv6 default gateway.

111
MCQmedium

A security team requires that all vCenter Server administrative logins be validated against an external identity source, but they also want to retain the ability to log in with the local SSO administrator account during a directory service outage. An administrator has already added the Active Directory identity source to vCenter Single Sign-On. Which configuration should the administrator apply to meet both requirements?

A.Configure the Active Directory identity source as the default identity source and grant the AD domain admins the Administrator role on the root folder.
B.Add the Active Directory identity source, then assign the AD security group the Global Permissions Administrator role, and leave the default identity source as the local SSO domain.
C.Add the Active Directory identity source, set it as the default identity source, and keep the local SSO administrator account available for emergency access.
D.Set the identity source type to 'Active Directory over LDAP' and enable 'Use Windows session authentication'.
AnswerC

Setting the directory as the default identity source makes vCenter Single Sign-On present that domain first and validate administrative logins against it, satisfying the external-validation requirement. The local SSO administrator account is not deleted by adding an identity source, so it remains usable for break-glass access if the directory becomes unreachable, which satisfies the second requirement without weakening normal operations.

Why this answer

The requirement has two parts: external validation for administrative logins and a usable local fallback. Setting the added Active Directory source as the default identity source directs SSO to validate against the directory by default, while the built-in SSO administrator account persists and can still authenticate locally. Disabling or removing the local account would break the fallback requirement, and leaving the local domain as default would not enforce external validation.

Exam trap

The trap here is assuming that adding an Active Directory identity source to vCenter Single Sign-On automatically disables or removes the local SSO administrator account.

112
MCQmedium

A VM experiences high packet loss during peak hours. The VM is connected to a distributed switch port group with a traffic shaping policy: average bandwidth 100 Mbps, peak bandwidth 200 Mbps, burst size 50 KB. What is the most likely cause?

A.The peak bandwidth limit is being exceeded.
B.The burst size is too small, causing packets to be dropped when burst traffic exceeds the average.
C.The traffic shaping policy is disabled.
D.The physical uplink speed is less than 200 Mbps.
AnswerB

With 50 KB burst, sustained bursts above average cause drops.

Why this answer

Traffic shaping allows sustained traffic up to the average bandwidth (100 Mbps) and only permits bursts up to the peak bandwidth (200 Mbps) within the configured burst size. If the burst size is too small, burst traffic above the average during peak hours will be dropped, causing packet loss. The peak bandwidth limit is not necessarily being exceeded, a disabled policy would remove these shaping drops, and while a physical uplink slower than 200 Mbps could cause loss, the most likely cause given the configured policy and peak-hour burst behavior is the too-small burst size.

113
MCQhard

A company runs a critical e-commerce platform on a vSphere 7 cluster with ESXi hosts connected to a vSAN datastore. The environment uses vSphere Trust Authority (vTA) and VM encryption with an external KMS. Recently, after a successful vTA attestation, one of the VMs (WebServer-01) failed to power on with the error: 'Unable to decrypt the encrypted virtual machine upon re-registration. Reason: The KMS server is unreachable.' The administrator verifies that other encrypted VMs on the same host power on successfully. The KMS cluster consists of two servers: KMS-01 and KMS-02, both accessible from the management network. The administrator checks the VM's configuration and finds that it uses a custom storage policy with encryption. What is the most likely cause of this specific VM's failure?

A.The vCenter Server's KMS cluster configuration has been deleted, affecting all VMs but not this one.
B.The storage policy used by the VM has been modified and no longer includes encryption.
C.The vTA attestation process failed for the VM's host, but the error message is misleading.
D.The VM's encryption key was retrieved from a different KMS server that is now unavailable, and the key ID in the VM's metadata points to that KMS server.
AnswerD

Correct. The VM's encryption key may have been issued by a specific KMS server (e.g., KMS-01) that is now unreachable, while the KMS cluster overall is accessible. Other VMs may have keys from a different, reachable server (e.g., KMS-02), explaining why they power on successfully.

Why this answer

The error 'Unable to decrypt the encrypted virtual machine upon re-registration. Reason: The KMS server is unreachable' indicates that the ESXi host cannot contact the KMS server to retrieve the VM's encryption key. Since other encrypted VMs on the same host power on successfully, the host can reach the KMS cluster, but this specific VM's encryption key may have been issued by a different KMS server (e.g., an older or alternative KMS) that is now unavailable.

The key ID stored in the VM's metadata points to that unreachable server, causing the failure. Option A is incorrect because if the vCenter KMS cluster configuration were deleted, all VMs would be affected. Option B is incorrect because modifying the storage policy does not change the existing encryption key; the VM remains encrypted with its original key.

Option C is incorrect because vTA attestation is separate from KMS key retrieval; the error message is specific to KMS unavailability.

114
MCQmedium

A vLCM image is configured, but remediation fails with error: 'Image compliance check failed. Host does not have required add-on.' What should the administrator check first?

A.That the vCenter Service is running.
B.That the add-on is downloaded in the vLCM depot.
C.That the host has sufficient memory for the add-on.
D.That the host has internet access to download the add-on.
AnswerB

The error states the host lacks a required add-on, so the add-on component must exist in the vLCM depot before remediation can apply it. Verifying it is downloaded and available ensures the image can be composed and remediated successfully.

Why this answer

The error 'Image compliance check failed. Host does not have required add-on' indicates that the vLCM image includes an add-on component that is not present on the host. The first thing to check is whether that add-on is available in the vLCM depot, because if it is not downloaded, vLCM cannot apply it to the host.

Ensuring the add-on is in the depot is a prerequisite for successful remediation.

Exam trap

VCP-DCV often tests the assumption that the host needs internet access to download add-ons, but in vLCM, the vCenter server manages the depot, so the host does not require direct internet access.

How to eliminate wrong answers

Option A is wrong because the vCenter Service running is unrelated to the specific error about a missing add-on; if vCenter were down, you would not see this error. Option C is wrong because insufficient memory would typically cause a different error, not a missing add-on. Option D is wrong because the host does not download add-ons directly from the internet; vLCM uses the depot configured in vCenter, so internet access on the host is not required.

115
MCQeasy

An administrator needs to configure a vSphere Standard Switch (vSS) for a small environment. Which component must be created first before adding a virtual machine to the network?

A.Create a standard switch.
B.Configure a VMkernel interface.
C.Create a virtual machine port group.
D.Add a physical uplink to the host.
AnswerA

A standard switch provides the Layer 2 forwarding fabric that port groups and VM vNICs attach to. Without it, no uplink or virtual network exists, so it must be created before any virtual machine can be placed on the network.

Why this answer

Before a VM can be attached to a network on a vSphere Standard Switch, a standard switch must exist. The switch is the foundational layer; port groups and VMkernel interfaces are created on top of it. Therefore, creating the standard switch is the first required step.

Exam trap

VCP-DCV often tests the dependency order of vSS components — candidates pick 'port group' because that is what the VM connects to, forgetting the switch must exist first as the parent object.

How to eliminate wrong answers

Option B is wrong because a VMkernel interface is for host management, vMotion, iSCSI, etc., and is not required for VM network connectivity — it is created after the switch exists. Option C is wrong because a virtual machine port group is created on an existing standard switch; it cannot exist without the switch. Option D is wrong because adding a physical uplink is optional for a vSS (you can have an internal-only switch) and is done after the switch is created, not before.

116
Multi-Selectmedium

A cloud operations team is evaluating vSphere editions for a new data center. The team needs features that allow live migration of running workloads between hosts and automated placement of workloads across a cluster based on resource usage. Which two vSphere capabilities provide these requirements? (Choose two.)

Select 2 answers
A.vSphere High Availability (HA)
B.vSphere Distributed Resource Scheduler (DRS)
C.vSphere Network I/O Control
D.vSphere vMotion
E.vSphere Storage I/O Control
AnswersB, D

DRS monitors resource usage across hosts in a cluster and generates or applies placement recommendations to balance workloads. It satisfies the requirement for automated placement based on resource usage, and in fully automated mode it uses vMotion to act on those recommendations. DRS operates at the cluster level and respects affinity and anti-affinity rules.

Why this answer

vMotion provides live migration of running VMs between hosts, and DRS provides automated placement and balancing of workloads across a cluster based on resource usage. Together they meet both stated requirements. Storage I/O Control, Network I/O Control, and HA address storage performance, network performance, and failure recovery respectively, not live migration or automated placement.

Exam trap

The trap here is treating any cluster feature as a placement or migration mechanism, when only vMotion and DRS perform those specific functions.

117
MCQmedium

A company runs a critical application on a VM with 16 vCPUs and 128 GB RAM on an ESXi host that has 2 sockets (12 cores per socket, hyperthreading enabled) and 512 GB RAM. The application is known to scale well with multiple threads and memory bandwidth. Recently, a DRS migration moved the VM to a different host with the same CPU and memory configuration. After the migration, the application's performance dropped by 30%. The administrator checks vCenter and finds no other VMs on the destination host. esxtop shows the VM's CPU ready time is less than 1%, but the 'CPU cost' metric is high, and the 'Memory' section shows high values for 'Remote' memory accesses. What is the most likely cause of the performance drop?

A.The VM's virtual hardware version is not compatible with NUMA.
B.The VM is spanning multiple NUMA nodes, causing remote memory access.
C.The VM's memory shares have been reduced after the migration.
D.Transparent Huge Pages are not enabled on the destination host.
AnswerB

With 16 vCPUs on a 12-core-per-socket host, the VM spans both NUMA nodes, so vCPUs access memory attached to the remote node. High Remote memory values and CPU cost confirm this, while low CPU ready rules out scheduling contention.

Why this answer

The VM has 16 vCPUs and 128 GB RAM. On a host with 2 sockets, each socket has 12 cores (24 logical processors with hyperthreading). A 16-vCPU VM cannot fit within a single NUMA node (which typically corresponds to a physical socket, with 12 cores/24 threads).

Therefore, the VM spans both NUMA nodes. When a VM spans NUMA nodes, memory accesses from a vCPU on one node to memory on the other node become remote, increasing latency and reducing effective memory bandwidth. The esxtop output confirms this: low CPU ready (<1%) rules out CPU contention, but high 'CPU cost' and high 'Remote' memory accesses indicate NUMA remote memory access.

This explains the 30% performance drop, especially for a memory-bandwidth-sensitive application.

Exam trap

VCP-DCV often tests NUMA configuration and the impact of VM sizing on performance; the trap is assuming that CPU ready time is the only indicator of CPU contention, while ignoring memory access patterns and NUMA spanning.

How to eliminate wrong answers

Option A is wrong because virtual hardware version does not determine NUMA compatibility; NUMA support is available in hardware version 8 and later, and the VM is already running, so it's not the cause. Option C is wrong because memory shares are only relevant under memory contention; the destination host has no other VMs and 512 GB RAM, so there is no contention, and shares would not be reduced by migration. Option D is wrong because Transparent Huge Pages (THP) are enabled by default on ESXi and affect memory efficiency, not remote memory access; the esxtop output specifically points to remote memory accesses, not THP issues.

118
MCQeasy

A VM is experiencing high CPU ready time. The host has 16 physical cores and 20 vCPUs total across all VMs. Which action is MOST likely to reduce the CPU ready time on the VM?

A.Migrate the VM to another host with the same CPU load.
B.Decrease the number of vCPUs on the VM.
C.Increase the number of vCPUs on the VM.
D.Increase the memory reservation for the VM.
AnswerB

Fewer vCPUs reduce the number of co-scheduled vCPU worlds competing for the host's 16 physical cores, lowering the scheduler's wait time. CPU ready measures the percentage of time a vCPU is ready but waiting for a physical core, so shrinking the VM's vCPU count directly reduces contention.

Why this answer

Reducing the number of vCPUs on an over-provisioned VM decreases scheduling contention, lowering CPU ready time. Increasing vCPUs would worsen the issue. Migrating to another host with similar load would not help long-term.

Increasing memory does not directly reduce CPU contention.

119
MCQhard

An organization wants to upgrade ESXi hosts from 7.0 to 8.0 using vLCM. They have a cluster with mixed hardware (different NICs and HBAs). What is the best practice?

A.Create a custom image that includes all necessary drivers and add-ons for the mixed hardware.
B.Use vSphere Update Manager baselines instead of vLCM.
C.Use a single image with the latest ESXi version and no add-ons.
D.Upgrade hosts manually by booting from installation media.
AnswerA

A custom image built in vLCM bundles the specific NIC and HBA drivers plus add-ons required by the differing hardware, so every host in the mixed cluster remediates to one consistent, compatible image rather than failing validation against a vendor base image.

Why this answer

vLCM image-based management requires a single desired-state image per cluster, and that image must contain every driver, add-on, and component needed by all hosts in the cluster. With mixed hardware (different NICs and HBAs), the vendor add-on or custom image must bundle the appropriate async drivers so each host can boot and function after remediation. Creating a custom image that includes all necessary drivers and add-ons ensures the desired state is valid for every host, which is the documented best practice for heterogeneous clusters.

Exam trap

VCP-DCV often tests the misconception that a single vanilla ESXi image is sufficient for any cluster, ignoring that async drivers for NICs and HBAs must be included via vendor add-ons or custom images in vLCM.

How to eliminate wrong answers

Option B is wrong because vSphere Update Manager baselines are the legacy baseline-based approach and do not provide the desired-state image consistency the organization wants; vLCM supersedes UMB in vSphere 8. Option C is wrong because a single image with no add-ons will lack the async NIC/HBA drivers required by the mixed hardware, causing hosts to fail remediation or lose connectivity. Option D is wrong because manual installation media upgrades bypass vLCM entirely, defeating the purpose of using desired-state image management and introducing configuration drift.

120
MCQeasy

A vSphere cluster with DRS enabled is experiencing an imbalance in resource utilization across hosts. DRS is set to 'Manual' mode. What action should the administrator take to resolve the imbalance?

A.Change DRS to 'Fully Automated' mode.
B.Manually migrate VMs using vMotion.
C.Enable HA admission control.
D.Increase the DRS migration threshold.
AnswerB

Manual mode means DRS generates migration recommendations but applies none automatically. The administrator must therefore review the suggested moves and invoke vMotion to relocate VMs, correcting the imbalance. Switching to fully automated mode would change policy rather than resolve it directly.

Why this answer

In DRS Manual mode, vSphere generates migration recommendations but does not execute them automatically. The administrator must manually apply the recommended vMotion migrations to rebalance the cluster. Changing to Fully Automated would automate future balancing but does not immediately resolve the current imbalance without manual intervention.

Exam trap

The trap is assuming that changing DRS mode automatically resolves the current imbalance; the exam tests that Manual mode requires manual vMotion execution, and mode changes only affect future recommendations.

How to eliminate wrong answers

Option A is wrong because switching to Fully Automated will not retroactively apply pending recommendations; it only changes future behavior, and the current imbalance persists until a migration occurs. Option C is wrong because HA admission control is about reserving resources for failover, not about balancing load. Option D is wrong because increasing the migration threshold makes DRS more aggressive in generating recommendations, but in Manual mode it still requires manual execution.

121
MCQmedium

Refer to the exhibit. An administrator attempts to add a host to a vSAN cluster and receives this error. Which step should the administrator take to resolve the issue?

A.Reconfigure the vMotion interface (vmk1) to also carry vSAN traffic.
B.Add the host to the cluster without vSAN and enable vSAN later.
C.Create a new VMkernel adapter (vmk3) on the host's network and enable vSAN traffic.
D.Enable vSAN traffic on the existing vmk0 interface.
AnswerC

Creating a dedicated VMkernel adapter with vSAN traffic enabled satisfies the cluster's requirement for a vSAN-capable vmknic on the host. vSAN cannot join a host whose existing adapters lack this service enabled, so adding vmk3 and ticking vSAN traffic provides the necessary network path for cluster communication.

Why this answer

vSAN requires a dedicated VMkernel adapter with the vSAN traffic service enabled, and the error indicates no such adapter exists on the host. Creating a new vmk3 and enabling vSAN traffic on it satisfies the prerequisite without disturbing existing management or vMotion traffic.

Exam trap

The trap is assuming any existing VMkernel adapter can be reused for vSAN; the exam tests whether you know vSAN requires its own dedicated, vSAN-enabled VMkernel interface, not just any vmk.

How to eliminate wrong answers

Option A is wrong because vMotion and vSAN traffic should be separated for performance and isolation; sharing vmk1 does not satisfy vSAN's requirement for a vSAN-enabled VMkernel interface. Option B is wrong because adding the host without vSAN does not resolve the underlying missing VMkernel adapter and defers the problem. Option D is wrong because vmk0 is the management interface, and enabling vSAN on it mixes management and storage traffic, which is not best practice and may not be permitted.

122
Drag & Dropmedium

Sequence the steps to configure a DRS rule that keeps two VMs on different hosts.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence to configure a DRS rule that keeps two VMs on different hosts is: first access the cluster configuration, then add a new DRS rule, then name the rule, then choose the 'Separate VMs' type to enforce host separation, and finally assign the two VMs. This order ensures that each step logically follows the previous one, adhering to the typical workflow in vSphere where the rule is created before its properties are defined and applied.

123
MCQeasy

An administrator needs to apply a security patch to a vLCM-managed cluster. The patch is available as an ESXi image in the vSphere Lifecycle Manager depot. What is the correct procedure?

A.Create a new desired state image with the patch, validate, and remediate the cluster.
B.Attach a patch baseline to the cluster and remediate.
C.Export the current image, add the patch, and import it to the cluster.
D.Use Quick Boot to apply the patch to each host individually.
AnswerA

vLCM manages hosts through a desired-state image rather than baselines. Adding the patch means editing the image to include the updated ESXi base image, validating it against the cluster, then remediating so each host converges to that declared state, satisfying the depot-sourced patch requirement.

Why this answer

In a vLCM-managed cluster, the correct procedure to apply a security patch is to create a new desired state image that includes the patch from the vSphere Lifecycle Manager depot, validate the image against the cluster's hardware and software compatibility, and then remediate the cluster. This ensures all hosts are updated to the exact same image specification, maintaining consistency and compliance with the desired state.

Exam trap

The trap here is confusing vLCM's image-based management with the legacy baseline-based patching method, leading candidates to incorrectly select attaching a patch baseline (Option B) instead of creating a new desired state image.

How to eliminate wrong answers

Option B is wrong because attaching a patch baseline is a legacy approach used with baseline-based updates, not supported in vLCM-managed clusters which use image-based management. Option C is wrong because exporting the current image, adding the patch, and importing it is not a supported workflow; vLCM requires creating a new desired state image from the depot, not manual image manipulation. Option D is wrong because Quick Boot is a feature to reduce reboot time during remediation, not a method to apply patches individually; vLCM applies updates to all hosts in the cluster via a single remediation operation.

124
MCQhard

A vSphere administrator is troubleshooting a failed remediation attempt on an ESXi host in a cluster managed by vLCM. The image compliance status shows 'Non-Compliant'. The host is in maintenance mode. The administrator sees the following error: 'Failed to apply the software specification. Reason: The host's firmware version is incompatible with the selected ESXi image.' What is the most likely cause?

A.The hardware support manager (HSM) is not configured or the firmware baseline is outdated.
B.The host must be taken out of maintenance mode for the remediation to proceed.
C.The ESXi 8.0 image has deprecated certain drivers that are still in use.
D.The vLCM image is corrupted and needs to be re-imported.
AnswerA

vLCM compares host firmware against the hardware support manager's baseline during remediation. Without a configured HSM or with an outdated firmware baseline, the image's required firmware level cannot be validated or applied, producing the incompatibility error.

Why this answer

The error indicates that the host's firmware version is incompatible with the selected ESXi image. In vLCM, hardware compatibility is managed by the Hardware Support Manager (HSM), which provides firmware baselines. If the HSM is not configured or the firmware baseline is outdated, vLCM cannot validate or update the firmware to match the ESXi image requirements, leading to a 'Non-Compliant' status and remediation failure.

This is the most likely cause because the error directly points to firmware incompatibility, not driver issues or image corruption.

Exam trap

The trap here is that candidates may confuse firmware incompatibility with driver deprecation (Option C) or assume the host must be in maintenance mode (Option B), but the error message explicitly points to firmware version mismatch, which is managed by the HSM.

How to eliminate wrong answers

Option B is wrong because the host is already in maintenance mode, which is a prerequisite for remediation; taking it out of maintenance mode would not resolve the firmware incompatibility error. Option C is wrong because the error specifically mentions firmware version incompatibility, not deprecated drivers; while driver deprecation could cause issues, it would typically result in a different error message about missing or unsupported drivers. Option D is wrong because a corrupted vLCM image would likely produce a different error, such as 'Image import failed' or 'Invalid image', not a firmware version incompatibility error.

125
MCQmedium

A vSphere administrator manages a vLCM cluster with a desired image. The administrator wants to add a new vendor add-on to the image. Before applying the change, the administrator needs to understand the impact. What happens when a vendor add-on is added to the desired image?

A.The cluster becomes non-compliant, and remediation is required to apply the add-on to all hosts.
B.The add-on is applied only to the host that is currently in maintenance mode.
C.The add-on is stored in the vLCM depot but not applied until the next ESXi upgrade.
D.The add-on is automatically installed on all hosts without remediation.
AnswerA

Adding a vendor add-on changes the desired image, so hosts no longer match it. vLCM marks the cluster as non-compliant. Remediation applies the new add-on to each host. This is the expected behavior when modifying the desired image, and it ensures all hosts receive the updated software consistently.

Why this answer

When a vendor add-on is added to the desired image, the cluster's target state changes. Hosts no longer match the desired image and are marked non-compliant. Remediation is required to apply the add-on to all hosts.

This ensures consistent software across the cluster and is the standard vLCM workflow.

Exam trap

The trap here is assuming the add-on is applied automatically or deferred, when in fact the cluster becomes non-compliant and requires remediation.

126
Multi-Selecteasy

Which TWO actions are required to enable vSphere VM encryption? (Choose two.)

Select 2 answers
A.Configure a Key Management Server (KMS) or native key provider
B.Enable SSH on each ESXi host to manage encryption keys
C.Disable vMotion on the cluster
D.Assign an encryption storage policy to the virtual machine or enable encryption on the VM
E.Place the ESXi hosts in lockdown mode
AnswersA, D

vSphere VM encryption requires a key provider before any disk can be encrypted; either an external Key Management Server or the native key provider supplies the keys. This satisfies the stem's prerequisite of establishing key management, without which encryption cannot be enabled.

Why this answer

vSphere VM encryption requires a key provider to supply the encryption keys, so option A is correct: you must configure a Key Management Server (KMS) or a vSphere Native Key Provider and add it to the vCenter Server before any VM can be encrypted. Option D is also correct because, after the key provider is trusted, you must actually apply encryption by assigning a VM encryption storage policy to the virtual machine (or enabling encryption on the VM), which triggers the encryption of the VM's files and disks. Option B is not required: SSH access to ESXi hosts is not used to manage encryption keys, since key management is handled through the KMS/Native Key Provider and vCenter.

Option C is not required: vMotion remains fully supported with encrypted VMs and does not need to be disabled. Option E is not required: lockdown mode is a security hardening setting for host access and has no role in enabling VM encryption.

Exam trap

The trap is selecting operational or security-hardening steps (SSH, lockdown mode, disabling vMotion) as if they were encryption prerequisites; only the key provider and the encryption policy/action are required.

127
Multi-Selecteasy

Which two are benefits of using vLCM over legacy baseline-based patching? (Choose two.)

Select 2 answers
A.Support for heterogeneous cluster configurations.
B.No requirement to put hosts in maintenance mode.
C.Real-time compliance monitoring of all hosts.
D.Built-in integration with vRealize Automation.
E.Single image management for cluster consistency.
AnswersC, E

vLCM continuously reconciles desired-state images against each host, reporting drift as it occurs rather than only at scheduled baseline scans. This satisfies the stem's compliance-monitoring benefit, since legacy baselines surface compliance solely during remediation runs, leaving drift undetected between scans.

Why this answer

Option C is correct because vLCM (vSphere Lifecycle Manager) continuously and automatically checks each host in the cluster against the desired image and reports drift in real time, unlike legacy baselines that require manual compliance scans. Option E is correct because vLCM manages the entire cluster from a single desired-state image (base ESXi image plus firmware add-ons and components), ensuring every host is identical and consistent, whereas baselines apply separate patch/extension baselines per host. Option A is not a vLCM benefit since vLCM requires homogeneous clusters with identical hardware and image, and heterogeneous configurations are actually a limitation.

Option B is incorrect because remediation with vLCM still requires hosts to enter maintenance mode (or use the quick-boot/stateless options) just as with baselines. Option D is incorrect because vLCM does not provide built-in integration with vRealize Automation; that is not a documented vLCM capability.

128
MCQmedium

A vSphere administrator is observing that a VM with a 2 TB thin-provisioned virtual disk on a VMFS6 datastore is reporting 1.5 TB of used space inside the guest OS, but the datastore shows only 800 GB consumed by the VM. What is the most likely cause of this discrepancy?

A.The virtual disk needs to be defragmented to reclaim space.
B.The VM has a snapshot that is consolidating, reducing storage usage.
C.The virtual disk is thick-provisioned lazy zeroed, which delays allocation.
D.The virtual disk is thin-provisioned, so only the actual written blocks consume space on the datastore.
AnswerD

Thin provisioning allocates datastore blocks only when the guest actually writes data, so consumed capacity reflects written blocks rather than the guest-reported 1.5 TB. The 800 GB datastore figure is therefore expected, not an error, and matches the thin disk's on-demand allocation behaviour.

Why this answer

The discrepancy is because the virtual disk is thin-provisioned. Thin provisioning means the virtual disk file (VMDK) on the datastore only occupies space for blocks that have been written to by the guest OS, not the full allocated size. The guest OS reports 1.5 TB of used space because it sees the logical file system usage, but the datastore only shows 800 GB consumed because that is the actual physical storage used by the written blocks.

Exam trap

The trap here is that candidates may confuse guest OS reported usage with datastore consumption, not realizing that thin provisioning only allocates storage for blocks actually written, leading them to incorrectly suspect snapshots or defragmentation issues.

How to eliminate wrong answers

Option A is wrong because defragmentation reorganizes data within the guest OS but does not reclaim space on the datastore for thin-provisioned disks; it may even increase fragmentation of the underlying VMDK. Option B is wrong because a consolidating snapshot would temporarily increase storage usage, not decrease it, and the scenario describes a lower datastore consumption, not higher. Option C is wrong because a thick-provisioned lazy zeroed disk allocates all space at creation (2 TB) and does not show only 800 GB consumed; it would show the full 2 TB allocated on the datastore regardless of guest usage.

129
MCQmedium

A vSphere administrator is configuring a vSphere Standard Switch on an ESXi host. The physical switch port is configured as a trunk allowing VLANs 10, 20, and 30. The administrator needs to ensure that virtual machine traffic tagged with VLAN 20 is properly isolated and that the ESXi host itself can communicate on VLAN 10 for management. Which configuration should the administrator apply to the port group used by the VMs?

A.Set the port group VLAN ID to 0 (None).
B.Set the port group VLAN ID to 4095 (All).
C.Set the port group VLAN ID to 20.
D.Set the port group VLAN ID to 10.
AnswerC

Setting the port group VLAN ID to 20 ensures that all traffic from VMs connected to this port group is tagged with VLAN 20 (if the virtual switch tagging is used) or placed into VLAN 20. This matches the trunk configuration on the physical switch, allowing proper isolation. The host's management traffic is separate, typically on a different port group or VMkernel adapter with VLAN 10, so this port group correctly serves the VMs.

Why this answer

The port group VLAN ID must match the desired VLAN for the VMs, which is 20. This ensures that traffic from VMs is tagged with VLAN 20 and isolated from other VLANs. Using None or All would not correctly tag the traffic, and using VLAN 10 would misplace the VMs.

The physical switch trunk already allows VLAN 20, so the configuration aligns.

Exam trap

The trap here is confusing VLAN 0 (None) with VLAN 4095 (All) and assuming that None allows the physical switch to assign the VLAN based on the trunk's native VLAN, which would not isolate VLAN 20.

130
MCQeasy

A vSphere administrator needs to create a VMFS6 datastore on a new 4 TB LUN presented to an ESXi 7.0 host. The LUN is not yet formatted. Which method should the administrator use to create the datastore?

A.Use the ESXi Shell and run the partedUtil command to create a GPT partition.
B.Use the ESXi Shell and run the vmkfstools command to format the LUN.
C.Use the vSphere Client to add storage and select VMFS6.
D.Use the vSphere Client to create an NFS datastore and then convert it to VMFS6.
AnswerC

The vSphere Client provides a guided workflow to create a VMFS6 datastore on an unformatted LUN. This is the standard and recommended method for ESXi 7.0, as it automatically applies the correct partition layout and block size. It ensures compatibility and proper alignment without manual intervention.

Why this answer

The vSphere Client provides a straightforward wizard to create a VMFS6 datastore on an unformatted LUN. This method ensures correct partitioning, alignment, and registration with the ESXi host. It is the supported and recommended approach for ESXi 7.0, avoiding manual errors and ensuring compatibility.

Exam trap

The trap here is assuming that command-line tools like vmkfstools or partedUtil are required for creating VMFS datastores, when the vSphere Client is the standard method.

131
MCQeasy

A vSphere administrator is responsible for a vLCM-managed cluster. The administrator needs to check whether the cluster's hosts match the desired image before performing remediation. Which vLCM feature provides this information?

A.Remediation pre-check
B.Hardware compatibility list (HCL) validation
C.Compliance check
D.Image export
AnswerC

The compliance check compares each host's current software and firmware against the desired image. It reports whether hosts are compliant or non-compliant and provides details on any discrepancies. This is the correct feature for verifying host alignment with the desired image before remediation.

Why this answer

The compliance check in vLCM compares each host's current state to the cluster's desired image and reports compliance status. It is the standard way to verify whether hosts match the desired image before remediation. Other features like pre-checks or HCL validation serve different purposes.

Exam trap

The trap here is confusing the compliance check with the remediation pre-check, which is a later step in the remediation workflow.

132
MCQmedium

An administrator is troubleshooting a VM that is running slowly. The VM has 4 vCPUs and 16 GB of memory. The host has 2 physical CPUs with 10 cores each, hyper-threading enabled. The administrator runs esxtop and sees that %RDY for the VM is consistently above 15%. Which action would most likely reduce the ready time?

A.Increase the CPU shares for the VM.
B.Increase the number of vCPUs to 8 to improve parallelism.
C.Increase the memory allocation to 32 GB.
D.Reduce the number of vCPUs to 2 if the workload does not require 4.
AnswerD

High %RDY means vCPUs wait for physical cores. With hyper-threading, four vCPUs contend for limited logical processors, so reducing to two lowers scheduling pressure and co-stop, directly cutting ready time while still meeting the workload's needs.

Why this answer

A %RDY value consistently above 15% indicates the VM is ready to run but is waiting for CPU scheduling time on the host. With 4 vCPUs on a host that has 20 logical CPUs (2 sockets × 10 cores × 2 threads), the VM is likely over-provisioned relative to its workload needs, causing co-scheduling contention. Reducing the number of vCPUs to 2 decreases the co-scheduling demands and reduces ready time, as the VM will require fewer physical CPUs to be available simultaneously.

Therefore, option D is correct. Increasing CPU shares (option A) would not help if the host is saturated, adding more vCPUs (option B) would worsen contention, and increasing memory (option C) does not address CPU ready time.

Exam trap

The trap here is that candidates often assume adding more vCPUs will improve performance, but in reality, over-provisioning vCPUs increases co-scheduling overhead and ready time, making reduction the correct fix.

How to eliminate wrong answers

Option A is wrong because increasing CPU shares only affects relative priority during contention, not the underlying scheduling contention caused by too many vCPUs; it does not reduce %RDY. Option B is wrong because increasing vCPUs to 8 would worsen co-scheduling overhead and likely increase %RDY, not reduce it. Option C is wrong because memory allocation does not directly affect CPU ready time; %RDY is a CPU scheduling metric, not a memory metric.

133
MCQeasy

A vSphere administrator needs to present a new Fibre Channel LUN to an ESXi host. The LUN is already zoned and visible to the host's HBA. Which action should the administrator take to make the datastore available for use?

A.Rescan the storage adapter in the vSphere Client.
B.Create a new datastore and select the LUN from the list.
C.Reboot the ESXi host to detect the new LUN.
D.Run the esxcli storage core adapter rescan command from the host's DCUI.
AnswerA

After zoning and presenting a new LUN, the ESXi host must rescan its storage adapters to detect the new device. This can be done via the vSphere Client by selecting the host, going to Configure > Storage Adapters, and clicking Rescan. The rescan discovers new LUNs and makes them available for creating a datastore. Without a rescan, the host will not see the LUN.

Why this answer

To make a newly presented Fibre Channel LUN available, the administrator must rescan the storage adapter on the ESXi host. This can be done through the vSphere Client by navigating to the host's Storage Adapters and initiating a rescan. Once the rescan completes, the LUN appears and can be used to create a datastore.

Creating the datastore without a rescan will not work because the LUN is not yet detected.

Exam trap

The trap here is assuming that creating a datastore will automatically detect the new LUN, when a rescan is required first.

134
MCQhard

A vSphere environment uses Active Directory for authentication. The administrator notices that users from a specific AD group cannot log in to the vCenter Server, although other AD users can. The group is added to vCenter Server with the correct permissions. What is the most likely cause?

A.The users are not members of the vCenter Single Sign-On domain
B.The user accounts have expired passwords
C.The group is nested within another group
D.The domain of the group is not configured as an identity source in vCenter Single Sign-On
AnswerD

vCenter Single Sign-On only authenticates principals from identity sources it has been configured with. If that AD domain was never added as an identity source, its groups resolve to nothing, so members fail to log in despite correct vCenter permissions.

Why this answer

The most likely cause is that the domain of the group is not configured as an identity source in vCenter Single Sign-On. Even if the group is added with correct permissions in vCenter Server, vCenter SSO must be able to authenticate users against the domain. Without the domain listed as an identity source, vCenter cannot validate the credentials of users from that group, causing authentication failures for all users in that domain.

Exam trap

The trap here is that candidates often assume that adding a group to vCenter permissions is sufficient for authentication, overlooking the prerequisite that the group's domain must first be registered as an identity source in vCenter Single Sign-On.

How to eliminate wrong answers

Option A is wrong because vCenter Single Sign-On domains are not the same as Active Directory domains; users are not members of the SSO domain unless they are explicitly created there, and the question states the users are from an AD group, meaning they are AD users, not SSO domain users. Option B is wrong because expired passwords would affect individual users, not an entire group, and the symptom is that all users from the specific group cannot log in, which points to a domain-level issue rather than individual password expiration. Option C is wrong because nested groups are fully supported in Active Directory and vCenter Server; if the group is nested within another group, the permissions would still apply as long as the parent group has the correct permissions, and this would not cause a complete authentication failure for all users in the group.

135
MCQeasy

An ESXi host is connected to an iSCSI storage array using software iSCSI initiator. The administrator has configured two NICs for iSCSI traffic. During setup, the administrator selects 'Round Robin' as the path policy for the storage device. What is the benefit of this path policy?

A.It uses a single path until failure, then switches to another
B.It minimizes latency by always using the path with lowest latency
C.It load balances I/O across all active paths
D.It provides the highest performance for all workloads
AnswerC

Round Robin cycles I/O across every active path to the device, distributing load rather than using one path. With two iSCSI NICs configured, this policy uses both paths simultaneously, improving throughput and balancing traffic, unlike Fixed or Most Recently Used.

Why this answer

Round Robin is a VMware PSA (Pluggable Storage Architecture) path selection policy that actively distributes I/O across all active paths to a given device in a rotating fashion. With two iSCSI NICs configured, Round Robin sends commands down both paths, increasing aggregate throughput and utilizing both NICs simultaneously. This is the defining benefit of Round Robin compared to failover-only policies.

Exam trap

VCP-DCV often tests the confusion between path selection policies — candidates mix up Fixed (single path until failover), Round Robin (load balance across active paths), and Latency (prefer lowest-latency path), and pick the one that sounds most 'optimal' rather than the one matching the described behavior.

How to eliminate wrong answers

Option A is wrong because 'uses a single path until failure, then switches' describes the Fixed path policy, not Round Robin. Option B is wrong because 'always using the path with lowest latency' describes the Latency-based path policy (introduced in vSphere 6.5), which measures path latency and prefers the lowest. Option D is wrong because 'highest performance for all workloads' is an overgeneralization — Round Robin improves aggregate throughput but can actually reduce performance for workloads that benefit from path affinity or that are sensitive to out-of-order completion, and it is not universally the highest-performing policy.

136
MCQeasy

An administrator needs to create a datastore cluster for a set of VMs that require high availability. The VMs should be automatically balanced across datastores based on I/O latency. Which feature must be enabled on the datastore cluster?

A.Storage I/O Control (SIOC) on each datastore.
B.vSphere HA for the datastore cluster.
C.Storage DRS without I/O metric, using space only.
D.Storage DRS with I/O metric enabled.
AnswerD

Storage DRS with the I/O metric enabled satisfies the I/O latency balancing requirement: Storage DRS migrates VM disks between datastores in the cluster, and enabling the I/O metric makes it use observed latency and throughput, not just capacity, when generating migration recommendations.

Why this answer

Storage DRS with the I/O metric enabled uses datastore latency and I/O load (via SIOC) to make initial placement and ongoing balancing decisions, which is exactly what is needed to balance VMs across datastores based on I/O latency. Enabling the I/O metric is the specific setting that activates latency-aware recommendations.

Exam trap

The trap is conflating SIOC with Storage DRS — candidates pick SIOC because it deals with I/O latency, but SIOC only prioritizes and measures I/O; it is Storage DRS with the I/O metric that actually balances VMs across datastores.

How to eliminate wrong answers

Option A is wrong because SIOC alone provides I/O prioritization and latency stats but does not perform automated cross-datastore balancing — that is Storage DRS's job. Option B is wrong because vSphere HA is a compute-cluster availability feature for VM restart on host failure, not a datastore-cluster balancing feature. Option C is wrong because Storage DRS without the I/O metric balances only on space utilization, ignoring I/O latency entirely.

137
MCQhard

A vSphere administrator manages a cluster of 50 ESXi hosts using vLCM with image-based management. The cluster includes hosts from two different hardware vendors. The administrator needs to ensure firmware updates are consistently applied across all hosts. What is the best practice for this scenario?

A.Use baseline groups to manage firmware separately.
B.Create a single cluster image that includes firmware for both vendors.
C.Create separate cluster images for each hardware vendor and apply to respective hosts.
D.Manually update firmware using vendor tools, then use vLCM for ESXi updates.
AnswerC

Separate cluster images per vendor satisfy the stem's mixed-hardware constraint, because a vLCM image bundles vendor-specific firmware add-ons that only apply to matching hardware. A single image spanning both vendors would fail validation or skip firmware components, so splitting images ensures consistent firmware delivery across all 50 hosts.

Why this answer

In vLCM image-based management, a cluster image is a single desired-state specification that includes ESXi base image, vendor add-ons, and firmware add-ons. Firmware add-ons are hardware-vendor-specific (e.g., Dell, HPE, Lenovo), so a single image cannot contain firmware components for two different vendors. The correct best practice is to create separate cluster images per hardware vendor, each containing the appropriate vendor add-on and firmware add-on, and apply them to the respective hosts.

This ensures consistent firmware updates while respecting vendor-specific packaging.

Exam trap

VCP-DCV often tests the misconception that a single vLCM cluster image can include firmware for multiple hardware vendors, confusing the desired-state model with legacy baseline groups that could be combined.

How to eliminate wrong answers

Option A is wrong because baseline groups are a legacy vSphere Update Manager (VUM) construct, not part of vLCM image-based management; using them would abandon the desired-state model and not meet the requirement for consistent firmware updates via vLCM. Option B is wrong because a single cluster image cannot include firmware for both vendors—firmware add-ons are vendor-specific and mutually exclusive; attempting to combine them would cause validation errors or apply incorrect firmware. Option D is wrong because manual firmware updates via vendor tools break the vLCM desired-state model, introduce drift, and do not provide the consistent, automated firmware compliance that vLCM image-based management is designed to deliver.

138
MCQmedium

A VM with a large memory footprint is experiencing high swap rates. The host has free memory but the swap rate is still high. What is the most likely cause?

A.The VM's virtual machine swap file is on a slow datastore.
B.The VM's memory limit is set too low.
C.The host is using software iSCSI causing high latency.
D.The VM's memory reservation is set too high.
AnswerB

A configured memory limit caps the VM's usable guest RAM below what the workload needs, so ESXi swaps pages out even though the host has free physical memory. Raising or removing the limit lets the VM retain its working set in RAM.

Why this answer

A VM memory limit in vSphere caps the amount of host physical memory the VM can consume. When the limit is lower than the guest's working set, the VM balloons and then swaps to its .vswp file even though the host has free memory, because the limit — not host pressure — is driving reclamation. Raising or removing the limit resolves the swap.

Exam trap

VCP-DCV often tests the confusion between memory reservation and memory limit; candidates assume 'host has free memory' means no swapping, forgetting that a VM-level limit forces reclamation regardless of host capacity.

How to eliminate wrong answers

Option A is wrong because a slow datastore would increase swap latency but would not cause high swap rates when the host has free memory; the swap rate is driven by reclamation, not storage speed. Option C is wrong because software iSCSI latency affects storage I/O, not memory reclamation, and would not trigger swapping on a host with free RAM. Option D is wrong because a high reservation guarantees memory and reduces the likelihood of swapping — it does not cause it; reservations only fail to protect when the host is overcommitted, which is not the case here.

139
Multi-Selecteasy

An administrator is troubleshooting performance issues on a vSphere cluster. Which TWO metrics should be monitored to identify CPU ready time contention?

Select 2 answers
A.Disk Kernel Latency
B.Memory Swap In Rate
C.Co-Stop
D.Network Packet Drop Rate
E.%RDY (CPU Ready)
AnswersC, E

Co-Stop measures the percentage of time a symmetric multiprocessor virtual machine waits while its vCPUs are descheduled unevenly, directly exposing CPU ready time contention across the cluster. Monitoring it alongside CPU ready pinpoints whether oversized vCPU allocations or host overcommitment are starving virtual machines of physical cores.

Why this answer

CPU ready time contention occurs when a virtual machine is ready to execute instructions but the ESXi host's CPU scheduler cannot immediately allocate physical CPU cycles. The %RDY metric directly measures the percentage of time a VM is waiting to be scheduled on a physical CPU, while Co-Stop specifically tracks time lost when vCPUs in a single VM are forcibly co-scheduled and then descheduled due to contention on the same physical core. Both metrics are primary indicators of CPU scheduling pressure.

Exam trap

The trap here is that candidates confuse CPU ready time with memory or storage metrics, especially since high CPU ready time can manifest as general VM slowness, leading them to incorrectly select Disk Kernel Latency or Memory Swap In Rate instead of the correct CPU-specific counters.

140
MCQeasy

What is the default block size of a VMFS5 datastore?

A.1 MB
B.8 MB
C.2 MB
D.4 MB
AnswerA

VMFS5 uses a 1 MB file block size by default, replacing the 1 MB to 8 MB range available in VMFS3. This uniform block size supports volumes up to 64 TB and individual files up to 62 TB, satisfying the datastore capacity and large virtual disk requirements in the scenario.

Why this answer

The default block size of a VMFS5 datastore is 1 MB. VMFS5 introduced a unified 1 MB block size that supports large files up to 2 TB minus 512 bytes, eliminating the need for multiple block sizes. This default applies to all VMFS5 datastores unless upgraded from VMFS3.

Exam trap

VCP-DCV often tests the difference between VMFS3 and VMFS5 block sizes; candidates may remember VMFS3's 8 MB default or confuse it with VMFS5's 1 MB default.

How to eliminate wrong answers

Option B is wrong because 8 MB was a possible block size in VMFS3, not the default for VMFS5. Option C is wrong because 2 MB was not a standard VMFS block size; VMFS3 offered 1, 2, 4, and 8 MB, but VMFS5 uses 1 MB. Option D is wrong because 4 MB was a VMFS3 block size option, not the VMFS5 default.

141
MCQmedium

An administrator is configuring storage performance for a vSphere cluster that runs a mix of I/O-intensive databases and general-purpose VMs. The storage array is capable of providing high IOPS, but the administrator wants to ensure that the database VMs receive preferential treatment during periods of storage contention. The administrator has created a datastore cluster and enabled Storage DRS. Which additional configuration should be applied to meet this requirement?

A.Create a separate datastore for the database VMs and place it on a dedicated LUN.
B.Configure Storage DRS to use the 'I/O latency' threshold and set it to a low value.
C.Enable Storage I/O Control on the datastore cluster and set shares on the database VMs' virtual disks.
D.Set a storage limit on the general-purpose VMs to restrict their I/O usage.
AnswerC

Storage I/O Control (SIOC) allows you to set shares on virtual disks, which determines their relative priority for I/O resources when the datastore experiences contention. By enabling SIOC and assigning higher shares to database VMs, they receive preferential treatment during congestion. This directly addresses the requirement for preferential I/O treatment during contention.

Why this answer

Storage I/O Control (SIOC) is the correct solution because it enables per-virtual-disk share-based prioritization when a datastore becomes congested. By assigning higher shares to database VMs, they receive a larger portion of I/O resources during contention, ensuring preferential treatment without isolating storage or resorting to limits.

Exam trap

The trap here is confusing Storage DRS, which handles initial placement and migration, with Storage I/O Control, which manages runtime I/O prioritization during contention.

142
Multi-Selecthard

Which THREE are valid methods to isolate and secure management traffic on a vSphere Distributed Switch? (Choose three.)

Select 3 answers
A.Enable Route based on IP hash on the management port group.
B.Assign a specific VLAN ID to the management port group.
C.Use Private VLANs on the management port group.
D.Configure the ESXi firewall to restrict management access.
E.Create a dedicated VMkernel port group for management.
AnswersB, D, E

VLANs provide isolation.

Why this answer

Assigning a specific VLAN ID to the management port group isolates management traffic at Layer 2 by tagging frames with a unique VLAN identifier. This prevents unauthorized access from other VLANs and ensures that management traffic is logically separated from other network traffic on the same vSphere Distributed Switch.

Exam trap

The trap here is that candidates often confuse load-balancing policies (like Route based on IP hash) with security features, or they overcomplicate isolation by choosing Private VLANs instead of the simpler and more reliable VLAN assignment.

143
MCQmedium

A company has multiple clusters with different hardware. They want to create separate vLCM images for each cluster. What is the best practice?

A.Create a single image that includes all possible components.
B.Use baseline groups instead of images.
C.Create separate images for each cluster tailored to their hardware.
D.Use Auto Deploy with a single image.
AnswerC

Hardware-specific firmware add-ons cannot be shared across dissimilar hosts, so a single image would flag mismatches. Creating one image per cluster, tailored to its hardware, keeps each cluster compliant and is the documented vLCM best practice.

Why this answer

vLCM (vSphere Lifecycle Manager) images are cluster-scoped and must match the hardware compatibility of the hosts in that cluster. Because the company has multiple clusters with different hardware, the best practice is to create a separate image per cluster, tailoring the firmware add-on, driver add-on, and ESXi base image to that cluster's specific server models. This ensures HCL compliance and avoids remediation failures caused by incompatible drivers.

Exam trap

VCP-DCV often tests the misconception that a single vLCM image can serve heterogeneous clusters, or that baseline groups are still the recommended approach — candidates must recognize that image-based management is cluster-scoped and hardware-specific.

How to eliminate wrong answers

Option A is wrong because a single image containing all possible components would include drivers and firmware for hardware not present in each cluster, causing HCL violations and remediation errors — vLCM images are validated against the actual host hardware. Option B is wrong because baseline groups are the legacy vSphere Update Manager (VUM) approach; vLCM image-based management is the modern replacement and the question explicitly states image-based management is in use. Option D is wrong because Auto Deploy is a stateless provisioning mechanism, not an image management strategy, and a single image across heterogeneous hardware would fail HCL checks.

144
MCQeasy

A vSphere cluster has DRS enabled and hosts with unbalanced resource usage. Which DRS feature automatically migrates VMs to balance CPU and memory loads across hosts?

A.High Availability (HA)
B.Distributed Resource Scheduler (DRS)
C.Enhanced vMotion Compatibility (EVC)
D.Storage I/O Control (SIOC)
AnswerB

DRS continuously monitors and balances resource usage by migrating VMs.

Why this answer

DRS (Distributed Resource Scheduler) uses vMotion to migrate VMs based on resource utilization thresholds, balancing workloads across hosts. HA provides failover, EVC ensures compatibility, and SIOC manages storage I/O.

145
MCQhard

An administrator has a vSphere 7 cluster with vMotion enabled. They need to perform a vMotion of a VM from host1 to host2 while preserving the VM's memory state. The VM has a PCIe passthrough device assigned (NVMe controller). What should the administrator do before initiating the vMotion?

A.Use shared storage for the VM
B.Remove the PCIe passthrough device from the VM
C.Enable Enhanced vMotion Compatibility (EVC) on the cluster
D.Upgrade to vSphere 8
AnswerB

vMotion cannot preserve memory state when a PCIe passthrough device is attached, because direct device assignment pins the VM to host1's hardware. Removing the passthrough device first makes the VM migratable, allowing memory-state vMotion to host2.

Why this answer

vMotion does not support VMs with PCIe passthrough devices because the device is tied to the physical host. The device must be removed or the VM must be powered off.

146
MCQhard

An administrator is troubleshooting a performance issue where a VM is not receiving the expected CPU resources. The VM is a member of a resource pool with a CPU Shares value of 2000. The host has two other resource pools: one with 1000 shares and another with 500 shares. All resource pools are competing for CPU. The VM's reservation is set to 2 GHz, and the host has 8 GHz available. What is the minimum CPU allocation the VM is guaranteed?

A.4 GHz (based on share ratio)
B.2 GHz
C.8 GHz (all host CPU)
D.0 GHz (no guarantee without reservation)
AnswerB

A reservation is a guaranteed minimum, not a share-based entitlement. The VM's 2 GHz reservation is fully covered by the host's 8 GHz capacity, so regardless of the competing resource pools' shares, the VM is guaranteed at least 2 GHz.

Why this answer

The VM's reservation of 2 GHz guarantees that the host will reserve at least that amount of CPU capacity for the VM, regardless of contention or share values. Shares only affect the distribution of excess resources beyond reservations, not the guaranteed minimum. Since the host has 8 GHz available, the reservation is fully satisfiable, so the VM is guaranteed 2 GHz.

Exam trap

The trap here is that candidates often confuse shares with reservations, assuming that a higher share value guarantees more CPU, when in fact only a reservation provides a hard guarantee, and shares only affect the distribution of unused capacity.

How to eliminate wrong answers

Option A is wrong because it incorrectly applies the share ratio (2000:1000:500 = 4:2:1) to the total host CPU, but shares only determine proportional allocation of unreserved resources, not guaranteed minimums. Option C is wrong because a reservation of 2 GHz does not guarantee all 8 GHz of host CPU; the VM is limited to its reservation unless additional resources are available and shares allow it. Option D is wrong because a reservation explicitly provides a guaranteed minimum allocation; without a reservation, the VM would have no guarantee, but here a reservation is set.

147
MCQmedium

An administrator is adding an ESXi host to vCenter Server and is prompted to verify the host's certificate thumbprint. The administrator compares it to the output above and it matches. However, the add operation fails with a certificate verification error. What else could be the issue?

A.The vCenter Server's certificate is invalid
B.The certificate has expired
C.The certificate is not signed by a trusted Certificate Authority
D.The certificate common name does not match the hostname
AnswerD

Thumbprint matching only proves the certificate's authenticity, not its identity. vCenter also validates that the certificate's common name or subject alternative name matches the hostname or IP used to add the host, so a mismatch there still triggers verification failure despite the correct thumbprint.

Why this answer

When adding an ESXi host to vCenter Server, the thumbprint verification ensures the host's certificate fingerprint matches what is expected, but it does not validate the certificate's subject attributes. If the certificate's Common Name (CN) does not match the ESXi host's FQDN or IP address used during the add operation, vCenter Server will reject the connection with a certificate verification error, even if the thumbprint is correct. This is because vCenter Server performs hostname verification as part of TLS/SSL certificate validation to prevent man-in-the-middle attacks.

Exam trap

The trap here is that candidates assume thumbprint verification alone guarantees certificate validity, overlooking that vCenter Server also performs hostname matching as part of TLS certificate validation.

How to eliminate wrong answers

Option A is wrong because the vCenter Server's certificate is not directly involved in the host certificate verification during the add operation; the error is about the ESXi host's certificate. Option B is wrong because an expired certificate would typically cause a different error (e.g., 'certificate has expired') and would not pass thumbprint verification if the thumbprint was generated from the current certificate. Option C is wrong because vCenter Server does not require the ESXi host's certificate to be signed by a trusted CA for thumbprint verification; it only checks the thumbprint match, and the error here is specifically about hostname mismatch, not trust chain issues.

148
MCQeasy

During a vLCM remediation, one host fails with error 'Could not complete the operation due to a network error'. What is the first troubleshooting step?

A.Reset the vLCM image.
B.Check network connectivity between vCenter and the host.
C.Restart the vLCM service.
D.Reboot the host.
AnswerB

The error explicitly cites a network problem, so verifying connectivity between vCenter and the ESXi host is the logical first step. Remediation depends on that channel, and a dropped or blocked connection would halt the operation before any configuration issue matters.

Why this answer

The error 'Could not complete the operation due to a network error' during vLCM remediation indicates that vCenter Server lost communication with the ESXi host mid-operation. Since vLCM remediation pushes an image payload from vCenter to the host over the management network, the first logical step is to verify that vCenter can reach the host on the management VMkernel interface (typically port 443 and 902). Confirming connectivity rules out transient network issues before touching the vLCM image or host state.

Exam trap

VCP-DCV often tests whether candidates jump to remediation actions (reset image, restart service, reboot) instead of performing basic connectivity troubleshooting first when the error message explicitly names a network condition.

How to eliminate wrong answers

Option A is wrong because resetting the vLCM image discards the desired-state configuration and does not address the underlying connectivity failure that produced the error. Option C is wrong because restarting the vLCM service on vCenter does not fix a network path problem between vCenter and the host, and would only be relevant if the service itself were hung. Option D is wrong because rebooting the host is a disruptive action that should never be the first step when the error explicitly points to a network condition.

149
MCQhard

A vSphere administrator is configuring a vSphere Distributed Switch (vDS) with multiple uplinks. The environment requires that vMotion traffic and virtual machine traffic use separate physical uplinks to avoid contention. The administrator creates two distributed port groups: one for vMotion and one for VM traffic. Which vDS feature should be used to ensure that vMotion traffic uses only vmnic2 and VM traffic uses only vmnic3?

A.Configure Network I/O Control (NIOC) with shares and reservations for the vMotion and VM traffic.
B.Use the teaming and failover policy on each distributed port group to specify active and standby uplinks.
C.Create a LAG and assign vmnic2 and vmnic3 to it, then configure NIOC to prioritize vMotion.
D.Assign each port group to a different VLAN and rely on VLAN tagging to direct traffic to the correct uplink.
AnswerB

By setting the teaming and failover policy on the vMotion port group to use vmnic2 as active and vmnic3 as standby, and on the VM port group to use vmnic3 as active and vmnic2 as standby, the administrator ensures that each traffic type uses its designated uplink. This provides the required separation and also offers failover protection if one uplink fails.

Why this answer

The teaming and failover policy on a distributed port group allows you to specify which physical uplinks are active and which are standby for that port group. By configuring the vMotion port group to use vmnic2 as active and vmnic3 as standby, and the VM port group to use vmnic3 as active and vmnic2 as standby, traffic is separated onto distinct uplinks. This also provides redundancy in case of uplink failure.

Exam trap

The trap here is confusing bandwidth prioritization (NIOC) with physical uplink selection, which is controlled by teaming and failover policies.

150
Multi-Selecthard

Which TWO storage performance best practices should be followed when scaling a vSphere environment using shared storage? (Choose two.)

Select 2 answers
A.Use Raw Device Mapping in physical compatibility mode for virtual machines.
B.Enable Storage I/O Control (SIOC) on datastores to manage I/O latency.
C.Configure multiple storage paths with round-robin load balancing policy.
D.Deploy vSphere Flash Read Cache to reduce read latency.
E.Use VMFS-3 for large datastores to reduce seek time.
AnswersB, C

SIOC applies per-datastore I/O shares and latency thresholds, throttling noisy-neighbour VMs when datastore latency exceeds a set limit. This directly satisfies the shared-storage scaling constraint by preventing one workload from starving others of I/O throughput.

Why this answer

Option B is correct because Storage I/O Control (SIOC) lets vSphere enforce per-datastore I/O latency thresholds and fairly share I/O among virtual machines when a shared datastore becomes congested, which is a recommended best practice for scaling shared storage. Option C is correct because configuring multiple paths to the shared LUN and using the round-robin path selection policy (PSP) enables multipathing, increases aggregate bandwidth, and provides path failover for better performance and availability at scale. Option A is not a general performance best practice; Raw Device Mapping in physical compatibility mode is used mainly for clustering or SAN-specific requirements and can limit vSphere features.

Option D is not a scaling best practice for shared storage because vSphere Flash Read Cache is a host-local read cache and does not address shared-storage scalability. Option E is incorrect because VMFS-3 is an obsolete version with datastore size and scalability limits compared with VMFS-5/VMFS-6, and it does not reduce seek time.

Exam trap

VCP-DCV often tests the confusion between legacy/deprecated features (Flash Read Cache, VMFS-3, RDM) and current best practices (SIOC, multipathing) — candidates pick RDM thinking it improves performance when it is actually a niche compatibility feature.

Page 1

Page 2 of 4

Page 3

All pages