Courseiva

VMware Certified Professional Data Center Virtualization VCP-DCV (VCP-DCV) — Questions 151–225

281 questions total · 4pages · All types, answers revealed

Page 2

Page 3 of 4

Page 4
151
MCQeasy

An administrator is configuring multipathing for a Fibre Channel storage array. The administrator wants to maximize throughput by using all available paths. Which path selection policy should be chosen?

A.Fixed (VMW_PSP_FIXED)
B.Most Recently Used (VMW_PSP_MRU)
C.Vendor-specific (VMW_PSP_FIXED_AP)
D.Round Robin (VMW_PSP_RR)
AnswerD

Round Robin (VMW_PSP_RR) satisfies the requirement to use all available paths by rotating I/O across every active path in the set, rather than confining traffic to a single preferred path. This maximises aggregate throughput for the Fibre Channel array, since each path carries a share of the load concurrently.

Why this answer

Round Robin (VMW_PSP_RR) is the only path selection policy that actively distributes I/O across all available paths to a given device in a round-robin fashion, thereby maximizing throughput by utilizing all paths simultaneously. It is the default PSP for most block storage arrays in ESXi and is recommended for active-active arrays. By cycling through each path, it avoids saturating a single path and can significantly improve performance.

This aligns with the administrator's goal of using all available paths to maximize throughput.

Exam trap

VCP-DCV often tests the misconception that MRU or Fixed can load balance, but only Round Robin actively distributes I/O across all paths for throughput.

How to eliminate wrong answers

Option A is wrong because Fixed (VMW_PSP_FIXED) uses only the single preferred path and does not utilize other available paths unless the preferred path fails, so it cannot maximize throughput. Option B is wrong because Most Recently Used (VMW_PSP_MRU) uses only one path at a time (the most recently used) and switches only upon path failure, not for load balancing. Option C is wrong because Vendor-specific (VMW_PSP_FIXED_AP) is a policy that uses a fixed path with array-specific failover behavior, not active load balancing across all paths.

152
MCQeasy

A resource pool has the following configuration: CPU shares = 4000, reservation = 2 GHz, limit = 4 GHz. The parent cluster has 10 GHz total CPU capacity. Another resource pool contains VMs with higher shares. If both resource pools contend for CPU, which statement is TRUE?

A.The pool is guaranteed 4 GHz when contention occurs.
B.The reservation is ignored because a limit is set.
C.The pool will always receive exactly 4 GHz due to its shares.
D.The pool will receive at least 2 GHz and at most 4 GHz.
AnswerD

Reservations guarantee a floor and limits impose a ceiling, independent of shares. Shares only arbitrate contention above the reservation. The pool therefore receives no less than its 2 GHz reservation and never exceeds its 4 GHz limit, even when the other pool holds higher shares.

Why this answer

A resource pool's reservation guarantees a minimum CPU allocation (2 GHz) during contention, while the limit caps the maximum it can consume (4 GHz). Shares only determine relative priority when contention occurs — they do not guarantee an exact amount. Therefore the pool is guaranteed at least 2 GHz and can use up to 4 GHz.

Exam trap

VCP-DCV often tests the confusion between reservation (guaranteed minimum), limit (maximum cap), and shares (relative priority) — candidates conflate shares with a guaranteed allocation or mistake the limit for the reservation.

How to eliminate wrong answers

Option A is wrong because the reservation is 2 GHz, not 4 GHz — 4 GHz is the limit (maximum), not the guaranteed minimum. Option B is wrong because reservations and limits are independent settings; a limit does not cause the reservation to be ignored — the reservation still guarantees the minimum. Option C is wrong because shares determine relative priority during contention, not an exact allocation — the pool will not 'always receive exactly 4 GHz' just because of its shares.

153
Multi-Selecteasy

An administrator is managing a vSphere cluster with vSphere Lifecycle Manager baselines. Which THREE are valid baseline types? (Choose three.)

Select 3 answers
A.Patch baseline
B.Firmware baseline
C.Upgrade baseline
D.Critical Hosts baseline
E.Extension baseline
AnswersA, C, E

Patch baselines are a valid vSphere Lifecycle Manager baseline type, grouping ESXi patches and updates for remediation across hosts. They satisfy the stem's requirement by letting administrators scan and remediate clusters against curated patch collections, distinct from upgrade and extension baselines, which handle version upgrades and additional components respectively.

Why this answer

In vSphere Lifecycle Manager, baselines are categorized into three valid types: Patch, Upgrade, and Extension. Option A (Patch baseline) is correct because patch baselines contain a collection of patches (VIBs) that can be applied to hosts to update or remediate them without changing the major ESXi version. Option C (Upgrade baseline) is correct because upgrade baselines contain an ESXi image that upgrades hosts to a new major version (for example, from ESXi 7 to ESXi 8).

Option E (Extension baseline) is correct because extension baselines contain additional VIBs, such as third-party drivers or custom extensions, that are not part of the standard patch or upgrade process. Option B (Firmware baseline) is not a valid baseline type in vSphere Lifecycle Manager baselines; firmware updates are handled through firmware add-ons in desired-state images, not baselines. Option D (Critical Hosts baseline) is not a valid baseline type; there is no such baseline category in vSphere Lifecycle Manager.

Exam trap

VCP-DCV often tests the boundary between baseline types and image-based management, tricking candidates into selecting 'firmware baseline' because firmware is a real vLCM concept — but it belongs to images, not baselines.

154
MCQmedium

A security administrator notices that a virtual machine (VM) running a legacy application is experiencing network connectivity issues after enabling Network I/O Control (NIOC) on the distributed switch. The VM is in a high-priority traffic class for management traffic. What is the most likely cause of the issue?

A.NIOC is blocking the VM's MAC address due to a security policy.
B.The VM is assigned to the management traffic class, but its traffic should be in a different class, causing bandwidth throttling.
C.The VM is using jumbo frames, which are not supported with NIOC.
D.The virtual switch has promiscuous mode enabled, which conflicts with NIOC.
AnswerB

Misclassifying the legacy VM's traffic as management places it under Network I/O Control's management share allocation, which throttles bandwidth when the physical uplinks are saturated. NIOC enforces per-traffic-class shares, so traffic belonging in a virtual machine class instead competes against management reservations, producing the connectivity issues described.

Why this answer

Network I/O Control (NIOC) on a vSphere Distributed Switch enforces bandwidth allocation based on traffic classes such as management, vMotion, iSCSI, and VM traffic. If a VM's traffic is incorrectly classified into the management traffic class, it is subject to that class's share, reservation, and limit, which can throttle the VM's bandwidth and cause connectivity issues. The most likely cause is misclassification of the VM's traffic into the wrong NIOC traffic class.

Exam trap

The trap is assuming NIOC blocks traffic or conflicts with MTU/promiscuous settings — the real issue is traffic-class misclassification causing bandwidth throttling.

How to eliminate wrong answers

Option A is wrong because NIOC does not block MAC addresses; MAC-based security is handled by port-level security policies (allow/promiscuous/MAC changes), not NIOC. Option C is wrong because NIOC is independent of MTU settings; jumbo frames are supported with NIOC as long as the MTU is configured consistently on the vSwitch, VMkernel, and physical uplinks. Option D is wrong because promiscuous mode is a security policy on port groups and does not conflict with NIOC bandwidth allocation.

155
MCQmedium

A company runs a critical SQL Server VM on vSphere 7.0. The VM has a single 300 GB virtual disk on a VMFS6 datastore backed by a SAN with 8 Gbps Fibre Channel. The VM is configured with 16 vCPUs and 64 GB RAM. Recently, users have reported slow query performance. The administrator checks the datastore performance and sees average latency of 15 ms with peaks of 50 ms during business hours. The storage array has multiple paths to the ESXi host, and the current path policy is Fixed with a single active path. The administrator wants to improve storage performance with minimal cost. Which action should the administrator take first?

A.Change the path selection policy to Round Robin on the ESXi host.
B.Add a vSphere Flash Read Cache to the VM.
C.Upgrade the Fibre Channel infrastructure to 16 Gbps.
D.Convert the virtual disk to thin provisioning to reduce I/O.
AnswerA

Round Robin spreads I/O across all active Fibre Channel paths, using the array's available bandwidth instead of one path. With Fixed policy, a single path bottlenecks at 15–50 ms latency, so this change is free and immediate.

Why this answer

The current Fixed path policy with a single active path underutilizes the available storage bandwidth, causing high latency during peak I/O. Changing to Round Robin (RR) distributes I/O across all available paths, reducing queue depth on any single path and lowering latency without any hardware cost. This is the most immediate and cost-effective fix for the observed performance issue.

Exam trap

The trap here is that candidates may assume hardware upgrades (like faster Fibre Channel) are the only solution to high latency, overlooking the fact that a misconfigured path policy can cause a single path to become a bottleneck even when multiple paths exist.

How to eliminate wrong answers

Option B is wrong because vSphere Flash Read Cache is deprecated in vSphere 7.0 and only accelerates read operations, not writes; the SQL Server workload likely involves significant write I/O, and adding it would not address the path-level bottleneck. Option C is wrong because upgrading the Fibre Channel infrastructure to 16 Gbps is a costly hardware change that does not fix the root cause—the single active path policy—and may not reduce latency if the bottleneck is path saturation rather than link speed. Option D is wrong because converting to thin provisioning does not improve I/O performance; it can actually increase latency due to on-demand allocation overhead and does not affect the path selection or queue depth issue.

156
MCQhard

A vSphere administrator is designing a new cluster for a workload that requires high memory bandwidth and low latency. The physical hosts have 512 GB of RAM each, and the VMs are expected to have large memory footprints. The administrator wants to ensure that memory overcommitment is minimized and that VM memory is backed by physical RAM as much as possible. Which configuration should be applied to the VMs to achieve this?

A.Configure the VM to use large memory pages and set a memory reservation of 50% of the configured memory.
B.Set a memory reservation equal to the configured memory size for each VM.
C.Set a memory limit equal to the configured memory size and enable memory ballooning.
D.Enable memory compression and set a memory limit equal to the configured memory size.
AnswerB

A memory reservation guarantees that the specified amount of physical RAM is reserved for the VM. Setting it equal to the configured memory size ensures that the VM's entire memory is backed by physical RAM, eliminating memory overcommitment for that VM. This provides predictable performance and low latency, which is critical for high-bandwidth workloads.

Why this answer

Setting a memory reservation equal to the VM's configured memory size ensures that all of the VM's memory is backed by physical RAM, preventing overcommitment and guaranteeing low-latency memory access. This is the most direct way to meet the requirement for high memory bandwidth and minimal overcommitment.

Exam trap

The trap here is confusing memory limits with reservations; limits cap usage but do not guarantee physical RAM allocation, while reservations do.

157
MCQhard

A vSphere administrator is using vSphere Lifecycle Manager (vLCM) to manage a cluster with a single image. After a recent hardware upgrade, one host in the cluster has a new network adapter that is not listed in the vSphere Compatibility Guide for the current ESXi version. The administrator attempts to remediate the cluster. What will happen?

A.The remediation will succeed, but the network adapter will be disabled until a compatible driver is installed.
B.The remediation will proceed, but the host will be marked as non-compliant after the update.
C.The remediation will succeed, and vLCM will automatically download and install the required driver from the internet.
D.The remediation will fail with an error indicating that the host hardware is not compatible with the image.
AnswerD

vLCM validates the desired image against each host's hardware compatibility. If a network adapter is not on the vSphere Compatibility Guide for the target ESXi version, the host fails the compatibility check, and remediation cannot proceed. The error will explicitly state the incompatibility.

Why this answer

vLCM enforces hardware compatibility before remediation. A network adapter not on the vSphere Compatibility Guide for the target ESXi version causes the host to be non-compliant, and remediation fails with a compatibility error. The correct answer reflects this pre-check behavior.

Exam trap

The trap here is thinking that vLCM will attempt remediation and then report issues, rather than blocking the update upfront due to hardware incompatibility.

158
MCQmedium

An administrator needs to capture traffic from a specific virtual machine for troubleshooting. Which vSphere networking feature should be used?

A.Port mirroring on the VDS.
B.LLDP on the VDS.
C.NetFlow on the VDS.
D.Traffic shaping on the VDS.
AnswerA

Port mirroring on a vSphere Distributed Switch copies frames from a source VM's dvPort to a destination dvPort or uplink, satisfying the requirement to capture one specific virtual machine's traffic without disrupting its connectivity. Standard vSwitches lack this capability, so the VDS is required.

Why this answer

Port mirroring on a vSphere Distributed Switch (VDS) copies traffic from a source VM's vNIC (or uplink) to a destination port where a packet analyzer is attached. It is the purpose-built feature for capturing VM traffic for troubleshooting, supporting both ingress/egress directions and multiple session types.

Exam trap

VCP-DCV often tests the distinction between monitoring features — port mirroring (packet capture), NetFlow (flow metadata), and LLDP (topology discovery) — baiting candidates who conflate them.

How to eliminate wrong answers

Option B is wrong because LLDP is a link-layer discovery protocol used to advertise switch identity and topology, not to capture traffic. Option C is wrong because NetFlow exports flow metadata (IPs, ports, byte counts) for traffic analysis, not full packet captures. Option D is wrong because traffic shaping controls bandwidth allocation and burst limits, not packet duplication for analysis.

159
Matchingmedium

Match each vSphere security feature to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Virtual Trusted Platform Module for VM encryption

Restricts direct root access to ESXi

Single sign-on authentication for vSphere

Replaces default certificates with custom ones

Encrypts vMotion traffic between hosts

Why these pairings

The correct matches are: ESXi Firewall controls network traffic, VM Encryption encrypts VM files, and vTPM provides virtual TPM. Common confusions involve swapping these definitions.

160
MCQhard

A vSphere administrator notices that VMs on a specific ESXi host lose connectivity intermittently. The VMs are on a distributed switch port group. The administrator finds that the Uplink 1 on that host is down. What should the administrator do first?

A.Increase the number of uplinks in the teaming policy
B.Check the physical switch port configuration for the failed uplink
C.Set the load balancing policy to Route based on source MAC
D.Configure a different failover order
AnswerB

A down uplink usually stems from the physical layer, so verify the connected switch port's configuration, VLAN trunking and status before touching vSphere settings. This identifies whether the fault lies with the physical switch or cabling.

Why this answer

When an uplink is down on a host attached to a distributed switch, the first step is to verify the physical layer — the physical switch port, cable, and SFP — because the most common cause is a physical link failure or misconfiguration on the upstream switch. Only after confirming the physical layer should you adjust vSphere teaming or failover settings.

Exam trap

VCP-DCV often tests whether candidates jump to vSphere-level remediation (teaming, failover order) instead of first checking the physical network layer, which is the actual root cause in most uplink-down scenarios.

How to eliminate wrong answers

Option A is wrong because adding uplinks to the teaming policy does not fix a down physical link and is not a first troubleshooting step. Option C is wrong because changing the load balancing policy does not restore a failed uplink and may mask the real issue. Option D is wrong because reconfiguring failover order is a workaround, not a diagnosis, and should come after confirming why Uplink 1 is down.

161
MCQhard

Based on the exhibit, what is the most likely cause of the remediation failure?

A.The local depot is not configured.
B.The DNS server is unable to resolve depot.vmware.com.
C.The vLCM service is not running on vCenter.
D.A firewall is blocking outbound HTTPS traffic to the internet.
AnswerD

vSphere Lifecycle Manager pulls firmware and software payloads from online depots over HTTPS. If outbound HTTPS to the internet is blocked, remediation cannot download the components, so the task fails while hardware compatibility checks may still pass.

Why this answer

A firewall blocking outbound HTTPS traffic to the internet would cause a connection timeout when vSphere Lifecycle Manager (vLCM) tries to reach the public VMware depot. This matches the error shown in the exhibit. Option A is incorrect because the local depot is not the source of the timeout; the issue is with external connectivity.

Option B is incorrect because a DNS resolution failure would typically produce a 'Name or service not known' error, not a timeout. Option C is incorrect because if the vLCM service were not running, the error would likely indicate a service unavailability, not a network timeout.

162
MCQeasy

A company has a cluster of 4 ESXi hosts. They want to ensure that virtual machines are automatically distributed evenly across hosts based on CPU and memory load. Which feature should be enabled on the cluster?

A.vSphere HA
B.Fault Tolerance
C.vSphere DRS
D.Distributed Power Management
AnswerC

vSphere DRS continuously balances VM placement across hosts by migrating workloads with vMotion based on CPU and memory demand, directly satisfying the requirement for automatic even distribution. Enabling it on the cluster activates initial placement plus ongoing load-balancing, which HA alone cannot provide.

Why this answer

DRS (Distributed Resource Scheduler) automatically balances VM loads based on resource usage. HA provides high availability, FT provides fault tolerance, and DPM manages host power.

163
MCQeasy

A vSphere administrator needs to ensure that a specific virtual machine's network traffic is isolated from all other virtual machines on the same ESXi host, even if they are on the same VLAN. Which vSphere networking feature should the administrator use?

A.Private VLANs (PVLANs) on a vSphere Distributed Switch
B.Network I/O Control (NIOC) on a vSphere Distributed Switch
C.VLAN tagging on the virtual machine's vNIC
D.Traffic shaping on a standard switch port group
AnswerA

Private VLANs allow isolation of virtual machines at layer 2 by using secondary VLANs. A PVLAN can isolate ports so that VMs cannot communicate with each other even if they are on the same primary VLAN. This provides the required isolation without changing the VLAN of the VMs.

Why this answer

Private VLANs (PVLANs) on a vSphere Distributed Switch enable isolation of virtual machines at layer 2 by using secondary VLANs. This allows VMs on the same primary VLAN to be isolated from each other, which is not possible with standard VLAN tagging alone. NIOC, traffic shaping, and VLAN tagging do not provide this level of isolation.

Exam trap

The trap here is thinking that VLAN tagging alone can isolate VMs; VMs on the same VLAN can still communicate unless PVLANs are used.

164
MCQmedium

Refer to the exhibit. A virtual machine on the VM Network is experiencing intermittent connectivity. The administrator notices that vmnic0 is saturated. Which action would improve performance without causing a single point of failure?

A.Change the active uplinks for VM Network to vmnic1 only.
B.Increase the MTU on vSwitch0 to 9000.
C.Configure load-based teaming on vSwitch0 for the VM Network portgroup.
D.Move the VM Network to vSwitch1.
AnswerC

Load-based teaming distributes traffic across physical uplinks according to current load, relieving the saturated vmnic0 while retaining multiple adapters so no single NIC becomes a point of failure. Route-based policies would not balance the existing flows causing saturation.

Why this answer

Load-based teaming (LBT) on vSwitch0 dynamically balances VM traffic across all active uplinks based on real-time utilization, so vmnic0's load is shared with vmnic1, relieving saturation. It also maintains redundancy because both uplinks remain active; if one fails, the other takes over. This directly addresses the intermittent connectivity caused by vmnic0 saturation without introducing a single point of failure.

Exam trap

VCP-DCV often tests the misconception that simply changing the active uplink or increasing MTU will solve saturation, when the real solution requires dynamic load balancing across multiple uplinks without sacrificing redundancy.

How to eliminate wrong answers

Option A is wrong because setting vmnic1 as the only active uplink for VM Network removes vmnic0 from the team, creating a single point of failure and leaving vmnic0's saturation unaddressed for other traffic. Option B is wrong because increasing MTU to 9000 does not reduce congestion on a saturated uplink; it only reduces per-packet overhead, which is negligible for typical VM traffic and may cause fragmentation if the physical network doesn't support jumbo frames. Option D is wrong because moving the VM Network to vSwitch1 does not guarantee that vSwitch1 has additional uplinks or that the traffic will be balanced; it could simply shift the problem or create a new single point of failure if vSwitch1 has only one uplink.

165
MCQmedium

Refer to the exhibit. A distributed virtual switch port shows dropped Rx packets and CRC errors. What is the most likely cause?

A.Faulty physical network cable or NIC.
B.Outdated NIC driver on the ESXi host.
C.MTU mismatch between the switch and the VM.
D.Incorrect VLAN configuration on the port group.
AnswerA

CRC errors and dropped receive packets indicate corrupted frames arriving at the physical layer, typically from a damaged cable, faulty NIC, or bad transceiver. This points to the physical medium rather than switch policy or VLAN misconfiguration.

Why this answer

CRC errors and dropped Rx packets on a distributed virtual switch port indicate physical-layer corruption of frames, typically caused by a faulty cable, damaged NIC, or bad transceiver. These errors occur when the cyclic redundancy check (CRC) computed by the receiver does not match the frame's CRC field, which is a direct symptom of signal integrity issues at Layer 1.

Exam trap

The trap here is that candidates confuse CRC errors (Layer 1 physical corruption) with MTU mismatch or VLAN misconfiguration (Layer 2/3 issues), leading them to select options that address logical configuration rather than physical cabling faults.

How to eliminate wrong answers

Option B is wrong because an outdated NIC driver would more likely cause driver-level errors, timeouts, or device disconnections, not CRC errors which are physical-layer corruption. Option C is wrong because an MTU mismatch causes fragmentation or packet drops at Layer 3, not CRC errors; CRC errors are Layer 1 issues. Option D is wrong because an incorrect VLAN configuration would result in connectivity failures or traffic being dropped at Layer 2, but it would not cause CRC errors, which are purely physical-layer corruption.

166
Multi-Selecthard

Which THREE factors should be considered when sizing a host cluster for a VDI environment with 1000 desktops? (Choose three.)

Select 3 answers
A.vMotion compatibility between hosts.
B.NUMA alignment of virtual desktops.
C.Storage IOPS capacity for boot storms.
D.vCPU-to-core ratio to prevent CPU contention.
E.Memory overcommitment ratio and available memory per host.
AnswersC, D, E

Storage IOPS capacity directly addresses the boot-storm constraint: when 1000 desktops power on simultaneously, concentrated read/write bursts can saturate the datastore and stall logons. Sizing must account for peak concurrent IOPS, not steady-state averages, since VMware's linked-clone and full-clone desktops both amplify boot-time demand.

Why this answer

Option C is correct because boot storms in a 1000-desktop VDI environment generate massive concurrent storage I/O, so the datastore's IOPS capacity (and latency) must be sized to absorb peak demand without degrading performance. Option D is correct because VDI workloads are CPU-intensive, so the vCPU-to-physical-core ratio must be kept within acceptable limits (typically 4:1 to 8:1 depending on workload) to prevent CPU contention and ready time. Option E is correct because memory is usually the most constrained resource in VDI; the memory overcommitment ratio and per-host available memory must be calculated so that each desktop receives its required working set without excessive swapping or ballooning.

Option A is not a sizing factor but a design/operational requirement for cluster mobility, and Option B, while relevant to performance tuning, is not a primary capacity-sizing factor for the cluster.

Exam trap

The trap here is that candidates often confuse operational features (like vMotion compatibility) with true capacity-sizing factors, or they mistakenly think NUMA alignment is a sizing input rather than a post-deployment optimization.

167
MCQeasy

A vSphere administrator is evaluating the performance of a new cluster. The administrator notices that the CPU ready time for a particular VM is consistently above 10%. The host has 24 physical cores and is running 30 VMs, each with 2 vCPUs. Which action would most directly reduce the CPU ready time for this VM?

A.Migrate the VM to a host with fewer VMs using vMotion.
B.Enable CPU affinity for the VM to pin it to specific cores.
C.Increase the CPU shares of the VM to High.
D.Increase the number of vCPUs assigned to the VM.
AnswerA

CPU ready time indicates that the VM is waiting for physical CPU resources. Moving the VM to a less utilized host reduces contention, allowing the scheduler to allocate CPU cycles more quickly. This directly addresses the root cause by balancing the workload across the cluster. vMotion is a non-disruptive way to achieve this.

Why this answer

High CPU ready time means the VM is waiting for physical CPU resources. The most direct way to reduce it is to decrease contention on the host. Migrating the VM to a host with fewer VMs via vMotion reduces the number of vCPUs competing for physical cores, allowing the scheduler to allocate CPU time more quickly.

Other options either increase demand or do not address the root cause.

Exam trap

The trap here is thinking that adding more vCPUs or increasing shares will solve CPU ready time, when in fact they can exacerbate the problem or are ineffective under heavy overcommitment.

168
Multi-Selecteasy

Which two factors most directly influence vSphere NUMA scheduling decisions for a VM? (Choose two.)

Select 2 answers
A.Host NUMA node topology
B.VM memory reservation
C.Number of vCPUs
D.VM storage policy
E.Virtual machine version
AnswersA, C

The host's physical NUMA node topology determines which memory and CPU resources are local to each other, so vSphere bases its initial placement and any rebalancing on that layout. Without knowing the node boundaries, the scheduler cannot keep a VM's vCPUs and memory within one node.

Why this answer

Option A (Host NUMA node topology) is correct because vSphere's NUMA scheduler bases its placement decisions on the physical NUMA node layout of the ESXi host, including how many nodes exist, how many cores and how much memory each node contains, and the relative latency between nodes; a VM's vCPUs and memory are placed to keep them within a single node whenever possible. Option C (Number of vCPUs) is correct because a VM's vCPU count determines whether it can fit inside one NUMA node: if the vCPU count exceeds the cores in a single node, the VM becomes wide and vSphere must span multiple NUMA nodes, changing the scheduling behavior (and potentially enabling vNUMA). Option B is not a primary factor because a memory reservation affects admission control and whether memory is backed by reserved physical pages, not the NUMA placement logic itself.

Option D is unrelated since a VM storage policy governs datastore placement and storage services such as IOPS limits or encryption, not CPU/memory NUMA scheduling. Option E is also unrelated because the virtual machine version (hardware compatibility level) determines available virtual hardware features, not how the NUMA scheduler places the VM's vCPUs and memory.

Exam trap

VCP-DCV often tests whether candidates confuse NUMA scheduling factors with resource allocation settings like reservations or limits, which affect admission control but not NUMA placement.

169
MCQmedium

A company's vSphere environment has multiple clusters with varying workloads. The operations team notices that one cluster consistently shows high CPU ready times on several hosts. Which action should be taken to address this performance issue?

A.Increase the memory allocation of VMs with high CPU ready times.
B.Increase the CPU reservation for VMs with high ready times.
C.Reduce the number of virtual CPUs assigned to VMs and consider adding more hosts.
D.Enable Storage DRS to balance storage I/O load.
AnswerC

High CPU ready indicates VMs are waiting for physical CPU cycles, so reducing vCPUs cuts scheduling contention and adding hosts increases available cores. This directly relieves the oversubscription driving the elevated ready times across that cluster's hosts.

Why this answer

High CPU ready times indicate that VMs are contending for physical CPU resources because the host is over-provisioned with vCPUs relative to available pCPUs. Reducing the number of vCPUs per VM decreases scheduling overhead and contention, while adding more hosts increases the total pCPU count, directly alleviating the bottleneck. Option C correctly addresses both the demand-side (vCPU reduction) and supply-side (host addition) of the CPU scheduling issue.

Exam trap

The trap here is that candidates confuse CPU ready time with memory pressure or storage latency, leading them to choose memory or storage-related solutions instead of addressing the core CPU over-provisioning issue.

How to eliminate wrong answers

Option A is wrong because increasing memory allocation does not reduce CPU contention; it may even increase memory overhead without affecting CPU scheduling. Option B is wrong because increasing CPU reservation guarantees CPU time for specific VMs but does not reduce overall contention; it can actually worsen ready times for other VMs by reserving resources that could otherwise be shared. Option D is wrong because Storage DRS balances storage I/O load, not CPU scheduling; high CPU ready times are a compute issue, not a storage issue.

170
MCQmedium

The administrator configured this LAG on a distributed switch and corresponding LACP settings on the physical switch. But the LAG is not coming up. What is a likely issue?

A.The load balancing policy should be IP hash.
B.The LAG name is not used by the physical switch.
C.The LAG mode is passive, but the physical switch is also configured as passive.
D.The uplinks should be in active/active mode.
AnswerC

LACP requires at least one side to initiate negotiation by sending LACPDUs. With both the distributed switch LAG and the physical switch set to passive, neither transmits, so no aggregation forms. Configuring the vSphere side as active satisfies the requirement that one endpoint actively initiates the LAG.

Why this answer

When both the vSphere distributed switch LAG and the physical switch are configured in passive mode, LACP negotiation fails because neither side initiates the negotiation. One side must be set to active for LACP to establish. Option A is incorrect because the load balancing policy (e.g., IP hash) is separate from LACP mode; it controls traffic distribution, not LACP negotiation.

Option B is incorrect because the LAG name is not used by LACP; LACP uses system identifiers and port keys, so a name mismatch does not prevent the LAG from coming up. Option D is incorrect because active/active mode refers to the uplink teaming policy, not the LACP mode setting.

171
MCQeasy

An administrator has created a standard vSwitch port group with VLAN ID 100. Virtual machines in this port group can communicate with each other but not with devices on the physical network. What is a possible cause?

A.The vSwitch has only one uplink.
B.The virtual machines have duplicate MAC addresses.
C.The physical switch port is not configured to pass VLAN 100.
D.The virtual machines are using different subnets.
AnswerC

A standard vSwitch port group tags egress frames with VLAN 100, but if the physical switch port is left as an access port on a different VLAN, or lacks VLAN 100 in its allowed list, tagged frames are dropped. This breaks the uplink path to physical devices while intra-host traffic still flows.

Why this answer

When a standard vSwitch port group is assigned VLAN ID 100, the ESXi host tags outbound frames with VLAN 100 (802.1Q). For those frames to reach the physical network, the physical switch port that the uplink connects to must be configured as a trunk that permits VLAN 100. If the physical switch port is an access port on a different VLAN or does not allow VLAN 100, traffic stays isolated within the virtual switch, which is exactly the symptom described.

Exam trap

VCP-DCV often tests whether candidates assume the problem is inside vSphere (uplinks, MACs, subnets) when the actual cause is the physical switch port not trunking the required VLAN — a classic 'look outside the hypervisor' trap.

How to eliminate wrong answers

Option A is wrong because having only one uplink does not prevent external communication — a single uplink can still carry VLAN 100 traffic if the physical switch port is configured correctly. Option B is wrong because duplicate MAC addresses would cause intermittent connectivity or MAC flapping, not a clean isolation where VMs talk to each other but never reach the physical network. Option D is wrong because different subnets would prevent VM-to-VM communication too (absent routing), but the scenario states VMs can communicate with each other, so subnetting is not the cause.

172
MCQeasy

A company has a single ESXi host with a standard switch. The administrator creates a new port group for a DMZ network and assigns a VM to it. The VM cannot ping the default gateway. The physical switch port is configured as a trunk with VLAN 100 allowed. The port group VLAN ID is set to 100. The physical NIC is connected to the switch port and shows link up. What should the administrator do to resolve the issue?

A.Enable VLAN tagging on the physical switch port
B.Change the VLAN ID to 0
C.Verify the VM's IP configuration
D.Add a second physical NIC to the standard switch
AnswerC

With the trunk allowing VLAN 100 and the port group tagged 100, the virtual switching path is already correct, so the fault lies inside the guest. Checking the VM's IP configuration verifies its address, subnet mask and default gateway before further changes.

Why this answer

The physical switch port is already configured as a trunk allowing VLAN 100, and the port group VLAN ID is correctly set to 100, so the virtual networking layer is properly tagged. The most likely remaining cause is that the VM itself has an incorrect IP address, subnet mask, or default gateway setting for the DMZ subnet. Verifying the guest OS IP configuration is the correct next troubleshooting step.

Exam trap

VCP-DCV often tests whether candidates jump to switch or vSwitch configuration changes when the real fault is inside the guest OS — always verify the VM's IP settings before altering network infrastructure.

How to eliminate wrong answers

Option A is wrong because the physical switch port is already configured as a trunk with VLAN 100 allowed, so enabling VLAN tagging again is redundant and not the issue. Option B is wrong because setting the port group VLAN ID to 0 would place the VM on the native/untagged VLAN, which would break DMZ connectivity rather than fix it. Option D is wrong because adding a second physical NIC does not address a guest-level IP misconfiguration and is unnecessary for a single-VM connectivity problem.

173
MCQhard

An administrator is planning a vCenter Server deployment for a large environment with 15 ESXi hosts and 300 VMs. The environment requires high availability for vCenter Server. Which deployment topology should the administrator choose?

A.A Windows vCenter Server with a mirrored SQL database.
B.A VCSA configured with vCenter HA (active-passive).
C.A single VCSA with an embedded database.
D.A VCSA deployed with an external Platform Services Controller.
AnswerB

vCenter HA uses an active-passive node arrangement with a witness, providing automatic failover of the vCenter Server appliance. For 15 hosts and 300 VMs, this meets the high-availability requirement without relying on manual restoration or external database clustering.

Why this answer

vCenter HA (active-passive) is the native, supported high-availability solution for VCSA, providing automatic failover between an active, passive, and witness node. For a large environment (15 hosts, 300 VMs) requiring vCenter HA, this topology ensures minimal downtime and is the recommended approach in modern vSphere versions.

Exam trap

VCP-DCV often tests the deprecated Windows vCenter/external PSC topologies as distractors, causing candidates to pick legacy architectures that sound robust (mirrored SQL, external PSC) but are no longer supported or do not provide true HA.

How to eliminate wrong answers

Option A is wrong because Windows vCenter Server with a mirrored SQL database is a legacy, deprecated architecture (Windows vCenter was deprecated in vSphere 6.7 and removed in 7.0) and does not provide the same automated failover as vCenter HA. Option C is wrong because a single VCSA with an embedded database has no redundancy — a failure takes down vCenter entirely. Option D is wrong because an external Platform Services Controller is a deprecated topology (PSC was embedded by default starting in vSphere 6.7) and does not by itself provide vCenter HA.

174
MCQmedium

An administrator notices that HTTP connections to the ESXi host are timing out frequently. Based on the exhibit, which configuration change would most likely resolve the issue?

A.Increase maxKeepAliveTimeout to a higher value, such as 180
B.Restart the rhttpproxy service
C.Set useProxy to true and specify a proxy server
D.Set maxKeepAliveTimeout to 0 to disable keepalive
AnswerA

Raising maxKeepAliveTimeout extends how long ESXi holds idle HTTP connections open before closing them, directly addressing the frequent timeouts caused by premature connection teardown under the exhibit's load. The constraint is persistent client sessions needing longer idle windows, which the default timeout cuts short.

Why this answer

Increasing maxKeepAliveTimeout to a higher value, such as 180, would most likely resolve the issue of HTTP connections timing out frequently. The maxKeepAliveTimeout setting controls how long the ESXi host's reverse proxy (rhttpproxy) keeps an HTTP connection open for keep-alive requests. If it is too low, connections may time out prematurely, causing frequent timeouts.

Increasing it allows longer-lived connections.

Exam trap

The trap is thinking that restarting the service or disabling keep-alive solves the problem, when the actual fix is to adjust the timeout value. Candidates may also confuse this with proxy settings, which are unrelated to inbound connection timeouts.

How to eliminate wrong answers

Option B is wrong because restarting the rhttpproxy service might temporarily alleviate the issue but does not address the root cause of frequent timeouts due to a low timeout value. Option C is wrong because setting useProxy to true and specifying a proxy server is for environments where ESXi must use a proxy to reach external resources; it does not affect inbound HTTP connection timeouts. Option D is wrong because setting maxKeepAliveTimeout to 0 disables keep-alive, which would cause connections to close after each request, likely worsening the timeout issue.

175
MCQhard

A company uses an external Platform Services Controller (PSC) in a vSphere 6.7 environment. They plan to upgrade to vSphere 7.0. Which security-related consideration is most important?

A.The external PSC will automatically convert to an embedded PSC during upgrade.
B.The external PSC is deprecated; it must be converged into the vCenter Server.
C.The SSL certificates for the PSC must be reissued from a new CA.
D.The STS certificates need to be replaced with custom ones immediately after upgrade.
AnswerB

External Platform Services Controller deployments are deprecated in vSphere 7.0, so the PSC services must be converged into the vCenter Server during upgrade. This convergence is the critical security and supportability consideration for the migration.

Why this answer

In vSphere 7.0, external Platform Services Controllers (PSC) are deprecated and must be converged into the vCenter Server during upgrade. This convergence simplifies management and improves security by reducing the attack surface. The upgrade process requires a topology change to embedded PSC.

Exam trap

VCP-DCV often tests the deprecation of external PSC and the requirement to converge, but candidates may assume automatic conversion or focus on certificate issues instead.

How to eliminate wrong answers

Option A is wrong because the external PSC does not automatically convert; a manual convergence process is required before or during upgrade. Option C is wrong because while certificates are important, reissuing from a new CA is not a mandatory security consideration for the upgrade; existing certificates can often be reused. Option D is wrong because STS certificates do not need immediate replacement after upgrade; they are managed automatically and only need replacement if they expire or are compromised.

176
MCQeasy

A security audit requires that all ESXi hosts in a vSphere 7.0 environment use encrypted connections for remote logging. An administrator configures the syslog service on each host to send logs to a central server. Which setting should be enabled to ensure the logs are transmitted over TLS?

A.Set the syslog.global.logHost parameter to tcp://logserver.example.com:1514 and enable the ESXi firewall rule for syslog.
B.Set the syslog.global.logHost parameter to ssl://logserver.example.com:1514.
C.Set the syslog.global.logHost parameter to ssl://logserver.example.com:514.
D.Set the syslog.global.logHost parameter to udp://logserver.example.com:514 and enable log signing.
AnswerB

The ssl:// prefix in syslog.global.logHost instructs ESXi to use TLS for remote logging. Port 1514 is commonly used for secure syslog. This configuration ensures logs are encrypted in transit. The administrator must also ensure the remote server supports TLS on that port. This meets the requirement for encrypted connections. No additional firewall rule is needed if the default rules allow outbound syslog.

Why this answer

To encrypt remote syslog traffic from ESXi, configure the syslog.global.logHost parameter with the ssl:// prefix and the correct port, typically 1514. This uses TLS to protect log data in transit. Other protocols like tcp:// or udp:// do not provide encryption, and log signing does not encrypt.

The ssl:// setting directly satisfies the requirement for encrypted connections.

Exam trap

The trap here is using tcp:// or udp:// and assuming they provide encryption, when only ssl:// enables TLS for syslog.

177
MCQeasy

An organization wants to migrate a VM from one vCenter Server to another without shutting down the VM. Both vCenter Servers are in Enhanced Linked Mode. Which migration method should the administrator use?

A.Cold migration
B.Cross-vCenter vMotion
C.Storage vMotion
D.Export the VM as OVF and import it to the other vCenter
AnswerB

Cross-vCenter vMotion moves a running VM's compute and storage between vCenter Servers while it stays powered on, with no downtime. Enhanced Linked Mode provides the shared SSO and inventory visibility this migration requires across both vCenters.

Why this answer

Cross-vCenter vMotion (option B) is the correct method because it allows a live, zero-downtime migration of a running VM between vCenter Server instances, even when both are in Enhanced Linked Mode. This feature uses the vMotion protocol to transfer memory and execution state across vCenter boundaries without requiring shared storage, as long as the source and destination hosts are in the same vCenter Single Sign-On domain and meet compatibility requirements.

Exam trap

The trap here is that candidates may confuse Enhanced Linked Mode with the ability to perform any migration between vCenters, but only Cross-vCenter vMotion supports live migration; Storage vMotion and OVF export/import are often incorrectly chosen because they are associated with moving VMs without understanding the vCenter boundary limitation.

How to eliminate wrong answers

Option A is wrong because cold migration requires the VM to be powered off, which contradicts the requirement of not shutting down the VM. Option C is wrong because Storage vMotion only moves the VM's virtual disks between datastores within the same vCenter Server, not between different vCenter Server instances. Option D is wrong because exporting a VM as OVF and importing it to another vCenter Server requires the VM to be powered off (or at least quiesced) and involves significant downtime, not a live migration.

178
MCQeasy

Which vSphere component is responsible for managing the lifecycle of ESXi hosts, including patching and upgrading?

A.vSphere Lifecycle Manager
B.Host Profiles
C.Auto Deploy
D.vSphere Distributed Resource Scheduler
AnswerA

vSphere Lifecycle Manager manages ESXi host remediation through desired-state images, applying patches and upgrades across clusters. It satisfies the stem's lifecycle requirement by basing host compliance on a single image, unlike baselines or standalone update tools, and integrates directly with vCenter Server for orchestrated remediation.

Why this answer

vSphere Lifecycle Manager (vLCM) is the correct component because it is specifically designed to manage the lifecycle of ESXi hosts, including patching, upgrading, and firmware/driver updates. It uses desired-state management to ensure hosts conform to a specified image or baseline, automating the entire update process across clusters.

Exam trap

The trap here is that candidates often confuse Host Profiles (which manage configuration) with lifecycle management, or they think Auto Deploy handles patching because it deploys images, but Auto Deploy is for initial provisioning, not ongoing patching of existing hosts.

How to eliminate wrong answers

Option B (Host Profiles) is wrong because Host Profiles capture and apply host-level configuration settings (e.g., networking, storage) but do not manage patching or upgrading of ESXi software. Option C (Auto Deploy) is wrong because Auto Deploy provisions ESXi hosts from a central image repository using PXE boot, but it does not handle patching or upgrading of already-deployed hosts; it is primarily for stateless or stateful deployment. Option D (vSphere Distributed Resource Scheduler) is wrong because DRS manages workload placement and resource balancing across hosts in a cluster, not host software lifecycle tasks like patching or upgrading.

179
MCQeasy

A network administrator needs to isolate traffic between VMs in the same VLAN on a distributed switch. Which feature should be used?

A.Network I/O Control
B.Private VLAN
C.VLAN trunking
D.Traffic shaping
E.Port binding
AnswerB

Private VLANs subdivide a single VLAN into isolated secondary VLANs, preventing VM-to-VM traffic on the same segment while permitting promiscuous uplinks. This delivers the required Layer 2 isolation on a distributed switch, which port groups alone cannot enforce between members of one VLAN.

Why this answer

Private VLANs (PVLANs) on a vSphere Distributed Switch allow Layer 2 isolation between VMs in the same VLAN by using primary and secondary VLANs with promiscuous, isolated, and community port types. This is the specific feature designed to prevent VM-to-VM traffic within a single VLAN while still allowing communication with a gateway or designated promiscuous ports. It directly addresses the requirement to isolate same-VLAN VM traffic.

Exam trap

VCP-DCV often tests the confusion between bandwidth features (NIOC, traffic shaping) and isolation features (PVLAN), catching candidates who pick a QoS option for a segmentation requirement.

How to eliminate wrong answers

Option A is wrong because Network I/O Control manages bandwidth allocation and shares, not L2 traffic isolation between VMs. Option C is wrong because VLAN trunking carries multiple VLANs over one uplink; it does not isolate traffic within a single VLAN. Option D is wrong because traffic shaping controls average bandwidth, peak bandwidth, and burst size — it has no isolation function.

Option E is wrong because port binding determines how a VM's vNIC is assigned to a dvPort (static, dynamic, ephemeral), not whether VMs can communicate with each other.

180
Multi-Selectmedium

An administrator is designing a vSphere 8 environment that will use vSphere Distributed Resource Scheduler (DRS) in a cluster. The administrator wants to ensure that DRS can automate the initial placement of virtual machines and provide recommendations for migration. Which two components are required for DRS to function? (Choose two.)

Select 2 answers
A.vSAN datastore
B.vSphere Distributed Switch (vDS)
C.vSphere High Availability (HA)
D.vCenter Server
E.ESXi hosts with compatible CPUs for vMotion
AnswersD, E

DRS is a vCenter Server feature; it requires vCenter Server to collect resource usage data from ESXi hosts, calculate migration recommendations, and perform automated vMotion migrations. Without vCenter Server, DRS cannot operate. The administrator must have a vCenter Server instance managing the cluster.

Why this answer

DRS requires vCenter Server to manage the cluster and ESXi hosts with compatible CPUs for vMotion. vCenter Server provides the centralized management and automation, while CPU compatibility ensures that vMotion migrations can occur. vSphere HA, vDS, and vSAN are not prerequisites for DRS.

Exam trap

The trap here is assuming that vSphere HA or a vSphere Distributed Switch is required for DRS, when they are separate features that can be used independently.

181
MCQhard

A company uses vSphere 7 with vLCM. They want to update hosts in a cluster with a new ESXi version. The cluster has mixed hardware. What is the recommended method?

A.Use vSphere Update Manager baseline
B.Manually upload ISO to each host
C.Use cluster image management
D.Use Auto Deploy
AnswerC

Cluster image management applies a single desired-state image across all hosts, letting vLCM remediate each host to the target ESXi version while validating against its specific hardware. This handles mixed hardware without per-host baselines, which is the recommended vSphere 7 approach.

Why this answer

For a vSphere 7 cluster with mixed hardware managed by vLCM, the recommended method to update ESXi is cluster image management. vLCM's cluster image is a single desired-state image that includes the ESXi base version plus vendor add-ons and firmware/driver add-ons, and it handles hardware diversity by letting you include the appropriate vendor add-ons for each host model.

Exam trap

VCP-DCV often tests the distinction between the legacy VUM baseline model and the vLCM image model — candidates who default to 'baseline' answers miss that vLCM clusters use cluster images, not baselines.

How to eliminate wrong answers

Option A is wrong because vSphere Update Manager baselines are the legacy (pre-vLCM) approach and do not provide the desired-state image model that vLCM uses; baselines are still supported but not the recommended method for vLCM-managed clusters. Option B is wrong because manually uploading an ISO to each host is error-prone, does not scale, and bypasses vLCM's compliance tracking entirely. Option D is wrong because Auto Deploy is a stateless provisioning mechanism for booting ESXi hosts from images, not the update method for an existing vLCM cluster with mixed hardware.

182
MCQeasy

What is the purpose of the 'Export System Logs' option in vSphere Lifecycle Manager?

A.Collect logs for troubleshooting
B.Create a recovery image
C.Back up configuration
D.Transfer logs to vCenter
AnswerA

Export System Logs bundles vSphere Lifecycle Manager and related service logs into a downloadable archive, giving support and administrators the diagnostic evidence needed to troubleshoot remediation, compliance, or sync failures without manually gathering files from each component.

Why this answer

The 'Export System Logs' option in vSphere Lifecycle Manager (vLCM) is designed to gather diagnostic information from the vLCM components, including the vLCM service logs, image depot logs, and related vCenter Server logs. This bundled log archive is used by VMware support and administrators to troubleshoot issues such as image compliance failures, remediation errors, or depot synchronization problems. It does not create backups or recovery images; it is purely a diagnostic tool.

Exam trap

VCP-DCV often tests the distinction between diagnostic and backup/recovery functions, so candidates may confuse 'Export System Logs' with configuration backup or image export features.

How to eliminate wrong answers

Option B is wrong because creating a recovery image is not the purpose of exporting logs; recovery images are typically created via backup solutions or vSphere Replication, not vLCM. Option C is wrong because backing up configuration involves exporting vCenter configuration data (e.g., via VAMI or vSphere Client), not system logs. Option D is wrong because transferring logs to vCenter is not the primary goal; logs are exported to a local file or a remote syslog server, not specifically to vCenter, and vLCM already runs on vCenter.

183
MCQeasy

A vSphere administrator needs to add a new VMFS6 datastore to an ESXi 7.0 host. The storage array has presented a 2 TB LUN to the host. The administrator wants to ensure the datastore uses the entire LUN and is aligned correctly. Which action should the administrator take?

A.Use the ESXi Shell to run partedUtil to create a GPT partition and then format it with vmkfstools.
B.Use the vSphere Client to create a new VMFS6 datastore but specify a smaller extent to leave room for snapshots.
C.Use the vSphere Client to create a new VMFS6 datastore and manually set the partition alignment to 64 KB for performance.
D.Use the vSphere Client to create a new VMFS6 datastore and select the entire LUN as the extent.
AnswerD

Creating a VMFS6 datastore through the vSphere Client automatically handles partition alignment and uses the entire LUN if selected. VMFS6 supports large volumes and automatically aligns partitions to the recommended 1 MB boundary. This is the simplest and most reliable method to ensure correct alignment and full LUN utilization without manual partitioning.

Why this answer

The vSphere Client's datastore creation wizard automatically aligns VMFS6 partitions to the optimal 1 MB boundary and uses the entire LUN when selected. This ensures correct alignment and full capacity utilization without manual intervention. Manual partitioning or leaving unallocated space is unnecessary and can introduce errors.

Exam trap

The trap here is thinking that manual partitioning or leaving unallocated space is required for alignment or snapshot space, when the vSphere Client handles alignment automatically.

184
MCQmedium

Refer to the exhibit. An administrator cannot resolve the hostname of a DNS server using the ESXi host. What is the most likely cause?

A.The search domain is incorrectly set to localdomain.
B.The DNS servers are unreachable.
C.The DNS servers are not configured correctly for the domain.
D.The ESXi host is not configured to use DNS.
AnswerC

The hostname resolution failed, indicating the DNS server cannot resolve the name.

185
MCQmedium

An administrator is configuring a vSAN cluster with all-flash capacity. The cluster uses RAID-5 erasure coding with a policy of 'Number of failures to tolerate = 1' (PFTT=1). The administrator wants to minimize storage overhead while ensuring availability. Which vSAN storage policy setting should be used?

A.Set 'Primary level of failures to tolerate' to 1 and 'Primary level of failures to tolerate method' to 'RAID-1 (Mirroring)'
B.Set 'Primary level of failures to tolerate' to 2 and 'Primary level of failures to tolerate method' to 'RAID-6 (Erasure Coding)'
C.Set 'Primary level of failures to tolerate' to 1 and 'Primary level of failures to tolerate method' to 'RAID-5 (Erasure Coding)'
D.Set 'Primary level of failures to tolerate' to 0
AnswerC

RAID-5 erasure coding with PFTT=1 delivers roughly 1.33x overhead versus 2x for RAID-1 mirroring, satisfying the all-flash minimum-overhead constraint while still tolerating one host failure. The policy must explicitly select the RAID-5 method, not RAID-1.

Why this answer

For an all-flash vSAN cluster with PFTT=1, RAID-5 erasure coding provides the lowest storage overhead (approximately 1.33x) while still tolerating one failure. Setting the primary level of failures to tolerate to 1 and the method to RAID-5 (Erasure Coding) achieves the administrator's goal of minimizing overhead while maintaining availability.

Exam trap

VCP-DCV often tests whether candidates know the minimum host requirements and overhead ratios for vSAN RAID-5 vs RAID-6, and candidates frequently pick RAID-1 assuming it is always the most efficient or forget that erasure coding requires all-flash.

How to eliminate wrong answers

Option A is wrong because RAID-1 mirroring with PFTT=1 requires 2x storage overhead, which does not minimize storage consumption compared to RAID-5. Option B is wrong because PFTT=2 with RAID-6 requires a minimum of 6 hosts and incurs higher overhead (approximately 1.5x), and the question specifies PFTT=1. Option D is wrong because PFTT=0 provides no redundancy at all, violating the availability requirement.

186
MCQhard

A company has a vSphere 7.0 cluster with 6 ESXi hosts connected to a Dell EMC PowerStore array using iSCSI. They are using VMFS6 datastores. After a recent firmware upgrade on the array, they notice that performance on one datastore has degraded significantly. The datastore is used by several high-I/O VMs. The administrator runs 'esxcli storage core path list' and sees that all paths to that datastore are active but with varying latency. The PSP is set to Round Robin with IOPS limit of 1000. The SATP is VMW_SATP_ALUA. The storage administrator confirms that the array is in active-active mode. What should the administrator do to improve performance?

A.Enable the array's QoS policy and configure the datastore for VAAI.
B.Change the PSP to Most Recently Used (MRU) to reduce path thrashing.
C.Increase the Round Robin IOPS limit to 10000.
D.Change the SATP to VMW_SATP_DEFAULT_AA and reconfigure the iSCSI initiator.
AnswerC

Raising the Round Robin IOPS limit to 10000 lets the PSP switch paths more frequently, spreading I/O across all active-active array ports instead of saturating one path for 1000 IOPS. Since VMW_SATP_ALUA reports every path active, the current limit concentrates load, causing the latency variance observed.

Why this answer

The Round Robin PSP with an IOPS limit of 1000 is causing the ESXi host to switch paths too frequently, which can lead to higher latency due to path thrashing and suboptimal use of the array's active-active ALUA mode. Increasing the Round Robin IOPS limit to 10000 reduces the frequency of path switches, allowing each path to handle more I/Os before switching, which improves performance for high-I/O workloads on VMFS6 datastores.

Exam trap

The trap here is that candidates often assume a higher IOPS limit will cause more path switching and latency, when in fact the opposite is true—a low IOPS limit causes thrashing, and increasing it stabilizes performance on active-active arrays.

How to eliminate wrong answers

Option A is wrong because enabling QoS on the array does not directly address path switching behavior, and VAAI is a storage offload feature that does not resolve high latency from path thrashing. Option B is wrong because changing the PSP to MRU would use only one active path, negating the benefits of the active-active array and likely worsening performance for high-I/O VMs. Option D is wrong because VMW_SATP_DEFAULT_AA is a legacy SATP for active-active arrays without ALUA, and changing to it would break the ALUA path selection logic, potentially causing incorrect path states or failover issues.

187
Multi-Selectmedium

Which TWO actions can help reduce network latency for a latency-sensitive VM in a vSphere environment? (Choose two.)

Select 2 answers
A.Use a standard virtual switch instead of a distributed switch.
B.Configure NetQueue on the physical NIC.
C.Enable SR-IOV on the physical NIC and assign the virtual function to the VM.
D.Enable jumbo frames on the virtual switch.
E.Disable TCP segmentation offload on the VM.
AnswersB, C

NetQueue offloads packet classification and filtering from the VMkernel to the physical NIC, letting the adapter steer flows into separate receive queues. This parallelises interrupt handling across CPU cores, cutting per-packet processing delay for the latency-sensitive VM's traffic. It directly satisfies the stem's requirement to reduce network latency in a vSphere environment.

Why this answer

Option B is correct because NetQueue allows the physical NIC to use multiple receive queues and distribute network traffic across multiple CPUs, reducing per-packet processing latency and improving throughput for latency-sensitive workloads. Option C is correct because SR-IOV lets the VM bypass the virtual switch datapath by directly accessing a virtual function on the physical NIC, which significantly lowers latency and CPU overhead. Option A is incorrect because a standard vSwitch versus a distributed switch does not inherently reduce network latency; both are software-based datapaths.

Option D is incorrect because jumbo frames reduce per-packet overhead and CPU utilization but do not directly lower latency, and they require end-to-end MTU consistency. Option E is incorrect because disabling TCP segmentation offload increases CPU overhead and can degrade, not improve, network performance.

Exam trap

The trap here is that candidates often confuse throughput-enhancing features (like jumbo frames or TSO) with latency-reducing features, failing to recognize that SR-IOV and NetQueue directly address packet processing overhead and interrupt handling.

188
Drag & Dropmedium

Order the steps to perform a vMotion migration of a powered-on virtual machine.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Prerequisites check, initiate migration, select type, choose destination, and confirm.

189
MCQhard

An administrator is using vSphere Lifecycle Manager (vLCM) to manage a cluster with a single image. The image includes a base ESXi image and a vendor add-on. During remediation, the task fails with the error: 'Cannot remediate host because the desired image contains a component that is not compatible with the host.' Which action should the administrator take first to resolve this issue?

A.Remove the incompatible component from the image and remediate again.
B.Update the host's firmware to the latest version and retry remediation.
C.Remove the host from the cluster and add it back.
D.Check the vSphere Compatibility Guide for the component's supported hardware and ESXi versions.
AnswerD

The error indicates a compatibility issue. The first step is to verify whether the component is supported on the host's hardware and ESXi version. The vSphere Compatibility Guide provides this information. This helps determine if the component can be used or if an alternative is needed.

Why this answer

When vLCM remediation fails due to an incompatible component, the administrator must first determine why the component is incompatible. The vSphere Compatibility Guide lists supported hardware, drivers, and ESXi versions for components. Checking it helps identify if the component is supported on the host or if an update or alternative is needed.

This systematic approach avoids unnecessary changes.

Exam trap

The trap here is jumping to remove the component or update firmware without first verifying compatibility, which could lead to further issues or not resolve the root cause.

190
MCQhard

A vSphere administrator is planning a Storage DRS implementation for a datastore cluster containing multiple VMFS datastores. The VMs have various I/O patterns. Some VMs should always remain together on the same datastore. Which configuration should be used?

A.Create a VM-to-VM affinity rule in the datastore cluster.
B.Set individual datastore affinity rules on each host.
C.Apply Storage I/O Control with high shares to the VMs.
D.Create a VM-to-VM anti-affinity rule in the datastore cluster.
AnswerA

VM-to-VM affinity rules keep specified virtual machines together on the same datastore within the datastore cluster. This satisfies the requirement that certain VMs must always remain co-located, which Storage DRS would otherwise separate during automated migrations.

Why this answer

Storage DRS supports VM-to-VM affinity rules within a datastore cluster, which ensure that specified VMs are always placed on the same datastore. This is the correct configuration when VMs must remain together, such as for application clusters that require shared storage locality or licensing constraints. The rule is enforced during initial placement and during Storage DRS migrations.

Exam trap

VCP-DCV often tests the confusion between compute-level DRS rules (host affinity) and storage-level DRS rules (datastore affinity), causing candidates to select host-based options for a storage placement requirement.

How to eliminate wrong answers

Option B is wrong because datastore affinity rules are configured at the datastore cluster level, not per host; host-level rules govern compute placement (vSphere DRS), not storage placement. Option C is wrong because Storage I/O Control with high shares prioritizes I/O throughput for specific VMs but does not control which datastore they reside on, so it cannot keep VMs together. Option D is wrong because a VM-to-VM anti-affinity rule does the opposite — it forces VMs onto separate datastores, which directly contradicts the requirement that they remain together.

191
MCQeasy

A company plans to deploy a new homogeneous cluster with vSphere 8. They want to use vLCM to simplify lifecycle management. What is the recommended approach for maintaining the ESXi hosts?

A.Define a single cluster image and apply it to all hosts.
B.Manually upgrade each host via ISO and then import into vLCM.
C.Use vSphere baselines to manage patches.
D.Create separate images for each host based on its hardware.
AnswerA

A single cluster image satisfies the homogeneous hardware constraint, letting vLCM manage every host against one desired-state specification. Because all hosts share identical components, firmware and driver add-ons apply uniformly, avoiding per-host baselines. vLCM then remediates drift automatically, keeping the whole cluster compliant with the image.

Why this answer

vLCM (vSphere Lifecycle Manager) uses a desired-state model where a single cluster image defines the ESXi base image, vendor add-on, and firmware. Applying one image to all hosts in a homogeneous cluster ensures consistency and simplifies patching and upgrades.

Exam trap

VCP-DCV often tests vLCM vs VUM baselines — candidates pick 'baselines' because they are familiar with older vSphere versions, missing that vLCM image-based management is the recommended approach for vSphere 8 homogeneous clusters.

How to eliminate wrong answers

Option B is wrong because manually upgrading each host via ISO defeats the purpose of vLCM and introduces drift; vLCM is designed to manage the entire lifecycle from a single image. Option C is wrong because vSphere baselines are the legacy vSphere Update Manager (VUM) approach; vLCM replaces baselines with images for image-managed clusters. Option D is wrong because creating separate images per host based on hardware contradicts the 'homogeneous cluster' premise and increases management overhead; vLCM images are per-cluster, not per-host.

192
MCQeasy

An administrator wants to configure the ESXi host firewall to allow connections only from a specific management subnet. How can this be achieved?

A.Enable vSphere HA and set it to control management traffic.
B.Use the ESXi firewall settings to define allowed IP addresses for the required services.
C.Configure the DCUI to restrict management access.
D.Set the firewall to enabled and allow all incoming connections.
AnswerB

Defining allowed IP addresses per service in the ESXi firewall directly enforces the management-subnet restriction, since each rule's allowedIP list filters inbound traffic at the host level. This satisfies the stem's requirement to permit connections only from that subnet, without relying on external network controls.

Why this answer

ESXi's built-in firewall allows you to restrict each service (e.g., SSH, vSphere Client, vMotion) to specific IP addresses or subnets via the 'Allowed IP addresses' list in the firewall ruleset. By editing the ruleset for the management services and specifying the management subnet, you limit connections to only those sources.

Exam trap

The trap is thinking that vSphere HA, DCUI, or a blanket firewall enablement can restrict management access by subnet; only the per-ruleset allowed IP list in the ESXi firewall does this.

How to eliminate wrong answers

Option A is wrong because vSphere HA is a clustering availability feature and has nothing to do with firewall or management traffic filtering. Option C is wrong because the DCUI is a local console interface for host configuration and does not provide IP-based access restrictions for network services. Option D is wrong because enabling the firewall and allowing all incoming connections does the opposite of restricting access to a specific subnet.

193
MCQeasy

What is the purpose of the vLCM hardware compatibility check?

A.Verify ESXi build
B.Check storage performance
C.Check if hardware is on HCL
D.Validate network drivers
AnswerC

vLCM's hardware compatibility check validates each host's CPU, storage controllers, NICs and drivers against the VMware Compatibility Guide, confirming the hardware appears on the HCL for the intended ESXi version. This satisfies the stem's requirement by preventing remediation of clusters containing unsupported components, which would otherwise fail during firmware or driver updates.

Why this answer

The vLCM hardware compatibility check validates that the host's physical hardware (CPU, storage controllers, NICs, HBAs) is listed on the VMware Hardware Compatibility List (HCL) for the target ESXi version. This ensures the image being applied is supported on that hardware, preventing unsupported configurations that could cause instability or void support.

Exam trap

VCP-DCV often tests whether candidates confuse the HCL check (hardware compatibility) with driver validation or build verification — the HCL check is specifically about whether the physical hardware is certified for the ESXi version.

How to eliminate wrong answers

Option A is wrong because verifying the ESXi build is a version/compliance check, not a hardware compatibility check — vLCM already knows the build from the image spec. Option B is wrong because storage performance benchmarking is not part of vLCM; that would be handled by tools like HCIBench or vSAN Performance Diagnostics. Option D is wrong because validating network drivers is a subset of driver/firmware compliance, but the HCL check is broader — it covers all hardware components against VMware's compatibility database, not just network drivers.

194
MCQeasy

An ESXi host has an NFS datastore mounted from a NAS array. The administrator wants to enable hardware acceleration (VAAI) for the datastore. Which requirement must be met?

A.The NAS array must present the LUN as an iSCSI target
B.The datastore must be formatted as VMFS6
C.The ESXi host must have a software FCoE adapter configured
D.The NAS array must support NFSv3 and VAAI primitives
AnswerD

NFS VAAI hardware acceleration relies on the NAS array implementing the NFSv3 primitives, specifically `SEXCL` (space reservation), `FILESIZE`, and `FULLFILE`, which ESXi offloads to the array. The datastore must be mounted over NFSv3, since these primitives are not defined for NFSv4.1, satisfying the stem's hardware acceleration requirement.

Why this answer

VAAI (vStorage APIs for Array Integration) for NFS requires the NAS array to support NFSv3 and the specific VAAI primitives for NFS, such as Full File Clone, Fast File Clone, Reserve Space, and Extended Statistics. ESXi detects these primitives via the array's NFSv3 protocol extensions and enables hardware acceleration for operations like clone and snapshot. Without array support for these primitives, VAAI cannot be enabled.

Exam trap

VCP-DCV often tests the confusion between block VAAI (which requires VMFS and array support for primitives like ATS, XCOPY, WRITE SAME) and NFS VAAI (which requires NFSv3 and array support for Full File Clone, Reserve Space, etc.) — candidates pick VMFS6 or iSCSI answers that apply to block storage, not NFS.

How to eliminate wrong answers

Option A is wrong because presenting the LUN as an iSCSI target changes the datastore from NFS to block (VMFS), which is a different protocol and not the NFS VAAI scenario described. Option B is wrong because VMFS6 is a block-based filesystem for iSCSI/FC datastores, not for NFS datastores — NFS datastores are not formatted as VMFS. Option C is wrong because a software FCoE adapter is for Fibre Channel over Ethernet block storage, unrelated to NFS VAAI.

195
MCQhard

A vSphere administrator is configuring Network I/O Control (NIOC) on a vSphere Distributed Switch. The administrator creates a new network resource pool named 'High Priority' and assigns it a shares value of 'High'. The administrator then assigns a VM's vNIC to a port group that uses this resource pool. However, the VM's traffic is not receiving the expected prioritization during congestion. What is a possible reason for this?

A.The VM's vNIC is not configured with a reservation.
B.The physical switch is not configured to trust CoS/DSCP tags.
C.The port group is not assigned to a VLAN.
D.NIOC is not enabled on the vSphere Distributed Switch.
AnswerD

NIOC must be enabled on the vSphere Distributed Switch for network resource pools and shares to take effect. If NIOC is disabled, all traffic is treated equally, and no prioritization occurs regardless of the shares configured. The administrator must enable NIOC on the switch before resource pools can be used to prioritize traffic.

Why this answer

NIOC must be enabled on the vSphere Distributed Switch for network resource pools and shares to function. If NIOC is disabled, the shares values are ignored, and all traffic is treated equally. The other options are either unrelated to NIOC (VLAN, physical switch QoS) or misconceptions (reservations are not required for shares).

Therefore, the administrator should verify that NIOC is enabled on the switch.

Exam trap

The trap here is assuming that configuring shares alone is sufficient, but NIOC must be explicitly enabled on the distributed switch for those shares to be enforced.

196
MCQmedium

An administrator needs to migrate a powered-on VM from one datastore to another without any downtime. Which vSphere feature should be used?

A.Storage DRS
B.Storage vMotion
C.vSphere Replication
D.vSphere vMotion
AnswerB

Storage vMotion relocates a VM's virtual disks between datastores while the VM remains powered on, using changed-block tracking to synchronise writes during the copy. This satisfies the no-downtime constraint, unlike cold migration, which requires the VM to be powered off first.

Why this answer

Storage vMotion migrates a powered-on VM's virtual disks from one datastore to another with zero downtime, keeping the VM running throughout the copy. It is the correct feature when the requirement is datastore-level migration of a live VM.

Exam trap

VCP-DCV often tests the confusion between vMotion (compute/host migration) and Storage vMotion (datastore migration), so candidates pick vMotion when the requirement is specifically moving storage without downtime.

How to eliminate wrong answers

Option A is wrong because Storage DRS automates datastore placement and balancing based on policies, but it is not the manual migration feature used to move a specific powered-on VM's files. Option C is wrong because vSphere Replication asynchronously replicates VMs to a recovery site for DR; it does not migrate a live VM between datastores. Option D is wrong because vSphere vMotion migrates the VM's compute (CPU/memory state) between ESXi hosts, not its storage between datastores.

197
MCQeasy

A vSphere administrator needs to apply a critical ESXi security patch to a cluster of 10 hosts. The cluster is managed by vLCM using image-based management. What is the correct procedure to apply the patch?

A.Create a new baseline group with the patch and attach it to the cluster.
B.Update the cluster image to include the patched version and remediate the cluster.
C.Manually update each host using the patch's ISO.
D.Use vCenter Update Manager to push the patch as a baseline.
AnswerB

Updating the cluster image to include the patched ESXi version, then remediating the cluster, satisfies image-based management's requirement that desired state be declared at cluster level. vLCM compares each host against the image and applies only the delta, patching all 10 hosts consistently without per-host baselines.

Why this answer

In vLCM image-based management, patches are applied by updating the cluster's image to a newer ESXi base image version that includes the patch, then remediating the cluster. vLCM computes the difference between the current host state and the desired image state and applies only the necessary changes, rolling through hosts per the remediation settings (e.g., maintenance mode, DRS). This is the correct image-based workflow.

Exam trap

VCP-DCV often tests the confusion between legacy VUM baselines and modern vLCM images — candidates who default to 'create a baseline' miss that image-based clusters require updating the image itself, not attaching a baseline.

How to eliminate wrong answers

Option A is wrong because baselines and baseline groups belong to the legacy VUM workflow, not image-based management — vLCM images do not use baselines. Option C is wrong because manually applying an ISO bypasses vLCM entirely, breaks the desired-state model, and is not the correct procedure in an image-managed cluster. Option D is wrong because vCenter Update Manager (the legacy VUM) is not used for image-based clusters; vLCM is the integrated replacement, and pushing a baseline contradicts the image-based model.

198
MCQhard

Refer to the exhibit. The vSphere administrator observes that vm1 has a %RDY value of 20.5. What is the most likely cause of this high ready time?

A.The VM is experiencing network packet loss
B.The VM's virtual disk is causing I/O latency
C.The host's physical CPUs are overcommitted
D.Insufficient memory is allocated to vm1
AnswerC

%RDY measures the percentage of time a virtual machine's vCPUs are ready but waiting for physical CPU scheduling. A sustained 20.5 percent indicates CPU contention, meaning the host's physical cores are overcommitted relative to the running virtual machines' demand.

Why this answer

%RDY (ready time) measures the percentage of time a VM's virtual CPUs are ready to run but cannot be scheduled onto a physical CPU because the host's pCPUs are busy. A sustained value of 20.5% indicates significant CPU contention, meaning the host's physical cores are overcommitted relative to the total vCPU demand of all powered-on VMs. This is a classic symptom of CPU over-subscription on the ESXi host.

Exam trap

VCP-DCV often tests whether candidates can distinguish CPU ready time (%RDY) from memory, network, and storage performance counters — the trap is picking a resource that 'feels' related to slowness but is measured by a completely different metric.

How to eliminate wrong answers

Option A is wrong because network packet loss is diagnosed via dropped packets, %DRPTX/%DRPRX, or vNIC stats, not %RDY. Option B is wrong because disk I/O latency is reflected in metrics like DAVG/KAVG (device latency) or %GAVG, not ready time. Option D is wrong because insufficient memory causes ballooning, swapping, or %SWPWT/%ACTV issues, not CPU ready time.

199
MCQhard

A vSphere environment uses an iSCSI storage array with multiple targets. The administrator configures CHAP authentication but some hosts fail to connect. The working hosts are configured with mutual CHAP, while the failing hosts use only one-way CHAP. What is the most likely reason for the failures?

A.The CHAP secret is not set on the failing hosts.
B.The storage array requires mutual CHAP, but the failing hosts are configured for one-way CHAP.
C.The iSCSI target name is incorrect on the failing hosts.
D.The storage array is configured to use only one-way CHAP.
AnswerB

Mutual CHAP requires authentication in both directions: the host authenticates to the target and the target authenticates to the host. The working hosts supply both sets of credentials, whereas one-way CHAP sends only the initiator's credentials, so the array's reverse challenge fails.

Why this answer

Mutual CHAP requires the target to authenticate the initiator and the initiator to authenticate the target. If the storage array is configured to require mutual CHAP, hosts using only one-way CHAP will fail to complete the authentication handshake. The working hosts are configured with mutual CHAP, confirming the array enforces mutual authentication.

Exam trap

The trap here is that candidates assume CHAP configuration is binary (enabled or disabled) and overlook the distinction between one-way and mutual CHAP, leading them to incorrectly select a missing secret or target name issue.

How to eliminate wrong answers

Option A is wrong because the failing hosts are configured with one-way CHAP, which still requires a CHAP secret; the issue is not the absence of a secret but the authentication direction. Option C is wrong because an incorrect iSCSI target name would cause all hosts to fail, not just those using one-way CHAP, and the working hosts connect successfully. Option D is wrong because if the array used only one-way CHAP, the hosts configured with mutual CHAP would fail, but they are working, so the array must require mutual CHAP.

200
MCQhard

An ESXi host experiences high memory ballooning in virtual machines. The administrator checks the host's memory metrics and sees a high swap rate. The host has 512 GB of memory, and the VMs are configured with memory reservations. Which configuration is most likely contributing to the excessive swapping?

A.Memory shares are set too low for the VMs experiencing ballooning.
B.Memory overcommitment is high, and some VMs have large memory reservations.
C.The host is configured for NUMA interleaving, causing memory access delays.
D.Transparent Page Sharing (TPS) is enabled and is aggressively sharing memory pages.
AnswerB

Large reservations lock physical pages, preventing the balloon driver from reclaiming them, so the host must swap to satisfy remaining demand. With 512 GB and overcommitment, reserved memory cannot be compressed or ballooned, forcing the VMkernel swap path and producing the high swap rate observed.

Why this answer

High memory overcommitment combined with large VM memory reservations forces ESXi to reclaim memory from unreserved VMs via ballooning and, when that is insufficient, host-level swapping. Reservations lock physical memory for some VMs, leaving less for others, which amplifies ballooning and swap activity on the overcommitted host. The correct fix is to reduce overcommitment or right-size reservations.

Exam trap

VCP-DCV often tests the interaction between reservations and overcommitment — the trap is blaming shares or TPS when the real driver is reserved memory reducing the reclaimable pool.

How to eliminate wrong answers

Option A is wrong because memory shares only affect the relative priority of reclaim under contention; low shares can influence which VM is ballooned first, but they do not cause the host-level swap rate to spike when overcommitment and reservations are the root cause. Option C is wrong because NUMA interleaving affects memory access latency and locality, not the amount of physical memory available, so it does not drive ballooning or swapping. Option D is wrong because TPS reduces memory pressure by sharing identical pages; it is a mitigation, not a cause of excessive swapping, and modern ESXi versions have TPS largely disabled by default for security.

201
MCQeasy

A company wants to minimize downtime during an ESXi upgrade from 7.0 to 8.0 on a vSAN cluster. What is the best approach?

A.Upgrade all hosts simultaneously to complete faster.
B.Upgrade vCenter Server first, then upgrade all hosts at once.
C.Place each host in maintenance mode, evacuate vSAN data, upgrade, and rejoin the cluster.
D.Use Quick Boot feature to speed up the upgrade process.
AnswerC

Maintenance mode with full data evacuation maintains vSAN availability throughout the upgrade, satisfying the no-downtime constraint. Each host's data is migrated to remaining cluster members before remediation, and the host rejoins once upgraded, avoiding any storage outage.

Why this answer

The correct approach is to place each host in maintenance mode, evacuate vSAN data, upgrade, and rejoin the cluster. This ensures vSAN data availability and cluster quorum are maintained throughout the upgrade, minimizing downtime. vSAN requires that data be migrated off a host before it enters maintenance mode with 'Ensure Accessibility' or 'Full Data Migration' to preserve policy compliance.

Exam trap

VCP-DCV often tests the misconception that upgrading all hosts simultaneously is faster and acceptable, but candidates must remember that vSAN requires data evacuation and quorum maintenance to avoid downtime.

How to eliminate wrong answers

Option A is wrong because upgrading all hosts simultaneously would cause a complete vSAN outage and data unavailability, as no hosts would be available to serve storage. Option B is wrong because upgrading vCenter first is necessary but upgrading all hosts at once still causes a full outage; vCenter upgrade alone does not address host upgrade sequencing. Option D is wrong because Quick Boot only speeds up the reboot phase of an upgrade but does not evacuate vSAN data or maintain availability; it is not a substitute for proper maintenance mode evacuation.

202
MCQeasy

An administrator runs the command shown in the exhibit on a vCenter Server appliance. What is the primary purpose of the Machine ID?

A.To calculate workload distribution in DRS
B.To identify an ESXi host to vCenter Server
C.To serve as a unique identifier for the vCenter Server instance in SSO
D.To uniquely identify a virtual machine for vMotion
AnswerC

The Machine ID uniquely identifies each vCenter Server instance within the Single Sign-On domain, distinguishing it from other nodes during authentication and replication. This satisfies the requirement of a unique SSO identifier for the vCenter Server instance.

Why this answer

The Machine ID serves as a unique identifier for the vCenter Server instance within VMware SSO (Single Sign-On) and is used for certificate management. It is not related to workload distribution in DRS (option A), ESXi host identification (option B), or virtual machine identification for vMotion (option D). Therefore, option C is correct.

203
MCQhard

An administrator is troubleshooting a failed vSphere Lifecycle Manager remediation operation on a cluster. The error message in the vLCM UI states: 'Hardware Compliance Check failed: The ESXi host does not meet the hardware requirements for the selected image.' The administrator verifies that the host is in the vSphere Hardware Compatibility List (HCL) for the ESXi version. What additional step should the administrator take to resolve this issue?

A.Remove the host from the cluster and re-add it after a clean installation.
B.Use the vSphere Client to export the host's hardware compatibility report.
C.Update the vLCM hardware compatibility plug-in to the latest version.
D.Manually add the host's hardware to the vCenter server's HCL database.
AnswerC

The hardware compatibility check is performed by the vLCM hardware compatibility plug-in, which holds its own HCL data separate from the web HCL. An outdated plug-in can misreport a supported host as incompatible, so updating it refreshes that data.

Why this answer

The error indicates that vLCM's hardware compatibility check failed even though the host is on the HCL. This often occurs when the vLCM hardware compatibility plug-in (provided by the hardware vendor) is outdated or not installed, preventing vLCM from correctly assessing the host's hardware against the desired image. Updating the plug-in to the latest version ensures accurate compliance checks.

Exam trap

The trap is assuming that HCL listing alone guarantees vLCM compliance — candidates may overlook that the hardware compatibility plug-in must be current for vLCM to correctly evaluate the host.

How to eliminate wrong answers

Option A is wrong because removing and re-adding the host does not address the underlying plug-in issue and would cause unnecessary downtime. Option B is wrong because exporting a hardware compatibility report is a diagnostic step, not a resolution; it does not fix the compliance check failure. Option D is wrong because administrators cannot manually add hardware to vCenter's HCL database; the HCL is maintained by VMware and vendors, and vLCM relies on vendor-provided plug-ins for hardware compatibility data.

204
MCQmedium

A vSphere administrator manages a cluster of six ESXi 8.0 hosts with vSphere Lifecycle Manager. The cluster's desired image specifies an ESXi base image and two add-ons: a vendor NIC driver add-on and a storage add-on. During a remediation pre-check, one host reports a hardware compatibility warning: its NIC firmware is older than the minimum version required by the vendor NIC driver add-on. The administrator wants to resolve the warning without removing the add-on from the image. Which action should the administrator take?

A.Put the host into maintenance mode and then run remediation with the option to skip hardware compatibility checks.
B.Update the host's NIC firmware to the minimum version required by the vendor add-on, then remediate the cluster again.
C.Remove the vendor NIC driver add-on from the desired image and add it back after remediation completes.
D.Replace the vendor NIC driver add-on with a generic ESXi base image driver and remediate the cluster.
AnswerB

vLCM validates hardware firmware against the requirements of vendor add-ons in the desired image. The warning indicates a firmware version mismatch, not a missing add-on. Updating the NIC firmware to the required level satisfies the add-on's dependency, and the cluster can then remediate successfully while keeping the desired image unchanged.

Why this answer

The warning is caused by host NIC firmware being older than the minimum version required by the vendor add-on in the desired image. vLCM checks firmware compatibility as part of remediation pre-checks. Updating the firmware to the required level resolves the warning while preserving the desired image and its add-ons, allowing remediation to proceed normally.

Exam trap

The trap here is assuming the warning can be bypassed or that the add-on must be removed, when the actual fix is updating the host firmware to meet the add-on's requirement.

205
MCQmedium

After adding a new ESXi host to a vLCM-managed cluster, the compliance status shows 'Non-Compliant'. All other hosts in the cluster are compliant. The cluster uses a custom image. Which is the most likely cause of the non-compliance?

A.The cluster image has not been exported to the host.
B.The host profile is not attached to the host.
C.The cluster image is corrupted.
D.The host's software inventory differs from the cluster image.
AnswerD

A newly added host retains its original software inventory, so any divergence from the cluster image's specified components, drivers or firmware triggers Non-Compliant status. vLCM compares each host's actual software against the image's desired state; because the other hosts already match, only this host's differing inventory explains the result.

Why this answer

In vSphere Lifecycle Manager (vLCM), a cluster image defines the exact desired software specification (ESXi base image, firmware add-ons, and components) for all hosts. When a new host is added, vLCM compares its actual software inventory against the cluster image. If any installed VIB, driver, or component version differs from the image, the host is marked Non-Compliant.

Since all other hosts are compliant, the cluster image itself is valid and properly applied; the new host simply hasn't been remediated to match the image yet. Therefore, the most likely cause is that the host's software inventory differs from the cluster image.

Exam trap

VCP-DCV often tests the misconception that adding a host to a vLCM cluster automatically makes it compliant, when in fact the host must be remediated to match the cluster image.

How to eliminate wrong answers

Option A is wrong because vLCM does not 'export' cluster images to hosts; it applies the image during remediation, and the image is already defined at the cluster level. Option B is wrong because host profiles are a separate feature used with vSphere Configuration Profiles or legacy host profiles, not the primary compliance mechanism for vLCM cluster images. Option C is wrong because if the cluster image were corrupted, all hosts in the cluster would likely show non-compliance, not just the newly added host.

206
Multi-Selectmedium

Which TWO of the following are characteristics of vSphere High Availability (HA) heartbeat networks? (Choose two.)

Select 2 answers
A.Datastore heartbeats can be used as a secondary heartbeat mechanism.
B.A separate physical network is required for HA heartbeats.
C.The management network is the primary heartbeat network.
D.The default isolation address is the vCenter Server IP address.
E.Heartbeats are sent over the VM network to avoid interference with management traffic.
AnswersA, C

Datastore heartbeats provide a secondary mechanism when the management network fails, letting the master host distinguish a partitioned host from a genuinely failed one. This satisfies the stem's requirement for a valid HA heartbeat characteristic, since HA uses both management network and datastore heartbeats to confirm host state.

Why this answer

Option A is correct because vSphere HA uses datastore heartbeats as a secondary mechanism to determine whether a host is isolated or has failed when management network heartbeats are unavailable. Option C is correct because the management network is the primary heartbeat network used by HA agents to exchange heartbeats between hosts in the cluster. Option B is incorrect because HA heartbeats do not require a separate physical network; they use the management network by default.

Option D is incorrect because the default isolation address is the default gateway of the host's management network, not the vCenter Server IP address. Option E is incorrect because HA heartbeats are sent over the management network, not the VM network.

Exam trap

The trap here is that candidates often assume a separate physical network is mandatory for HA heartbeats (Option B) or that the default isolation address is the vCenter Server IP (Option D), when in fact the management network is primary and the default isolation address is the default gateway.

207
MCQeasy

A vSphere administrator manages a cluster that is currently using vSphere Lifecycle Manager (vLCM) images. The administrator needs to make the cluster use a baseline-based remediation approach instead. Which action should the administrator take?

A.Deactivate the image from the cluster, then attach baselines and remediate.
B.Remediate the cluster with a baseline while the image remains active.
C.Create a new baseline and attach it to the cluster, then remediate.
D.Delete the cluster from vCenter and recreate it without vLCM.
AnswerA

To switch from image-based to baseline-based management, the administrator must deactivate the image on the cluster. This removes the desired image and allows baselines to be attached. After deactivation, the cluster can be managed with baselines and remediated accordingly. This is the correct procedure to change the cluster's lifecycle management approach.

Why this answer

A cluster managed by vLCM images cannot simultaneously use baselines. To switch to baseline-based remediation, the administrator must deactivate the image on the cluster. This action removes the image-based desired state and enables baseline attachment.

After deactivation, baselines can be attached and remediation performed. This is the supported method to change the management approach without recreating the cluster.

Exam trap

The trap here is assuming that baselines can be attached to a cluster that is already managed by an image, but vLCM enforces mutual exclusivity between images and baselines.

208
MCQeasy

An administrator is creating a new vSphere Standard Switch on an ESXi host. The host has two physical NICs: vmnic0 and vmnic1. The administrator wants to use vmnic0 for VM traffic and vmnic1 for management traffic. How should the administrator configure the switch?

A.Create one standard switch with vmnic0 only and use VLANs for separation.
B.Create one standard switch with both vmnics and separate port groups for VM and VMkernel.
C.Create two standard switches: one with vmnic0 and a VM port group, and another with vmnic1 and a VMkernel port group.
D.Create a vSphere Distributed Switch with both vmnics.
AnswerC

Separating vmnic0 and vmnic1 onto distinct standard switches gives each traffic type a dedicated uplink, satisfying the requirement that VM traffic and management traffic never share a physical NIC. The VM port group binds to vmnic0, while the VMkernel port group on the second switch carries management traffic over vmnic1.

Why this answer

The requirement is to use separate physical NICs for different traffic types (VM traffic on vmnic0 and management traffic on vmnic1). In vSphere, a standard switch is a per-host virtual switch that connects virtual machines and VMkernel interfaces to physical NICs. To isolate traffic at the physical NIC level, you must create two distinct standard switches: one with vmnic0 and a VM port group for VM traffic, and another with vmnic1 and a VMkernel port group for management traffic.

This ensures that management traffic never traverses vmnic0 and VM traffic never traverses vmnic1, providing physical separation and avoiding contention.

Exam trap

The trap here is that candidates often assume a single standard switch with multiple uplinks and separate port groups is sufficient for traffic separation, but they overlook that physical NIC assignment is per-switch, not per-port-group, so both traffic types could still share the same NICs via teaming or failover unless explicit NIC binding is configured.

How to eliminate wrong answers

Option A is wrong because creating a single standard switch with only vmnic0 and using VLANs for separation does not physically separate management traffic onto vmnic1; management traffic would still be forced through vmnic0, violating the requirement. Option B is wrong because creating one standard switch with both vmnics and separate port groups for VM and VMkernel traffic would allow both traffic types to use either NIC (via teaming or failover), failing to enforce the dedicated NIC assignment. Option D is wrong because a vSphere Distributed Switch (VDS) requires vCenter Server and is not created directly on an ESXi host; it also does not inherently force specific traffic types to dedicated physical NICs without explicit configuration, and the question specifies a standard switch.

209
Multi-Selecthard

Which THREE components are part of a vSAN cluster?

Select 3 answers
A.vSAN datastore
B.vSAN network
C.vSAN witness host
D.ESXi hosts
E.vCenter Server
AnswersA, B, D

Correct: The datastore is the aggregated storage.

Why this answer

A vSAN datastore is a core component of a vSAN cluster because it is the aggregated, distributed storage object created from the local disks of the ESXi hosts in the cluster. This datastore is what VMs use for storage, and it is built and managed by the vSAN layer, making it an integral part of the cluster's architecture.

Exam trap

The trap here is that candidates often mistake vCenter Server as a required component of a vSAN cluster, but vCenter Server is only needed for management and initial configuration, not for the cluster's ongoing operation or data plane functionality.

210
MCQmedium

A company runs a vSphere cluster with vSphere Distributed Resource Scheduler (DRS) enabled in fully automated mode. The operations team wants to add a new ESXi host to the cluster without causing any VM downtime. Which statement describes what happens to the running workloads when the host is added?

A.All VMs must be powered off and registered again on the new host before the cluster recognizes it.
B.Running VMs continue without interruption, and DRS may use vMotion to rebalance them onto the new host if needed.
C.DRS immediately migrates all VMs to the new host to balance the cluster.
D.The new host remains in maintenance mode until an administrator manually evacuates it.
AnswerB

Adding a host does not disrupt running VMs. With DRS in fully automated mode, the scheduler evaluates cluster balance and may use vMotion to move selected VMs onto the new host to improve resource distribution. Because vMotion migrates live VMs with no downtime, the workloads remain available throughout the process.

Why this answer

When a host joins a DRS-enabled cluster, running VMs are unaffected. In fully automated mode DRS can perform vMotion migrations to place workloads on the new host if doing so improves balance, and live migration keeps those VMs available. No power-off, re-registration, or maintenance mode step is involved in normal cluster expansion.

Exam trap

The trap here is confusing DRS balancing with a mandatory evacuation, when DRS only moves VMs selectively to improve balance.

211
MCQhard

A vSphere administrator is trying to create a custom ESXi image for a cluster using vSphere Lifecycle Manager. The cluster contains hosts with a specific hardware that requires a third-party component (e.g., a NIC driver). The administrator adds the component to the image definition in vLCM. However, when applying the image, the component does not get installed on the hosts. What is the likely cause?

A.The component version is not compatible with the ESXi version in the image.
B.The administrator did not mount the component ISO during remediation.
C.The component is not signed by a trusted certificate authority.
D.The component must be installed manually on each host first.
AnswerA

vLCM validates each component against the ESXi base image's acceptance level and version dependencies. A component built for a different ESXi release is silently skipped during remediation, so the NIC driver never installs despite being present in the image definition.

Why this answer

In vSphere Lifecycle Manager (vLCM), a custom ESXi image is composed of a base ESXi version plus additional components (drivers, firmware). Each component has a compatibility matrix that specifies which ESXi versions it supports. If the component version added to the image definition is not compatible with the ESXi version in the image, vLCM will not install it during remediation — the component is effectively ignored or the image fails validation.

This is the most likely cause when a component silently does not get installed.

Exam trap

VCP-DCV often tests whether candidates overlook version compatibility between the component and the ESXi base image, instead blaming ISO mounting, signing, or manual installation — the exam expects you to know that vLCM enforces a compatibility matrix.

How to eliminate wrong answers

Option B is wrong because vLCM does not require mounting a component ISO during remediation — components are added to the image definition and vLCM handles delivery. Option C is wrong because while component signing is important, an untrusted signature would typically produce a validation error, not a silent non-installation; the more common cause is version incompatibility. Option D is wrong because vLCM is designed to install components automatically as part of the image; manual installation defeats the purpose of the desired-state model.

212
Multi-Selecthard

An administrator is managing a vSphere 8 cluster with vSphere Lifecycle Manager (vLCM) using a single image. The cluster's desired image includes an ESXi base image and a vendor add-on. The administrator needs to add a custom VIB that is not part of any depot. Which two steps are required to include this custom VIB in the vLCM image? (Choose two.)

Select 2 answers
A.Upload the custom VIB to a local depot or a web server accessible by vLCM.
B.Manually install the custom VIB on each host using ESXCLI before remediation.
C.Add the custom VIB to the cluster's desired image using the 'Add Component' option.
D.Convert the custom VIB to a firmware add-on.
E.Disable image compliance checks to allow unsigned VIBs.
AnswersA, C

vLCM can only use software from configured depots. To include a custom VIB, it must be added to a depot that vLCM can access. This can be a local depot on the vCenter Server or a web server hosting an offline depot. Without this step, the VIB will not appear in the image customization options.

Why this answer

To include a custom VIB in a vLCM image, the VIB must first be made available in a depot that vLCM can access, such as a local or web-based depot. Then, it can be added as a component to the cluster's desired image. Manual installation or disabling checks are not valid approaches.

Exam trap

The trap here is thinking that manually installing the VIB on hosts or disabling compliance checks will make it part of the vLCM image, when in fact the VIB must be in a depot and added as a component.

213
MCQmedium

An administrator needs to migrate a VM from a VMFS5 datastore to a vSAN datastore while preserving the storage policy. Which migration method should be used?

A.Cold migration
B.Clone
C.Storage vMotion
D.vMotion
AnswerC

Storage vMotion relocates a VM's virtual disks between datastores while the VM runs, and it carries the assigned VM storage policy to the destination. That satisfies the requirement to move from VMFS5 to vSAN without reconfiguring the policy manually.

Why this answer

Storage vMotion migrates a VM's virtual disks from one datastore to another while the VM remains powered on, and it preserves the VM's storage policy (e.g., vSAN storage policy). It is the correct method for moving a VM between datastores without downtime.

Exam trap

The trap is confusing vMotion (compute migration between hosts) with Storage vMotion (datastore migration) — candidates pick vMotion because it sounds like the general migration tool, missing that storage movement requires Storage vMotion.

How to eliminate wrong answers

Option A is wrong because cold migration requires the VM to be powered off, causing downtime, and is unnecessary when Storage vMotion can do it live. Option B is wrong because Clone creates a copy of the VM rather than migrating the original, leaving the source VM in place and potentially duplicating the storage policy assignment. Option D is wrong because vMotion migrates the VM's compute state (CPU/memory) between hosts, not its storage — it does not move virtual disks between datastores.

214
Multi-Selecthard

Which THREE techniques are recommended to improve virtual machine network performance in a vSphere environment? (Select three.)

Select 3 answers
A.Enable Jumbo Frames on the virtual switch.
B.Use the VMXNET3 virtual network adapter.
C.Use a dedicated virtual switch for each VM.
D.Use the e1000e network adapter type.
E.Enable SR-IOV on supported NICs.
AnswersA, B, E

Enabling jumbo frames raises the MTU to 9000 on the virtual switch, reducing per-packet header overhead and CPU interrupts for large, sequential transfers. This satisfies the stem's performance-improvement constraint, provided every device along the path—physical switch, uplinks and guest NICs—is configured identically, otherwise fragmentation degrades throughput.

Why this answer

Option A is correct because enabling Jumbo Frames (MTU 9000) on the virtual switch, physical uplinks, and guest OS reduces per-packet overhead and CPU utilization, improving throughput for large data transfers. Option B is correct because the VMXNET3 adapter is a paravirtualized NIC designed for vSphere that delivers higher throughput and lower CPU utilization than emulated adapters like e1000e. Option E is correct because SR-IOV on supported NICs allows a virtual function to be passed directly to the VM, bypassing the hypervisor's virtual switch datapath for near-native network performance and reduced latency.

Option C is not recommended because dedicating a separate virtual switch per VM adds management overhead and does not inherently improve performance; standard vSwitch design uses shared switches with proper uplink and teaming configuration. Option D is incorrect because e1000e is an emulated Intel adapter that offers lower performance and higher CPU overhead than VMXNET3.

Exam trap

VCP-DCV often tests the misconception that more virtual switches or emulated adapters improve performance, when in fact paravirtualized adapters and hardware offloads like SR-IOV are the recommended techniques.

215
Drag & Dropmedium

Order the steps to enable vSphere HA on a cluster.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for enabling vSphere HA ensures that all prerequisites are met, starting with cluster selection, then accessing the HA configuration page, toggling the enable option, customizing settings, and applying changes. Common mistakes include attempting to configure options before enabling HA or accessing settings before selecting the cluster.

216
MCQmedium

An administrator is configuring a vSAN cluster with a storage policy that uses RAID-5 erasure coding. The cluster has 6 hosts, each contributing capacity. The administrator sets the policy to 'Number of failures to tolerate' = 1. What is the minimum number of hosts required for this policy to be compliant?

A.6 hosts
B.4 hosts
C.5 hosts
D.3 hosts
AnswerB

RAID-5 erasure coding with FTT=1 requires a minimum of 4 hosts. This configuration stripes data and parity across 4 hosts, allowing the cluster to tolerate one host failure while maintaining data availability. With 4 hosts, the policy can be satisfied. Using more hosts increases resilience and performance, but 4 is the minimum for this specific policy.

Why this answer

For a vSAN storage policy using RAID-5 erasure coding with 'Number of failures to tolerate' set to 1, the minimum number of hosts required is 4. RAID-5 distributes data and parity across at least 4 fault domains (hosts), allowing the cluster to tolerate one host failure. With fewer than 4 hosts, the policy cannot be satisfied, and VMs would be non-compliant.

Exam trap

The trap here is confusing RAID-5 with RAID-1, where RAID-1 with FTT=1 requires only 3 hosts, but RAID-5 requires 4.

217
MCQeasy

An administrator needs to migrate a running VM from one datastore to another without any downtime. Which vSphere feature allows this?

A.Cross vCenter vMotion
B.Storage vMotion
C.Storage DRS
D.vMotion
AnswerB

Storage vMotion relocates a running VM's virtual disks between datastores while the guest OS keeps running, using changed-block tracking to mirror and switch over live I/O. This directly satisfies the stem's no-downtime constraint, unlike cold migration, which requires powering the VM off first.

Why this answer

Storage vMotion is the vSphere feature specifically designed to migrate a running VM's virtual disks (files) from one datastore to another while the VM remains powered on and continues serving workloads. It leverages a mirroring mechanism that copies disk blocks to the destination datastore and performs a fast switchover, achieving zero downtime. This is distinct from compute vMotion, which moves the VM's execution state between ESXi hosts.

Exam trap

VCP-DCV often tests the confusion between vMotion (compute migration between hosts) and Storage vMotion (disk migration between datastores), so candidates who see 'migrate a running VM' and reflexively pick vMotion miss the 'datastore' keyword.

How to eliminate wrong answers

Option A is wrong because Cross vCenter vMotion is used to migrate VMs between different vCenter Server instances (and possibly different SSO domains), not to move storage between datastores within the same host. Option C is wrong because Storage DRS is an automated load-balancing and placement feature that can trigger Storage vMotion operations based on datastore space and I/O metrics, but it is not the migration mechanism itself. Option D is wrong because standard vMotion migrates the compute state (CPU, memory, devices) of a running VM between ESXi hosts, not its virtual disk files between datastores.

218
Drag & Dropmedium

Place the steps to create a new standard virtual switch in vSphere in order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for creating a new standard virtual switch in vSphere is: select a host, access its networking settings, click Add Networking, choose the connection type (e.g., Virtual Machine), and finally create and configure the new standard switch. This order ensures you follow the wizard's logical steps and avoid errors.

219
Multi-Selecthard

Which THREE components are required to configure Storage DRS affinity and anti-affinity rules?

Select 3 answers
A.A resource pool
B.Datastores
C.An ESXi host
D.Virtual machines
E.A datastore cluster
AnswersB, D, E

Datastores are the actual storage backing devices that affinity and anti-affinity rules reference. Each rule specifies which virtual machines should or should not reside together on the same datastore, so at least two datastores within the cluster are needed to make placement decisions meaningful.

Why this answer

Storage DRS affinity and anti-affinity rules are configured at the datastore-cluster level, so option E (a datastore cluster) is required because it provides the boundary within which the rules are defined and enforced. Option B (datastores) is correct because the rules themselves specify which datastores within that cluster the virtual machines should be kept together on (affinity) or kept apart from (anti-affinity). Option D (virtual machines) is correct because the rules are applied to VM-to-datastore relationships, meaning the VMs are the objects whose placement is being constrained.

Option A (a resource pool) is not required, since resource pools govern CPU and memory allocation, not datastore placement. Option C (an ESXi host) is not required as a rule component, because Storage DRS rules operate on datastores and VMs within a datastore cluster rather than being defined per host.

Exam trap

The trap is confusing compute-layer objects (resource pools, ESXi hosts) with storage-layer objects — candidates who think 'affinity' always involves hosts or resource pools pick the wrong components.

220
MCQeasy

An administrator is troubleshooting a failed attempt to add an ESXi host to a vCenter Server domain. The error message states: 'The host's certificate has been tampered with or is invalid.' What is the most likely cause?

A.The vCenter Server's account lockout policy has been triggered.
B.The ESXi host's SSH keys have been rotated.
C.The ESXi host's certificate has expired.
D.The ESXi host's certificate thumbprint does not match the thumbprint stored in vCenter Server.
AnswerD

vCenter stores the ESXi thumbprint captured at first connection; any mismatch, such as after a host certificate regeneration or reinstall, triggers the tampered-or-invalid error. The stored thumbprint no longer matches the host's presented certificate, blocking the add.

Why this answer

The error 'The host's certificate has been tampered with or is invalid' occurs when the ESXi host presents a certificate whose thumbprint does not match the thumbprint that vCenter Server has stored for that host. This mismatch can happen if the host's certificate was replaced (e.g., due to a reinstall or manual rotation) without updating the vCenter Server's trusted store. vCenter Server verifies the host's identity by comparing the SHA-1 or SHA-256 thumbprint of the presented certificate against its stored record; a mismatch triggers this specific error.

Exam trap

The trap here is that candidates often confuse certificate expiration with thumbprint mismatch, but the error message 'tampered with or invalid' specifically points to a thumbprint mismatch rather than a date-based validity issue.

How to eliminate wrong answers

Option A is wrong because an account lockout policy would produce a different error, such as 'Login failed' or 'Access denied', not a certificate tampering message. Option B is wrong because SSH keys are used for SSH authentication, not for the SSL/TLS certificate validation that occurs during host addition to vCenter Server; rotating SSH keys does not affect certificate thumbprint matching. Option C is wrong because an expired certificate would generate an error like 'Certificate has expired' or 'Certificate is not yet valid', not a 'tampered with or invalid' message, which specifically indicates a thumbprint mismatch rather than a validity period issue.

221
MCQmedium

An administrator manages a cluster of 10 identical ESXi hosts using vLCM with image-based management. After importing a new hardware support package (HSP) and applying a new image specification, 5 hosts report non-compliant with the error 'Firmware version not supported'. The compliant hosts and non-compliant hosts are from the same vendor model. What is the most likely cause?

A.The image specification was applied only to the compliant hosts.
B.The non-compliant hosts have a different manufacturer than the compliant ones.
C.The vLCM service failed to download the HSP to the non-compliant hosts.
D.The firmware version on the non-compliant hosts is newer than what the hardware support package supports.
AnswerD

An HSP bundles validated firmware baselines per server model. Hosts already flashed beyond that validated version fail the image compliance check with 'Firmware version not supported', since vLCM cannot downgrade or match them to the package's supported firmware level.

Why this answer

The error 'Firmware version not supported' in vLCM image-based management indicates that the HSP (Hardware Support Package) included in the image specification does not support the firmware version currently running on the non-compliant hosts. HSPs are vendor-provided bundles that define supported firmware/driver combinations for specific hardware models. If the hosts have a newer firmware version than what the HSP was validated against, vLCM flags them as non-compliant because the HSP cannot guarantee compatibility.

Since all hosts are the same vendor model, the difference must be in firmware version, not hardware model or image application.

Exam trap

VCP-DCV often tests the distinction between image application errors and firmware compatibility errors, tricking candidates into choosing options about image distribution or hardware differences when the real issue is firmware version mismatch with the HSP.

How to eliminate wrong answers

Option A is wrong because if the image specification were applied only to the compliant hosts, the non-compliant hosts would not be evaluated against the new image at all, and they would not report a firmware version error; they would simply remain at their previous compliance state. Option B is wrong because the scenario explicitly states all hosts are from the same vendor model, so a different manufacturer is impossible. Option C is wrong because a failure to download the HSP would typically result in a download or connectivity error, not a 'Firmware version not supported' error; the HSP is already imported and applied, and the error specifically points to firmware incompatibility.

222
MCQeasy

An administrator needs to separate vMotion traffic from management traffic. Which should be created?

A.A new physical NIC.
B.A new VMkernel adapter on a different subnet.
C.A new VLAN on the existing port group.
D.A new standard switch port group.
AnswerB

A separate VMkernel adapter placed on a distinct subnet isolates vMotion traffic from management at layer 3, giving each its own IP stack and routing. This satisfies the requirement to fully separate the two traffic types.

Why this answer

Separating vMotion traffic from management traffic requires a dedicated VMkernel adapter, because VMkernel adapters carry vMotion, management, and other system traffic. Placing it on a different subnet ensures traffic isolation at Layer 3 and prevents vMotion from competing with management on the same network.

Exam trap

VCP-DCV often tests whether candidates confuse Layer 2 constructs (port groups, VLANs) with the Layer 3 VMkernel adapter that is actually required to carry vMotion traffic.

How to eliminate wrong answers

Option A is wrong because adding a physical NIC alone does not create a VMkernel interface; vMotion traffic still needs a VMkernel adapter to be enabled. Option C is wrong because a VLAN on an existing port group does not by itself create a separate VMkernel interface for vMotion. Option D is wrong because a standard switch port group is a Layer 2 construct; without a VMkernel adapter enabled for vMotion, traffic cannot be separated.

223
MCQmedium

An administrator observes that a VM with 4 vCPUs running on a host with hyperthreading enabled shows high %CSTP (co-stop) values in esxtop. What is a likely cause?

A.The VM has CPU affinity configured forcing vCPUs to specific pCPUs.
B.The VM's memory reservation is too high.
C.The host has deep C-states enabled causing CPU idle savings.
D.The host memory is overcommitted causing swapping.
AnswerA

CPU affinity pins each vCPU to a specific logical processor, so the VM's four vCPUs cannot be co-scheduled onto available cores. When the scheduler cannot run all vCPUs simultaneously, the remaining ones wait, inflating %CSTP. Removing the affinity rule restores flexible co-scheduling and resolves the co-stop.

Why this answer

High %CSTP (co-stop) in esxtop indicates that the VM's vCPUs are waiting for each other to be co-scheduled on physical CPUs. CPU affinity forcing vCPUs to specific pCPUs can restrict the scheduler's ability to co-schedule all vCPUs simultaneously, leading to co-stop. This is a likely cause when a VM has multiple vCPUs and affinity constraints.

Exam trap

The trap is assuming memory issues cause CPU co-stop: candidates may pick memory reservation or swapping, but co-stop is specifically a CPU scheduling metric related to vCPU co-scheduling, often caused by CPU affinity or excessive vCPUs.

How to eliminate wrong answers

Option B is wrong because a high memory reservation does not cause co-stop; memory reservation affects memory allocation, not CPU scheduling. Option C is wrong because deep C-states affect power management and can increase latency, but they do not directly cause co-stop — co-stop is about vCPU co-scheduling. Option D is wrong because memory overcommitment causing swapping affects memory performance, not CPU co-stop; swapping would show as high swap metrics, not %CSTP.

224
MCQmedium

A company is implementing vSphere 7.0 and wants to encrypt all vMotion traffic between ESXi hosts in a cluster. The cluster is not using any other encryption features. What is the minimum requirement to enable vMotion encryption?

A.A VM Encryption Key Management Server must be configured.
B.The ESXi hosts must be joined to an Active Directory domain.
C.The ESXi hosts must have a host profile applied with encryption enabled.
D.The cluster must be configured with Enhanced vMotion Compatibility (EVC).
AnswerC

A host profile applied with encryption enabled is the minimum requirement because it ensures consistent encryption policy across the cluster, leveraging default certificate trust.

Why this answer

In vSphere 7.0, enabling vMotion encryption does not require Active Directory, a Key Management Server, Enhanced vMotion Compatibility (EVC), or host profiles. The minimum requirement is simply to configure the vMotion encryption policy on each ESXi host (set to 'Required' or 'Opportunistic'). No additional infrastructure or profiles are needed.

Exam trap

Candidates often mistakenly believe that vMotion encryption requires external configuration such as host profiles, AD, or a KMS. In reality, it uses built-in certificate trust and can be enabled directly on each host without any additional setup.

How to eliminate wrong answers

Option A is wrong because a VM Encryption Key Management Server is required for encrypting virtual machine disks (VM-level encryption), not for vMotion traffic; vMotion encryption uses Kerberos from Active Directory, not a KMS. Option C is wrong because a host profile is a management tool for applying consistent configurations across hosts, but it is not a prerequisite for enabling vMotion encryption; the encryption setting can be configured directly on each host via advanced system parameters (e.g., 'VMkernel.Boot.vmotionEncryption'). Option D is wrong because Enhanced vMotion Compatibility (EVC) ensures CPU compatibility for live migrations but has no role in encrypting vMotion traffic; EVC does not provide any encryption or authentication mechanism.

225
MCQeasy

Based on the exhibit, which VM (indicated by the row) is most likely experiencing severe CPU scheduling contention?

A.The VM with %RDY = 2.3
B.The VM with %RDY = 30.0
C.The VM with %RDY = 15.5
D.The VM with %RDY = 0.5
AnswerB

%RDY measures the percentage of time a VM was ready to run but waited for a physical CPU. A sustained value of 30.0 far exceeds the roughly 5% threshold, indicating the VM is repeatedly delayed by scheduler contention on overcommitted cores.

Why this answer

The row with the highest %RDY (30.0) indicates the VM is spending a large percentage of time ready to run but not being scheduled, which is a sign of severe CPU contention. The other rows have lower %RDY values.

Page 2

Page 3 of 4

Page 4

All pages