Courseiva

VMware Certified Professional Data Center Virtualization VCP-DCV (VCP-DCV) — Questions 226–281

281 questions total · 4pages · All types, answers revealed

Page 3

Page 4 of 4

226
MCQhard

A multinational corporation runs a vSphere environment with 100 ESXi hosts managed by a single vCenter Server. The security team mandates that all virtual machine disks (VMDKs) must be encrypted at rest. The administrator enables vSphere Virtual Machine Encryption and creates a Key Management Server (KMS) cluster. After encrypting a test VM, the VM powers on successfully, but the administrator notices that the VM's configuration files (VMX, NVRAM) are not encrypted. The security policy requires that all VM files, including configuration files, be encrypted. The administrator checks the VM storage policy and sees that the policy is set to 'VM Encryption Policy' with 'Disk Encryption' enabled. What should the administrator do to ensure the entire VM is encrypted?

A.Modify the VM storage policy to include encryption of VM home files
B.Enable encryption on the datastore where the VM resides
C.Add a second KMS cluster for redundancy
D.Enable vSphere Host Encryption on each ESXi host
AnswerA

The VM storage policy's VM Encryption Policy encrypts only VMDKs by default; VM home files (VMX, NVRAM) require the separate 'Encrypt VM home files' setting. Enabling that component in the policy satisfies the mandate that configuration files be encrypted at rest.

Why this answer

The VM storage policy 'VM Encryption Policy' with only 'Disk Encryption' enabled encrypts VMDK files but not the VM configuration files (VMX, NVRAM, logs, etc.). To encrypt all VM files, the storage policy must include the 'Encrypt VM home files' option, which applies encryption to the entire VM home directory on the datastore. This ensures compliance with the security mandate for full VM encryption at rest.

Exam trap

The trap here is that candidates assume 'VM Encryption Policy' with 'Disk Encryption' covers all VM files, but VMware explicitly separates disk encryption from home file encryption in the storage policy settings.

How to eliminate wrong answers

Option B is wrong because datastore-level encryption (e.g., vSAN encryption or Storage DRS encryption) is a separate feature that encrypts the entire datastore, but it does not selectively encrypt VM home files when using VM Encryption Policy; the policy must explicitly include home file encryption. Option C is wrong because adding a second KMS cluster provides redundancy for key management but does not affect which VM files are encrypted; the encryption scope is defined by the storage policy, not the KMS topology. Option D is wrong because vSphere Host Encryption encrypts host memory and vMotion traffic, not VM files at rest on the datastore; it does not address VMDK or configuration file encryption.

227
MCQmedium

A vSphere administrator is troubleshooting a virtual machine that cannot communicate on the network. The VM is connected to a port group on a vSphere Standard Switch. The administrator verifies that the physical switch port is configured as an access port for VLAN 10, and the port group VLAN ID is set to 10. The VM's guest OS has a static IP address in the correct subnet. Which step should the administrator take next to diagnose the issue?

A.Change the port group VLAN ID to 4095.
B.Check the virtual machine's network adapter settings to ensure it is connected and the correct port group is selected.
C.Verify that the physical switch port is configured as a trunk.
D.Restart the management agents on the ESXi host.
AnswerB

The most likely cause is that the VM's network adapter is disconnected or connected to the wrong port group. Verifying the adapter's connection status and port group assignment is a fundamental troubleshooting step. If the adapter is disconnected or on a different port group, the VM will not communicate. This should be checked before more complex diagnostics.

Why this answer

The physical switch and port group VLAN configurations are correct. The next logical step is to verify the VM's network adapter settings, as a disconnected adapter or wrong port group is a common cause. Checking the adapter is non-disruptive and directly addresses the VM's connectivity.

Other options involve changing correct configurations or taking unnecessary actions.

Exam trap

The trap here is overlooking the VM's adapter settings and instead assuming a mismatch between the physical switch and port group, even though they are already aligned.

228
Multi-Selecthard

A vSphere administrator needs to ensure that vCenter Server can authenticate users against an Active Directory over LDAP identity source. The environment uses vCenter Server 7.0. Which two configurations are required to successfully add the identity source? (Choose two.)

Select 2 answers
A.Upload a trusted root CA certificate for the LDAP server's SSL certificate.
B.Provide the bind user's credentials with sufficient privileges to read the directory.
C.Configure the identity source to use Integrated Windows Authentication (IWA).
D.Enable FIPS mode on vCenter Server before adding the identity source.
E.Specify the base distinguished name (DN) for user and group searches.
AnswersB, E

vCenter Server uses a bind user to connect to the LDAP directory and search for users and groups. The bind user must have read access to the directory. Without valid credentials, the identity source cannot be queried. This is a required configuration for Active Directory over LDAP. The bind user can be a dedicated service account with minimal read-only privileges.

Why this answer

To add an Active Directory over LDAP identity source in vCenter Server 7.0, you must provide the base DN for searches and a bind user with read access. These allow vCenter Server to query the directory for authentication. IWA is a different identity source type, FIPS mode is unrelated, and a trusted CA certificate is only needed if using LDAPS, which is not specified here.

Exam trap

The trap here is assuming that a CA certificate is always required for LDAP, when it is only needed for LDAPS or StartTLS, which are not specified.

229
Matchingmedium

Match each vSphere storage concept to its definition.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Cluster file system for VM storage

Network file system protocol for VM storage

Block storage protocol over IP networks

Raw device mapping for direct LUN access

Hyper-converged storage from local disks

Why these pairings

Correct matches: VMFS is a cluster file system for block storage; NFS is a network file system for NAS; vSAN aggregates local disks for shared storage; VVols enable VM-level storage management. Common confusions: mixing VMFS and vSAN definitions, or swapping NFS and VMFS.

230
MCQhard

An organization is implementing vSphere Trust Authority for sensitive workloads. The administrator must configure the trusted ESXi hosts to attest to vCenter Server. Which component is responsible for performing attestation?

A.The administrator's workstation
B.A separate vCenter Server instance acting as the Trust Authority
C.The Key Provider (KMS) server
D.The trusted ESXi hosts themselves
AnswerB

Correct. A separate vCenter Server instance acting as the Trust Authority performs attestation of ESXi hosts.

Why this answer

VSphere Trust Authority uses a dedicated vCenter Server instance (Trust Authority vCenter) to perform attestation of ESXi hosts. Option A is incorrect because the administrator's workstation is not part of the trust chain and does not perform attestation. Option C is incorrect because the Key Provider (KMS) server is used for encryption key management, not for host attestation.

Option D is incorrect because the trusted ESXi hosts themselves are the subjects of attestation; they do not perform attestation.

231
MCQmedium

During a security audit, it is found that the vCenter Server is using the default self-signed certificate. The administrator is tasked to replace it with a certificate from an enterprise CA. What is the first step after obtaining the CA-signed certificate?

A.Convert the certificate and private key into PEM format and place them in the appropriate directory.
B.Use the vSphere Web Client to upload the certificate.
C.Import the private key into the Windows Certificate Store.
D.Restart the VMware Certificate Service.
AnswerA

vCenter expects PEM files for certificates and keys.

Why this answer

The certificate must be in a format that vCenter can use; typically, it needs to be combined with the private key. Option B is premature before preparing the certificate. Option C is incorrect because certificate import is done via certificate management tools, not vSphere Web Client.

Option D is incorrect because the private key is included in the signed certificate generation process, not imported separately.

232
MCQhard

An administrator is troubleshooting a VMFS6 datastore that has become inaccessible after a storage array controller failover. The ESXi host logs show multiple 'Lost access to volume' errors. The administrator verifies that the array is presenting the LUN to the host, but the datastore remains unavailable. Which step should the administrator take first to resolve the issue?

A.Unmount and delete the VMFS datastore, then recreate it and restore from backup.
B.Rescan the storage adapter to discover the LUN and restore access.
C.Check the VMFS metadata and run vmfsanalyzer to determine if the datastore is corrupt.
D.Verify that the host can see the LUN and check for permanent device loss (PDL) or all paths down (APD) conditions.
AnswerD

After a controller failover, the host may experience APD or PDL. APD occurs when all paths to a device become unavailable, while PDL indicates the device is permanently gone. Checking for these conditions helps determine the appropriate recovery action, such as re-establishing paths or rebooting the host. This is the first step to diagnose the issue.

Why this answer

When a VMFS datastore becomes inaccessible after a controller failover, the host may have lost all paths to the storage. This can trigger an APD or PDL condition. The administrator should first verify whether the LUN is visible and check for these conditions.

Depending on the state, the host may need to be rebooted or paths may need to be re-established. This approach avoids unnecessary data loss.

Exam trap

The trap here is jumping to conclusions about datastore corruption or immediately rescanning without first determining whether the issue is an APD/PDL condition, which requires different remediation.

233
MCQmedium

A financial services company runs a vSphere 8 environment with three clusters managed by a single vCenter Server. The security team mandates that all management traffic, including vMotion and vSAN, be isolated on dedicated VLANs. An administrator must verify which VMkernel adapters are configured for vMotion on each ESXi host. Which vSphere component provides this information in the vSphere Client?

A.The Physical adapters tab under the Networking section of each ESXi host
B.The Host Profiles configuration for each ESXi host
C.The VMkernel adapters tab under the Networking section of each ESXi host
D.The vSphere Distributed Switch topology diagram in the vSphere Client
AnswerC

The VMkernel adapters tab lists all VMkernel ports on an ESXi host, including their enabled services such as vMotion, vSAN, and management. This is the correct location to verify which adapters are configured for vMotion, as it directly shows the services enabled per adapter and their associated VLANs.

Why this answer

The VMkernel adapters tab is the authoritative place to see which services each VMkernel port has enabled, including vMotion. It shows the VLAN, IP address, and enabled services, allowing the administrator to confirm that vMotion is isolated on the correct VLAN across all hosts.

Exam trap

The trap here is assuming that the distributed switch topology or physical adapter view shows service enablement, when only the VMkernel adapters tab reveals which services are active per adapter.

234
MCQeasy

An administrator wants to stage updates to reduce downtime during remediation of a vLCM-managed cluster. What should they configure?

A.Enable 'Stage remediation' in the cluster image configuration.
B.Enable 'Quick Boot' to speed up reboots.
C.Configure the cluster to use a rolling schedule.
D.Create multiple host images for each host.
AnswerA

Enabling 'Stage remediation' in the cluster image configuration lets vLCM pre-download and stage all payloads to each host before any maintenance window, so remediation itself only applies the staged updates. This directly satisfies the stem's requirement to reduce downtime during remediation of the vLCM-managed cluster.

Why this answer

vLCM's 'Stage remediation' option pre-downloads and stages the update payload on each host before remediation begins, so the actual remediation step only needs to apply the staged bits and reboot. This shortens the per-host maintenance window and reduces the risk of remediation failing due to download issues during the change window.

Exam trap

VCP-DCV often tests the confusion between staging (pre-downloading payloads) and scheduling/concurrency (rolling remediation) or Quick Boot (faster reboot) — candidates must match the feature to the specific downtime-reduction goal.

How to eliminate wrong answers

Option B is wrong because Quick Boot speeds up the reboot itself by skipping certain firmware/hardware initialization, but it does not stage updates or reduce the time spent downloading and preparing payloads — it addresses a different phase. Option C is wrong because a rolling schedule controls the order and concurrency of remediation across hosts, not the staging of update payloads; it reduces risk but not the per-host downtime from downloading. Option D is wrong because creating multiple host images per host defeats the purpose of vLCM's desired-state model and does not stage updates — it fragments management and does not reduce remediation downtime.

235
MCQeasy

Which tool provides real-time performance monitoring at the ESXi host level, including CPU, memory, network, and storage metrics?

A.dcli
B.esxtop
C.resxtop
D.vCenter performance charts
AnswerB

esxtop runs directly on the ESXi host console, sampling live CPU, memory, network and storage counters at sub-second intervals. Unlike vCenter's five-minute rollups, it exposes per-world and per-device detail, satisfying the stem's real-time host-level requirement without vCenter dependency.

Why this answer

esxtop is a command-line tool that provides real-time host performance data. vCenter performance charts are historical. resxtop is for remote usage, and dcli is a different tool.

236
Multi-Selecthard

A vSphere administrator is managing a vLCM cluster with a desired image. The administrator needs to update the ESXi base image to a newer version. Before initiating remediation, the administrator wants to validate the image to ensure it is compatible with all hosts in the cluster. Which two actions should the administrator take to validate the image? (Choose two.)

Select 2 answers
A.Manually compare the image's VIB list with each host's installed VIBs.
B.Use the 'Validate Image' feature in the vLCM interface.
C.Run the 'Check Compliance' operation on the cluster.
D.Export the image to an ISO and test it on a standalone host.
E.Check the vSphere Compatibility Guide for the ESXi version.
AnswersB, C

vLCM provides a 'Validate Image' function that checks the desired image for internal consistency, such as missing VIBs, dependency conflicts, and compatibility with the cluster's hosts. It performs a pre-check to ensure the image is valid and can be remediated. This feature is specifically designed to validate the image before applying it. Hence, this action is correct.

Why this answer

To validate a desired image before remediation, the administrator should use vLCM's 'Check Compliance' operation and the 'Validate Image' feature. These tools automatically check for compatibility, dependencies, and potential issues with the hosts, ensuring a smooth remediation process.

Exam trap

The trap here is assuming that manual checks or external documentation can substitute for vLCM's built-in validation, which is specifically designed to catch image and host compatibility issues.

237
MCQmedium

A vSphere administrator is planning to upgrade a vSphere 7.0 U3 cluster to vSphere 8.0. The cluster currently uses vSphere Lifecycle Manager (vLCM) with a single image. After the upgrade, the administrator wants to ensure that all ESXi hosts apply firmware updates from a hardware support manager (HSM) integrated with vLCM. Which step must the administrator take before starting the cluster upgrade?

A.Disable vLCM and use baseline-based remediation for the upgrade.
B.Create separate baselines for ESXi and firmware and attach them to the cluster.
C.Remove the HSM integration because vLCM cannot apply firmware updates.
D.Ensure the desired ESXi version and firmware component are specified in the vLCM image.
AnswerD

vLCM only applies firmware through the hardware support manager when the firmware component is declared in the cluster image. Specifying both the target ESXi version and firmware component in that image before upgrading ensures hosts apply HSM-delivered firmware, satisfying the stated requirement.

Why this answer

VLCM with a single image can include both the ESXi version and firmware components from an integrated hardware support manager (HSM). By specifying the desired ESXi version and firmware component in the vLCM image, the administrator ensures that during the cluster upgrade, vLCM will apply the firmware updates provided by the HSM as part of the image-based remediation process. This is the required step before starting the upgrade to vSphere 8.0.

Exam trap

The trap here is that candidates may think vLCM cannot handle firmware updates or that separate baselines are needed, when in fact vLCM's single-image approach with HSM integration is designed to manage both ESXi and firmware updates together.

How to eliminate wrong answers

Option A is wrong because disabling vLCM and reverting to baseline-based remediation would lose the single-image management and HSM integration capabilities, which are key to applying firmware updates in a unified manner. Option B is wrong because vLCM with a single image does not use separate baselines for ESXi and firmware; instead, it uses a single image that includes both components, and attaching separate baselines would conflict with the image-based approach. Option C is wrong because vLCM can apply firmware updates when integrated with an HSM, and removing the HSM would prevent firmware updates from being applied during the upgrade.

238
MCQeasy

Which feature allows a VM to use storage directly from the host's local disks, pooled across a cluster?

A.VMFS
B.vFlash
C.NFS
D.vSAN
AnswerD

vSAN aggregates local disks attached to each ESXi host into a shared distributed datastore, presenting pooled capacity and performance across the cluster. This lets VMs consume storage from hosts' local devices rather than requiring external shared arrays, which is the feature described.

Why this answer

vSAN is VMware's software-defined storage solution that pools local disks (SSDs/HDDs) from ESXi hosts across a cluster into a shared datastore. It allows VMs to use storage directly from host local disks, aggregated and presented as a single distributed datastore. This matches the requirement exactly.

Exam trap

The trap is confusing vSAN with vFlash or VMFS: candidates may think vFlash pools local storage, but vFlash is only a caching mechanism, while vSAN is the actual pooling technology for local disks across a cluster.

How to eliminate wrong answers

Option A is wrong because VMFS is a clustered file system for shared storage (SAN/NFS), not a pooling mechanism for local disks across a cluster. Option B is wrong because vFlash uses local SSD as a read cache for VMs, but it does not pool storage across hosts. Option C is wrong because NFS is a network file system protocol for accessing remote storage, not a way to pool local disks.

239
MCQmedium

An administrator configures DRS on a cluster with two hosts. The administrator wants to ensure that two critical VMs (VM1 and VM2) always run on separate hosts. Which rule type should the administrator create?

A.Separate Virtual Machines
B.Virtual Machines to Hosts (Should run)
C.Keep Virtual Machines Together
D.Virtual Machines to Hosts (Must not run)
AnswerA

A Separate Virtual Machines rule enforces anti-affinity, satisfying the stem's requirement that VM1 and VM2 never share a host. DRS honours this during placement and vMotion, keeping the two critical VMs on distinct hosts within the cluster.

Why this answer

The 'Separate Virtual Machines' rule (option A) is correct because it explicitly instructs DRS to place VM1 and VM2 on different ESXi hosts, ensuring host-level isolation for availability. This rule type enforces an anti-affinity constraint that DRS respects during initial placement and subsequent load-balancing migrations, preventing both VMs from running on the same host simultaneously.

Exam trap

The trap here is that candidates often confuse 'Separate Virtual Machines' (anti-affinity between VMs) with 'Virtual Machines to Hosts – Must not run' (anti-affinity between VMs and specific hosts), leading them to select the wrong rule type for VM-to-VM separation.

How to eliminate wrong answers

Option B (Virtual Machines to Hosts – Should run) is wrong because it defines an affinity rule that attempts to keep VMs on a specified set of hosts, not separate them; it does not enforce separation between two VMs. Option C (Keep Virtual Machines Together) is wrong because it creates an affinity rule that forces the VMs to run on the same host, which is the opposite of the desired separation. Option D (Virtual Machines to Hosts – Must not run) is wrong because it restricts VMs from running on specific hosts, not from running on the same host as another VM; it addresses host-level prohibition, not VM-to-VM separation.

240
MCQmedium

A vSphere environment experiences periodic performance degradation during peak business hours. Analysis shows that one ESXi host's CPU ready time for a specific mission-critical VM is consistently above 20%. Which corrective action should be taken first?

A.Increase the VM's memory reservation
B.Set a higher CPU limit on the VM
C.Migrate the VM to a different host with lower CPU utilization
D.Add more vCPUs to the VM
AnswerC

Migrating the VM to a host with lower CPU utilisation directly reduces the scheduling delay causing high CPU ready time. CPU ready measures the time a vCPU waits for a physical core; moving the VM to a less contended host lowers the ready percentage, addressing the peak-hour degradation constraint without altering VM configuration.

Why this answer

CPU ready time above 20% indicates the VM is waiting for physical CPU resources because the host is overcommitted or contended. The first corrective action should be to migrate the VM to a less-utilized host (vMotion), which immediately relieves contention without changing the VM's configuration. This addresses the root cause — host-level CPU contention — rather than masking it.

Exam trap

VCP-DCV often tests the misconception that adding vCPUs or raising limits fixes CPU performance, when in fact CPU ready time is a host-contention symptom best resolved by reducing contention or migrating the VM.

How to eliminate wrong answers

Option A is wrong because memory reservations address memory contention, not CPU ready time; they do nothing to reduce CPU scheduling delay. Option B is wrong because a CPU limit caps the VM's CPU usage and would worsen performance, not improve ready time. Option D is wrong because adding vCPUs increases the number of scheduling slots the VM needs, which typically increases CPU ready time on a contended host rather than reducing it.

241
MCQeasy

A vSphere administrator wants to ensure that all ESXi hosts in a cluster boot from a consistent set of software packages, including firmware and drivers. Which vSphere feature should be used to achieve this?

A.vSphere Update Manager (VUM)
B.vSphere Lifecycle Manager (vLCM) with a single image
C.Host Profiles
D.Quick Boot
AnswerB

vLCM with a single image defines one desired-state image per cluster, containing the ESXi base image plus firmware and driver add-ons from the HSM. Remediation enforces that exact image on every host, satisfying the requirement for a consistent set of software packages.

Why this answer

vSphere Lifecycle Manager (vLCM) with a single image is the correct choice because it allows the administrator to define a complete software specification—including ESXi version, firmware, drivers, and add-ons—as a single desired state image. When applied to a cluster, vLCM ensures every ESXi host boots from exactly the same set of software packages, eliminating drift and guaranteeing consistency across all hosts.

Exam trap

The trap here is that candidates often confuse Host Profiles (which manage configuration settings) with image-based lifecycle management, not realizing that Host Profiles cannot enforce firmware or driver versions, while vLCM with a single image provides a holistic, boot-level software consistency.

How to eliminate wrong answers

Option A is wrong because vSphere Update Manager (VUM) applies updates and patches but does not enforce a single, unified image that includes firmware and driver baselines across all hosts; it operates on individual baselines and can leave hosts with different software combinations. Option C is wrong because Host Profiles capture host-level configuration settings (e.g., networking, storage, security) but do not manage firmware or driver versions; they are not designed to control the boot-time software package set. Option D is wrong because Quick Boot is a feature that reduces reboot time during updates by skipping hardware reinitialization; it has no role in ensuring consistent software packages across hosts.

242
Multi-Selectmedium

Which TWO of the following are functions of a vSphere Distributed Switch that are not available in a vSphere Standard Switch? (Select exactly two.)

Select 2 answers
A.Port mirroring (Distributed Port Mirroring).
B.NIC teaming with explicit failover order.
C.Network I/O Control (NIOC).
D.Traffic shaping policies.
E.VLAN tagging and trunking.
AnswersA, C

Distributed Port Mirroring requires a centralised control plane to replicate traffic across multiple hosts, which the vSphere Standard Switch lacks entirely. It satisfies the stem's constraint of a Distributed Switch-only function, since standard switches offer no equivalent monitoring capability at that scale.

Why this answer

Option A (Port mirroring / Distributed Port Mirroring) is correct because the vSphere Distributed Switch provides a centralized, dvSwitch-wide port mirroring feature configured at the distributed switch or distributed port group level, whereas a vSphere Standard Switch has no native port mirroring capability and requires third-party tools or workarounds. Option C (Network I/O Control / NIOC) is correct because NIOC, which uses shares, reservations, and limits to prioritize and manage bandwidth across traffic types (e.g., vMotion, iSCSI, NFS, VM traffic) on a per-dvSwitch basis, is a Distributed Switch-only feature and is not available on a Standard Switch. Option B (NIC teaming with explicit failover order) is not correct because Standard Switches also support NIC teaming with configurable failover order, so it is not exclusive to the Distributed Switch.

Option D (Traffic shaping policies) is not correct because both Standard and Distributed Switches support traffic shaping, though the Distributed Switch offers more granular per-port-group control. Option E (VLAN tagging and trunking) is not correct because VLAN tagging (VST, EST, VGT) and trunking are supported on both Standard and Distributed Switches.

243
MCQhard

A vSphere administrator is configuring Network I/O Control (NIOC) on a vSphere Distributed Switch. The environment has multiple traffic types: vMotion, iSCSI, and virtual machine traffic. The administrator wants to ensure that during periods of congestion, vMotion traffic does not starve iSCSI traffic, but vMotion should be able to use more bandwidth than iSCSI when available. Which NIOC configuration should the administrator apply?

A.Assign vMotion a higher limit than iSCSI.
B.Assign vMotion a higher shares value than iSCSI.
C.Assign vMotion a higher reservation than iSCSI.
D.Assign iSCSI a higher shares value than vMotion.
AnswerB

NIOC uses shares to allocate bandwidth during congestion. Shares define relative priority: a higher shares value gives vMotion more bandwidth than iSCSI when contention occurs. This meets the requirement that vMotion does not starve iSCSI (since iSCSI still gets its proportional share) and can use more bandwidth when available. Setting shares appropriately balances the two traffic types.

Why this answer

NIOC shares determine relative bandwidth allocation during congestion. Giving vMotion more shares than iSCSI ensures vMotion gets more bandwidth when needed, but iSCSI still receives its proportional share, preventing starvation. Limits and reservations do not provide the same relative prioritization.

Therefore, adjusting shares is the correct approach.

Exam trap

The trap here is confusing shares with limits or reservations, thinking that a higher limit or reservation automatically provides priority during congestion, when shares are the mechanism for relative priority.

244
MCQmedium

An administrator is designing a vSAN cluster with 6 hosts. The cluster will run production workloads that require high availability. The administrator wants to minimize storage overhead while ensuring data can survive a single host failure. Which storage policy setting should be used?

A.RAID-5 with Number of Failures to Tolerate = 1
B.RAID-6 with Number of Failures to Tolerate = 2
C.RAID-0 with Number of Failures to Tolerate = 0
D.RAID-1 with Number of Failures to Tolerate = 1
AnswerA

RAID-5 erasure coding in vSAN provides fault tolerance for one host failure with less storage overhead than RAID-1. It requires a minimum of 4 hosts and uses parity to reconstruct data. For a 6-host cluster, RAID-5 offers a good balance of availability and capacity efficiency, making it ideal for production workloads.

Why this answer

For a 6-host vSAN cluster requiring tolerance of one host failure with minimized overhead, RAID-5 erasure coding is the best choice. It provides the necessary fault tolerance while using less capacity than RAID-1 mirroring. RAID-6 would offer additional protection but at higher overhead, and RAID-0 offers no redundancy.

Exam trap

The trap here is assuming that RAID-1 is always the default for high availability, but RAID-5 can provide similar fault tolerance with less overhead in clusters of sufficient size.

245
MCQhard

An administrator is planning to upgrade a vSphere 7 environment to vSphere 8. The environment includes a vCenter Server Appliance 7.0 Update 3 and ESXi 7.0 Update 3 hosts. The administrator wants to minimize downtime and ensure the upgrade is supported. Which upgrade path should be used?

A.Use vSphere Update Manager to upgrade vCenter Server and ESXi hosts simultaneously.
B.Upgrade ESXi hosts to 8.0 first, then upgrade vCenter Server to 8.0.
C.Perform a fresh install of vCenter Server 8.0 and ESXi 8.0 on all hosts, then migrate VMs.
D.Upgrade vCenter Server to 8.0 first, then upgrade ESXi hosts to 8.0 using vSphere Lifecycle Manager.
AnswerD

VMware supports upgrading vCenter Server before ESXi hosts. vCenter Server 8.0 can manage ESXi 7.0 hosts, so this order allows the administrator to upgrade vCenter first, then use vSphere Lifecycle Manager (vLCM) to upgrade the hosts. This minimizes downtime because vCenter remains available during host upgrades.

Why this answer

The supported upgrade order is to upgrade vCenter Server first, then ESXi hosts. vCenter Server 8.0 can manage ESXi 7.0 hosts, allowing a phased upgrade. vSphere Lifecycle Manager is used to upgrade the hosts. Other options either violate upgrade order, cause unnecessary downtime, or use deprecated tools.

Exam trap

The trap here is assuming ESXi hosts can be upgraded before vCenter, or that vSphere Update Manager is still the tool for host upgrades.

246
MCQmedium

A company has a vSphere cluster consisting of 8 ESXi hosts connected to a single Fibre Channel SAN array. They use VMFS6 datastores to store virtual machine files. The storage administrator has scheduled a firmware upgrade for the SAN array that requires a controller reboot. This will cause a temporary loss of connectivity to one LUN (datastore) for approximately 5 minutes. The datastore hosts 15 production VMs, including critical database servers. The cluster has sufficient spare capacity on other datastores, but the VMs are large (each about 200 GB). The vSphere administrator must ensure that these VMs remain available during the upgrade. The cluster has vSphere HA enabled with default settings. What should the administrator do to meet the requirement?

A.Use Storage vMotion to migrate all VMs on the affected datastores to a healthy datastore before the upgrade.
B.Configure a vSphere HA admission control policy to reserve resources in case of host failure.
C.Place all ESXi hosts into maintenance mode.
D.Enable Storage I/O Control on the affected datastore to manage I/O during the upgrade.
AnswerA

Storage vMotion relocates the running VMs' files to a healthy datastore, so the five-minute LUN loss never affects them. vSphere HA default settings would only restart VMs after an APD timeout, causing downtime, so proactive migration satisfies the availability requirement.

Why this answer

Storage vMotion migrates the VMs' files to a different datastore while they remain powered on, so when the affected LUN goes offline for the controller reboot the VMs are no longer dependent on it and stay available. This directly addresses the requirement of continuous availability during a planned 5-minute storage outage. The other options either don't move the VMs off the impacted datastore or address unrelated concerns (HA admission control, host maintenance, I/O prioritization).

Exam trap

VCP-DCV often tests the confusion between host-level availability (HA, maintenance mode) and storage-level availability (Storage vMotion, datastore evacuation) — candidates pick HA admission control thinking it protects against storage loss.

How to eliminate wrong answers

Option B is wrong because vSphere HA admission control reserves capacity for host failures; it does nothing to protect VMs from a datastore/LUN becoming temporarily unavailable, and the VMs would still lose access to their files. Option C is wrong because putting hosts into maintenance mode would evacuate or power off VMs, causing an outage rather than preventing one, and it doesn't relocate storage. Option D is wrong because Storage I/O Control only manages I/O contention/prioritization on a datastore; it cannot keep VMs running when the LUN is offline and provides no availability during a controller reboot.

247
MCQmedium

An organization is using vSphere Trust Authority (vTA) to secure ESXi hosts. A newly added ESXi host fails to attest with the Trust Authority. The administrator verifies that the host is connected to the vTA cluster and the trust relationship is configured. What is the most likely cause of the attestation failure?

A.The Trust Authority's network is isolated from the ESXi host's management network.
B.The ESXi host is not in the same cluster as the Trust Authority.
C.The ESXi host does not have a virtual Trusted Platform Module (vTPM) attached.
D.The TPM on the ESXi host is disabled or not properly initialized.
AnswerD

Attestation requires a healthy, enabled TPM to produce the quoted measurements the Trust Authority verifies. If the TPM is disabled or uninitialised, the host cannot generate valid attestation evidence, so the vTA cluster rejects it even though connectivity and trust configuration are correct.

Why this answer

vSphere Trust Authority attestation depends on a functioning, properly initialized TPM 2.0 on each ESXi host. The host's TPM measures the boot process (UEFI Secure Boot, bootloader, VMkernel modules) and produces quotes that the Trust Authority verifier compares against a trusted baseline. If the TPM is disabled in BIOS/UEFI or has not been initialized (no Endorsement Key taken ownership), the host cannot produce valid attestation quotes, so attestation fails even though the trust relationship and network connectivity are fine.

Exam trap

VCP-DCV often tests the distinction between host-level TPM (physical, required for vTA attestation) and guest-level vTPM (virtual, used for VM encryption), so candidates who see 'TPM' and pick the vTPM option fall into the trap.

How to eliminate wrong answers

Option A is wrong because network isolation would prevent the host from reaching the vTA cluster at all, but the question states the host is already connected to the vTA cluster and the trust relationship is configured, so connectivity is not the issue. Option B is wrong because vSphere Trust Authority is explicitly designed to attest hosts outside the Trust Authority cluster — the Trusted Cluster and the Trust Authority cluster are separate by design, so co-location is not required. Option C is wrong because vTPM is a virtual machine feature for guest OS encryption (e.g., Windows BitLocker in a VM); ESXi hosts use a physical discrete or firmware TPM, not a vTPM, so this option confuses guest-level and host-level TPM concepts.

248
Drag & Dropmedium

Order the steps to take a snapshot of a virtual machine.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct order for taking a snapshot in VMware vSphere is to first initiate the snapshot by right-clicking the VM and selecting 'Snapshot > Take Snapshot', then in the dialog provide a name and optional description, select whether to snapshot the virtual machine's memory and whether to quiesce the file system, and finally confirm by clicking OK. This sequence ensures that all necessary parameters are set before the snapshot is created.

249
MCQmedium

A financial services firm maintains a multi-site vSphere environment with independent vCenter Server systems in New York and London, each managing approximately 200 virtual machines. The company requires a disaster recovery solution that can orchestrate failover of an entire site with automated IP address changes and integrated testing capabilities. They also need centralized management and the ability to attach the recovery site's vCenter to the same vCenter Single Sign-On domain as the protected site. The current vCenter versions are 7.0 Update 3. Which solution best meets these requirements while adhering to VMware best practices?

A.Implement a vSAN stretched cluster across both data centers and enable proactive HA policies.
B.Deploy vCenter Site Recovery (SRM) paired with vSphere Replication, and use Enhanced Linked Mode to connect the vCenter systems.
C.Configure vCloud Availability for vCloud Director to replicate VMs between sites.
D.Use vCenter High Availability (VCHA) to protect the vCenter Server and rely on vSphere HA for VMs.
AnswerB

SRM provides orchestrated failover, IP customization, and testing; Enhanced Linked Mode allows centralized management and a single SSO domain.

Why this answer

VMware Site Recovery Manager (SRM) with vSphere Replication provides orchestrated disaster recovery with automated IP address changes and integrated testing capabilities. Enhanced Linked Mode allows both vCenter Server systems to share the same vCenter Single Sign-On domain, meeting the centralized management requirement. This combination is the VMware best-practice solution for multi-site failover with independent vCenter Servers.

Exam trap

The trap here is that candidates often confuse vSphere HA with site-level disaster recovery, overlooking that SRM is specifically designed for orchestrated failover with automated IP changes and testing, while vSphere HA only handles host-level failures within a single cluster.

How to eliminate wrong answers

Option A is wrong because a vSAN stretched cluster requires a single vCenter Server managing both sites and does not support independent vCenter Server systems; it also lacks orchestrated failover with automated IP changes and integrated testing. Option C is wrong because vCloud Availability for vCloud Director is designed for service providers and multi-tenant environments, not for a financial firm's private vSphere deployment with independent vCenter Servers; it does not provide the required SRM-level orchestration or Enhanced Linked Mode integration. Option D is wrong because vCenter High Availability (VCHA) only protects the vCenter Server appliance itself, not the virtual machines, and vSphere HA alone cannot orchestrate site-level failover with automated IP changes or provide integrated testing capabilities.

250
Multi-Selectmedium

Which THREE security hardening measures should be applied to an ESXi host? (Choose three.)

Select 3 answers
A.Increase memory resource allocation for management VMs
B.Enable lockdown mode
C.Enable SNMP v3
D.Apply a host profile for security settings
E.Disable ESXi Shell and SSH services
AnswersB, D, E

Lockdown mode forces all administrative access through vCenter Server or an authorised directory, blocking direct root logins to the host. This satisfies the hardening requirement by removing the local bypass path an attacker would otherwise use after obtaining host credentials.

Why this answer

Option B is correct because enabling lockdown mode restricts direct root access to an ESXi host, forcing all administrative actions through vCenter Server or an authorized privileged account, which reduces the attack surface from unauthorized local or remote logins. Option D is correct because applying a host profile enforces a consistent, validated set of security configuration settings (such as firewall rules, services, and authentication policies) across ESXi hosts, preventing configuration drift that could introduce vulnerabilities. Option E is correct because disabling the ESXi Shell and SSH services closes unneeded remote-access channels that attackers could exploit; these services should only be enabled temporarily for troubleshooting and then disabled again.

Option A is not a security hardening measure—increasing memory for management VMs is a performance/resource tuning action and does not reduce the host's attack surface. Option C, while SNMPv3 does provide authentication and encryption compared to earlier SNMP versions, is not one of the three required hardening measures here and enabling SNMP at all can expose management information, so it is not selected as a correct answer.

Exam trap

VCP-DCV often tests the confusion between performance tuning (like memory allocation) and security hardening, and may include distractors like SNMP v3 which is a management protocol, not a hardening measure.

251
MCQmedium

An administrator sees the above error in the vLCM remediation history. What is the most likely cause?

A.The desired image validation failed before remediation.
B.The host's acceptance level does not allow the VIB.
C.The host firmware is incompatible with the VIB.
D.The vCenter Server cannot reach the VMware depot.
AnswerD

The vLCM remediation history error indicates the vCenter Server failed to download metadata or payloads from the VMware depot, confirming a connectivity fault rather than a host-side configuration issue. This satisfies the stem's constraint: remediation requires the vCenter Server to reach the online depot, so blocked outbound HTTPS access is the most likely cause.

Why this answer

The error shown in the vLCM remediation history indicates a failure to download the desired image components. vLCM relies on the vCenter Server to fetch VIBs and software depots from the VMware online depot (or a local depot). If the vCenter Server cannot reach the VMware depot due to network issues, proxy misconfiguration, or firewall blocks (e.g., port 443 to *.vmware.com), the remediation will fail with a download error, not a validation or acceptance-level error.

Exam trap

The trap here is that candidates often confuse a depot connectivity error with a VIB acceptance-level or validation error, because all can prevent remediation, but only the depot error manifests as a download failure in the remediation history.

How to eliminate wrong answers

Option A is wrong because a validation failure would produce a specific error message about image compliance or component mismatch, not a download failure. Option B is wrong because an acceptance-level mismatch would generate a host-level error during VIB installation, not a depot connectivity issue. Option C is wrong because firmware incompatibility is checked during hardware compatibility validation, not during depot download, and would produce a different error related to hardware support.

252
MCQeasy

An administrator wants to use vLCM to manage a cluster with 10 ESXi hosts. After enabling vLCM, what is the first step to ensure all hosts are running the same desired image?

A.Define a desired state image for the cluster.
B.Remediate the cluster immediately to apply the default image.
C.Place all hosts into maintenance mode.
D.Create a host upgrade baseline and attach it to the cluster.
AnswerA

Defining a desired-state image establishes the cluster's target software specification, which vLCM then remediates each host against. This directly satisfies the stem's requirement to bring all ten ESXi hosts to a consistent image, since vLCM compares each host's current state to the image and flags drift for remediation.

Why this answer

With vLCM, the first step after enabling it on a cluster is to define a desired state image. This image specifies the exact ESXi version, firmware, and driver versions that all hosts in the cluster must match. Without defining this image, vLCM has no target configuration to validate or enforce against the hosts.

Exam trap

The trap here is that candidates often confuse vLCM's image-based approach with the legacy baseline-based workflow from Update Manager, leading them to select option D, or they assume remediation can proceed without first defining a desired state image.

How to eliminate wrong answers

Option B is wrong because remediating the cluster immediately would apply a default image that does not exist; vLCM requires an explicit desired state image to be defined before any remediation can occur. Option C is wrong because placing hosts into maintenance mode is a prerequisite for remediation, not the first step after enabling vLCM; the image must be defined first. Option D is wrong because vLCM does not use host upgrade baselines; baselines are a legacy Update Manager concept, and vLCM uses images and image-based clusters instead.

253
Matchingmedium

Match each vSphere feature to its correct description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Distributes VM workloads across hosts based on resource usage

Provides continuous availability by maintaining a secondary VM

Migrates VM storage without downtime

Powers hosts on/off to save energy based on demand

Standardizes host configuration across a cluster

Why these pairings

Key vSphere features: vMotion (live migration), HA (automatic restart), DRS (load balancing), FT (continuous availability via lockstep). Common confusions involve swapping the feature and its description.

254
MCQeasy

A company uses vSphere 7.0 with two ESXi hosts in a cluster. All virtual machines (VMs) are stored on a VMFS6 datastore backed by a single LUN from a mid-range SAN. The LUN is presented to both hosts and both hosts have identical multipathing configuration. Recently, an administrator noticed that one host shows the datastore as "Inactive" while the other host can access it normally. The administrator verifies that both hosts have connectivity to the SAN, the LUN is visible to both hosts, and the storage array reports the LUN as online. The administrator wants to restore access to the datastore on the affected host without disrupting VMs running on the other host. Which action should the administrator take?

A.Perform a storage rescan on the affected host.
B.Reboot the affected ESXi host.
C.Change the multipathing policy on the affected host to Round Robin.
D.Unmount the datastore from the affected host and then remount it.
AnswerA

A rescan refreshes the affected host's storage adapter and VMFS volume inventory, re-establishing the datastore path without touching the host that still has working access. Because the SAN LUN is online and visible, rescanning is the non-disruptive remedy.

Why this answer

The datastore showing as 'Inactive' on one host while remaining accessible on the other indicates a path failure or a transient storage connectivity issue at the host level, not a permanent problem with the LUN or array. Performing a storage rescan on the affected host forces the ESXi host to re-evaluate all storage paths and re-register the datastore, restoring access without impacting VMs on the other host. This is the safest and least disruptive action because it does not require a reboot, multipathing policy change, or unmounting the datastore.

Exam trap

The trap here is that candidates may assume an 'Inactive' datastore requires a disruptive action like a reboot or unmount, when in fact a simple storage rescan is the standard VMware-recommended first step to re-establish path connectivity without affecting running VMs.

How to eliminate wrong answers

Option B is wrong because rebooting the affected host would cause unnecessary downtime for any VMs running on that host and is not required to fix a simple path visibility issue; a rescan is sufficient. Option C is wrong because changing the multipathing policy to Round Robin addresses load balancing across multiple active paths, but the problem here is that the datastore is 'Inactive' (all paths are dead or not claimed), not that the current policy is suboptimal; changing the policy will not re-establish connectivity. Option D is wrong because unmounting and remounting the datastore is a more invasive operation that could disrupt VMs on the affected host if any are present, and it does not address the underlying path issue; a rescan is the correct first step to re-discover the LUN.

255
Multi-Selecteasy

A vSphere administrator is scaling a cluster by adding new ESXi hosts and VMs. Which two actions help ensure that performance continues to meet requirements as the environment grows? (Choose two.)

Select 2 answers
A.Place all VMs on the host with the fastest processors.
B.Enable DRS with fully automated mode.
C.Use a vSphere Distributed Switch for network scalability.
D.Configure vSphere HA on the cluster.
E.Set CPU reservations on all VMs.
AnswersB, C

DRS automates initial placement and ongoing load balancing, optimizing performance as VMs are added.

Why this answer

DRS with fully automated mode continuously monitors resource utilization across the cluster and automatically migrates VMs to balance CPU and memory loads. This ensures that as new hosts and VMs are added, workloads are redistributed to prevent hotspots and maintain performance requirements.

Exam trap

The trap here is that candidates often confuse vSphere HA (high availability) with performance scaling, but HA only reacts to failures and does not balance load or optimize resource usage as the environment grows.

256
MCQmedium

A vSphere administrator is managing a cluster with vLCM and receives a notification that a new ESXi patch is available. The administrator updates the desired image to include the patch and attempts to remediate, but the remediation fails with 'Cannot retrieve software depots'. What could be the issue?

A.The software depot URL in the image is incorrect or unreachable.
B.The hosts cannot communicate with the vCenter Server.
C.The image validation failed due to missing dependencies.
D.The desired image was not saved after adding the patch.
AnswerA

An unreachable or malformed depot URL prevents vLCM from downloading the patch payloads referenced by the desired image, so remediation aborts before any host enters maintenance mode. The error text names the depot retrieval stage specifically, making connectivity or URL accuracy the constraint that must be satisfied first.

Why this answer

The error 'Cannot retrieve software depots' indicates that vLCM is unable to reach the software depot URL specified in the desired image. This typically occurs when the URL is incorrect, the depot server is down, or network/firewall rules block access to the depot. Since the administrator updated the image and remediation fails at the depot retrieval stage, the most direct cause is an unreachable or misconfigured depot URL.

Exam trap

The trap here is that candidates may confuse a depot retrieval failure with a host communication issue or image validation problem, but the specific error message directly points to the depot URL being inaccessible, not to host connectivity or dependency checks.

How to eliminate wrong answers

Option B is wrong because if hosts cannot communicate with vCenter Server, the remediation would likely fail with a different error, such as 'Host connection lost' or 'Cannot communicate with host', not a depot retrieval error. Option C is wrong because image validation failures due to missing dependencies produce errors like 'Missing dependency' or 'Conflicting packages', not 'Cannot retrieve software depots'. Option D is wrong because if the desired image was not saved, the patch would not be included in the image, but the remediation would either proceed without the patch or fail with a different error; the depot retrieval error is unrelated to saving the image.

257
Multi-Selecthard

Which THREE components are required to implement vSphere with Tanzu (Workload Management)? (Choose three.)

Select 3 answers
A.A separate vCenter Server for Tanzu management
B.A vSphere Distributed Switch (vDS)
C.NSX-T Data Center for networking
D.A vSphere cluster with vSphere DRS enabled
E.Shared storage accessible by all ESXi hosts in the cluster
AnswersB, D, E

A vSphere Distributed Switch provides the port groups and uplinks that Supervisor control plane and Tanzu Kubernetes Grid clusters attach to, satisfying the networking prerequisite for Workload Management. Without a vDS, the Supervisor cannot present its Kubernetes API endpoint or route pod traffic, so deployment fails.

Why this answer

Option B is correct because implementing vSphere with Tanzu requires a vSphere Distributed Switch (vDS) to provide the networking foundation for the Supervisor Cluster and its namespaces, including the distributed port groups used by Tanzu workloads. Option D is correct because the vSphere cluster hosting the Supervisor must have vSphere DRS enabled, since DRS is a prerequisite for Workload Management and is used to place and manage Supervisor control plane and worker nodes. Option E is correct because shared storage (such as vSAN, NFS, iSCSI, or Fibre Channel) accessible by all ESXi hosts in the cluster is required so that Kubernetes control plane VMs and persistent volumes can be placed and migrated across hosts.

Option A is not required because vSphere with Tanzu uses the existing vCenter Server rather than a separate dedicated Tanzu vCenter. Option C is not required because NSX-T Data Center is only needed for certain networking configurations (such as NSX-based Supervisor networking); vSphere with Tanzu can also be deployed using a vDS with a HAProxy load balancer, so NSX-T is not a mandatory component.

Exam trap

The trap here is that candidates often assume NSX-T is mandatory for vSphere with Tanzu, but the exam tests that a vDS is the minimum networking requirement, with NSX-T being an optional but recommended component for advanced networking features.

258
Multi-Selecteasy

Which TWO are correct statements about vSphere resource pools? (Select two.)

Select 2 answers
A.Resource pools can be nested.
B.Resource pools can be used to isolate performance for individual VMs.
C.Resource pools inherit settings from parent pools by default.
D.Resource pools are only available in clusters.
E.Resource pools can have shares, limits, and reservations.
AnswersA, E

Resource pools support hierarchical nesting.

Why this answer

Correct: A (resource pools can be nested) and E (resource pools can have shares, limits, and reservations). Option B is false because resource pools aggregate resources for multiple VMs, not isolate individual VMs. Option C is false because child resource pools do not inherit settings from their parent by default; they have their own allocations unless explicitly configured.

Option D is false because resource pools are available on standalone hosts as well as clusters.

259
MCQeasy

An administrator is planning a new vSphere deployment for a small branch office. The branch has only three ESXi hosts and no shared storage array. The administrator wants to aggregate the local disks from all three hosts into a single distributed datastore that provides policy-based, software-defined storage. Which vSphere solution should be used?

A.VMware vSAN
B.NFS datastore mounted from a Linux server
C.VMware vSphere Storage Appliance (VSA)
D.VMware Virtual Volumes (vVols)
AnswerA

vSAN pools the local disks of ESXi hosts in the same cluster into a single distributed datastore managed through storage policies. It requires no external shared storage array, making it ideal for the three-host branch office. The administrator can define policies for capacity, performance, and availability, and vSAN handles placement and protection at the object level.

Why this answer

vSAN is the only listed solution that takes the local disks already present in the three ESXi hosts and presents them as one distributed, policy-driven datastore without requiring an external array or file server. The other choices either depend on external storage hardware or represent a retired product.

Exam trap

The trap here is assuming that any storage feature can aggregate local disks, when only vSAN provides software-defined shared storage from host-local devices.

260
MCQmedium

An administrator manages a vSphere 8 cluster that is currently using vSphere Lifecycle Manager (vLCM) with a single image. The cluster contains hosts from two different server vendors. The administrator needs to add a firmware add-on to the image to ensure firmware compliance. Which vLCM component must be present in the image to enable firmware updates?

A.Vendor add-on
B.Hardware Support Manager (HSM)
C.Component
D.Base ESXi image
AnswerB

Hardware Support Manager is a vLCM component that enables firmware updates for hosts. It is required in the desired image to manage firmware and drivers. Without HSM, firmware remediation is not possible. This is correct because HSM provides the necessary integration with hardware vendors to apply firmware updates during remediation.

Why this answer

Firmware updates in vLCM are performed through the Hardware Support Manager (HSM), which must be included in the desired image. The HSM integrates with vendor tools to apply firmware updates during remediation. Without HSM, the image can still update ESXi software but cannot manage firmware, so the administrator must ensure HSM is present to meet the requirement.

Exam trap

The trap here is assuming that a vendor add-on or base image automatically includes firmware management, when actually a separate Hardware Support Manager component is required.

261
MCQhard

A vSphere administrator is deploying VMs on a vSAN cluster with 6 hosts. Each host has two disk groups, each with one cache SSD and four capacity SSDs. The administrator applies a storage policy using RAID 5 erasure coding with Number of failures to tolerate set to 1. After some time, the administrator notices that several VMs are showing compliance status as 'Non-compliant'. Investigating further, the administrator finds that on one host, the cache SSD of the first disk group has failed. The capacity SSDs in that disk group are still functional. The vSAN cluster still has sufficient overall capacity and the health service shows no other issues. What is the most likely reason for the VMs' non-compliance?

A.The failed cache device reduces the overall cache capacity, causing the policy to be violated.
B.The vSAN cluster has lost a fault domain due to the failed cache device.
C.The RAID 5 policy requires a minimum of 4 hosts with cache devices, and now only 5 are available.
D.The failed cache device makes the entire disk group unavailable, so components on that disk group are inaccessible.
AnswerD

In vSAN, the cache tier is a single point of failure for its disk group. Losing the cache SSD renders the whole disk group inaccessible, so components stored on its capacity SSDs become absent, driving VMs non-compliant despite the cluster retaining sufficient capacity elsewhere.

Why this answer

A failed cache device renders the entire disk group non-operational; any VM components on that disk group become inaccessible, causing non-compliance. Option A is incorrect because cache capacity is not a compliance factor. Option B is incorrect because loss of a single cache device does not remove a fault domain.

Option C is incorrect because the number of hosts with cache devices is still sufficient.

262
Multi-Selecteasy

An administrator is analyzing performance data for a vSphere cluster and wants to identify VMs that are experiencing memory pressure. Which two metrics from esxtop or vCenter performance charts reliably indicate that a VM is actively reclaiming memory due to contention? (Choose two.)

Select 2 answers
A.Consumed memory
B.Active memory
C.Ballooned memory
D.Swapped memory
E.Overhead memory
AnswersC, D

Ballooned memory directly evidences the hypervisor reclaiming guest pages through the balloon driver, which only inflates under genuine host memory contention. It therefore satisfies the stem's requirement for a metric proving active reclamation, unlike metrics such as active memory or consumed memory that merely describe usage without confirming pressure-driven reclaim.

Why this answer

Ballooned memory (C) is correct because the balloon driver inflates inside the guest only when the ESXi host is under memory pressure and needs to reclaim pages from the VM, so a non-zero balloon value directly signals active reclamation due to contention. Swapped memory (D) is correct because host-level swapping occurs when the hypervisor has exhausted other reclamation options and forcibly moves VM pages to the swap file, which reliably indicates severe memory contention. Consumed memory (A) merely reflects the amount of physical host memory currently mapped to the VM and can be high without any pressure.

Active memory (B) measures the recently touched working set and is used for sizing, not for detecting reclamation. Overhead memory (E) is the fixed cost of virtualization resources for the VM and has no bearing on contention.

Exam trap

VCP-DCV often tests the distinction between demand metrics (consumed, active) and reclamation metrics (ballooned, swapped) — candidates confuse 'high memory usage' with 'memory pressure' and select consumed or active memory incorrectly.

263
MCQeasy

Refer to the exhibit. An ESXi 7.0 host is being configured for vSphere Trust Authority. The administrator runs the command shown and gets the output. What does this indicate?

A.The TPM 2.0 device is present but not accessible.
B.The command is incorrect; the correct command is 'esxcli system visorfs tpm list'.
C.The host does not have a TPM 2.0 chip, so vSphere Trust Authority cannot be used.
D.The host has a TPM 2.0 chip but it is not supported by ESXi.
AnswerC

A TPM 2.0 chip is mandatory for vSphere Trust Authority, since it stores the attestation key and measurement data used to prove host integrity. Without it, the host cannot be attested, so Trust Authority cannot be enabled on this ESXi 7.0 host.

Why this answer

The output shows 'No TPM device found', which indicates that the ESXi 7.0 host does not have a TPM 2.0 chip installed or it is not detected by the system. vSphere Trust Authority (vTA) requires a TPM 2.0 chip on each ESXi host to establish hardware-based attestation and secure the trusted infrastructure. Without a TPM 2.0, the host cannot participate in vTA, making option C correct.

Exam trap

The trap here is that candidates may confuse the absence of a TPM with a misconfiguration or an incorrect command, when in fact the output clearly indicates the hardware requirement is not met, and vTA cannot be enabled without a physical TPM 2.0 chip.

How to eliminate wrong answers

Option A is wrong because the output explicitly states 'No TPM device found', not that the TPM is present but inaccessible; an inaccessible TPM would typically show a different error or status. Option B is wrong because the command 'esxcli system visorfs tpm list' is not a valid ESXi command; the correct command to list TPM devices is 'esxcli hardware tpm list' (or similar), and the command shown in the exhibit is actually correct for checking TPM presence. Option D is wrong because if the host had a TPM 2.0 chip that was unsupported by ESXi, the output would likely indicate an unsupported version or a compatibility issue, not 'No TPM device found'.

264
MCQmedium

A company experiences frequent host failures. The cluster has 5 hosts with 128 GB RAM each. The VMs have vCPU and memory reservations ranging from 1 GHz/512 MB to 4 GHz/8 GB. The administrator needs to ensure that if one host fails, the remaining hosts can accommodate all VMs. Which admission control policy is recommended?

A.Define slot sizes based on the largest VM.
B.Use cluster resource percentage - reserve 20% CPU and memory.
C.Disable admission control and rely on DRS.
D.Use cluster resource percentage - reserve 25% CPU and memory.
AnswerB

20% (1/5) ensures one host failure is tolerated efficiently.

Why this answer

Percentage-based admission control with 20% reserve (equivalent to 1 out of 5 hosts) provides headroom for a single host failure while minimizing wasted capacity. For mixed VM sizes, slot-based admission control (Option A) can be inefficient due to varying reservation sizes. Disabling admission control (Option C) risks resource shortages during a failure.

Option D reserves 25%, which is more than necessary and wastes resources.

265
MCQhard

A vSphere administrator manages a cluster where several business-critical VMs must remain available even if an entire ESXi host fails. The administrator configures vSphere High Availability (HA) with host monitoring and admission control enabled, but the VMs are not configured with any restart priority. During a host failure, what is the default behavior for these VMs?

A.The VMs are not restarted because HA requires an explicit restart priority for every VM.
B.The VMs are restarted on surviving hosts according to the cluster's default VM restart priority.
C.The VMs are restarted only after an administrator manually approves the restart in the vSphere Client.
D.The VMs are migrated with vMotion to surviving hosts before the failed host goes down.
AnswerB

When a VM does not have an individual restart priority, vSphere HA applies the cluster-level default restart priority, which is typically medium. After a host failure is detected, the master host coordinates restart of affected VMs on hosts that have sufficient resources, subject to admission control reservations. The VMs therefore still receive HA protection without per-VM priority settings.

Why this answer

vSphere HA uses a cluster-level default restart priority when a VM has no individual setting. After detecting a host failure, the master host applies admission control and restarts the affected VMs on surviving hosts automatically. No per-VM priority, manual approval, or pre-failure vMotion is required for the VMs to be protected.

Exam trap

The trap here is believing HA needs a per-VM restart priority, when the cluster default applies whenever none is configured.

266
Multi-Selecteasy

Which TWO actions are effective in reducing CPU ready time on a vSphere host that is heavily overcommitted on CPU? (Choose two.)

Select 2 answers
A.Add more hosts to the cluster.
B.Enable hyperthreading on the host CPUs.
C.Increase the number of vCPUs on VMs with high ready times.
D.Reduce the number of vCPUs on over-provisioned VMs.
E.Configure CPU affinity to pin vCPUs to specific pCPUs.
AnswersA, D

Adding hosts expands the cluster's aggregate physical CPU capacity, so the same workload spreads across more cores. This lowers the vCPU-to-pCPU ratio, cutting the time VMs spend waiting in the run queue, which is precisely the overcommitment constraint the stem describes.

Why this answer

Option A is correct because CPU ready time reflects the percentage of time a vCPU is ready to run but is waiting for a physical CPU (pCPU) to become available; adding more hosts to the cluster increases the total pCPU capacity and reduces the vCPU-to-pCPU overcommitment ratio, directly lowering ready time. Option D is correct because reducing the number of vCPUs on over-provisioned VMs lowers the total number of vCPUs contending for the same pCPUs, which decreases scheduling contention and thus ready time. Option B is not correct because enabling hyperthreading exposes logical processors but does not add real execution resources, and it can even increase contention for physical cores.

Option C is not correct because adding vCPUs to VMs already experiencing high ready time increases the overcommitment and typically worsens ready time. Option E is not correct because CPU affinity pins vCPUs to specific pCPUs, which restricts the scheduler's flexibility and can increase ready time rather than reduce it.

Exam trap

VCP-DCV often tests the misconception that enabling hyperthreading or increasing vCPUs helps CPU ready time, when they can actually worsen it.

267
Drag & Dropmedium

Arrange the steps to add an existing virtual machine to a vCenter Server inventory.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence to add an existing VM to vCenter inventory is: right-click a datacenter or folder, select 'Add Existing Virtual Machine', browse to the VM's .vmx file, and click Finish. This order ensures the wizard is properly initiated and the VM is registered in the desired inventory location.

268
MCQmedium

A company has a vSphere environment with multiple clusters. The network team reports that a specific VLAN used for vMotion is intermittently dropping packets. What is the impact on vMotion operations?

A.vMotion will use the management network as fallback.
B.vMotion will fail with an error.
C.vMotion will work but at a reduced speed.
D.vMotion will automatically switch to another available network.
AnswerB

vMotion requires a reliable vMotion network; intermittent packet loss corrupts the migration stream, so the task aborts and returns an error rather than silently completing. The VM stays powered on at the source, but the operation itself fails.

Why this answer

vMotion requires a dedicated VMkernel adapter enabled for vMotion, and it does not fall back to the management network or any other interface if that specific network is unavailable or unreliable. When the vMotion VLAN is intermittently dropping packets, the vMotion process cannot maintain the reliable TCP connection needed to transfer the VM's memory state and device state, so the operation fails with an error. vSphere does not automatically reroute vMotion traffic to another network or degrade gracefully to a slower speed; it simply aborts the migration.

Exam trap

VCP-DCV often tests the misconception that vMotion will automatically fall back to the management network or another available network, or that it will simply slow down, when in fact it fails outright if the dedicated vMotion network is unreliable.

How to eliminate wrong answers

Option A is wrong because vMotion does not use the management network as a fallback; the management network is only used for vMotion if it is explicitly enabled for vMotion, and even then it is not an automatic fallback when a dedicated vMotion VMkernel adapter fails. Option C is wrong because vMotion does not throttle down to a reduced speed when packets are dropped; TCP retransmissions may occur, but intermittent loss severe enough to disrupt the connection causes the migration to fail rather than complete slowly. Option D is wrong because vMotion does not automatically switch to another available network; the VMkernel adapter selected for vMotion is fixed for that migration, and there is no dynamic failover to a different VMkernel interface or physical NIC team for vMotion traffic.

269
MCQeasy

An administrator is planning to decommission a vSphere cluster that currently uses baseline-based lifecycle management. They want to adopt image-based management for a new cluster. Which action must be taken to ensure a clean migration?

A.Manually recreate the baselines as images in the new cluster.
B.Assign host profiles to the new cluster to enforce configuration.
C.Export the existing baseline group and import it into the new cluster.
D.Create a new cluster with image-based management.
AnswerD

Creating a separate cluster lets vLCM manage hosts through a single desired-state image, avoiding the baseline-to-image conversion conflicts that arise when both methods coexist on the same cluster. This satisfies the clean migration constraint by keeping legacy baseline assignments isolated from the new image-based lifecycle management.

Why this answer

Image-based lifecycle management in vSphere Lifecycle Manager (vLCM) is a cluster-level construct; a cluster is either baseline-based or image-based, and you cannot convert an existing baseline-managed cluster in place. To adopt image-based management, you must create a new cluster configured for image-based management and then move hosts into it.

Exam trap

The trap is assuming baselines can be converted or exported into images; the exam tests whether you know that image-based management requires a new cluster because the two modes are mutually exclusive at the cluster level.

How to eliminate wrong answers

Option A is wrong because baselines and images are fundamentally different constructs — baselines are collections of patches/VIBs applied to hosts, while images are declarative desired-state specifications for an entire cluster, so you cannot simply recreate baselines as images. Option B is wrong because host profiles enforce configuration compliance and are orthogonal to lifecycle management; assigning them does not migrate a cluster from baseline to image-based management. Option C is wrong because baseline groups cannot be exported and imported as images; the data models are incompatible and vLCM does not provide such a conversion path.

270
Multi-Selectmedium

An administrator is planning to migrate from legacy baselines to vLCM for a cluster. Which TWO statements are true about vLCM?

Select 2 answers
A.vLCM allows individual host remediation for flexibility.
B.vLCM uses a desired state image to manage host configurations.
C.vLCM supports different images for different hosts in the same cluster.
D.vLCM can integrate with Hardware Support Manager for firmware updates.
E.vLCM uses baseline groups to apply updates.
AnswersB, D

vLCM replaces per-host baselines with a single desired-state image declared for the whole cluster. Hosts are remediated to match that image, so this statement accurately describes vLCM's core model and satisfies the stem's migration-planning question.

Why this answer

Option B is correct because vLCM (vSphere Lifecycle Manager) operates on a desired-state image model, where an administrator defines a single image (base ESXi version plus components and firmware add-ons) that the cluster's hosts are remediated to match. Option D is correct because vLCM integrates with a Hardware Support Manager (HSM) provided by OEM vendors, enabling firmware updates to be delivered alongside ESXi and driver updates through the same image. Option A is not correct because vLCM enforces a cluster-wide image, so remediation is applied at the cluster level rather than allowing per-host flexibility as legacy baselines did.

Option C is not correct because all hosts in a vLCM-managed cluster must conform to the same desired-state image; different images per host are not supported within one cluster. Option E is not correct because baseline groups are a feature of legacy vSphere Update Manager baselines, not vLCM, which replaces baselines with images.

Exam trap

The trap here is that candidates confuse vLCM's cluster-wide image with the older baseline-based approach, mistakenly thinking vLCM supports per-host flexibility or baseline groups, when in fact it enforces a single desired state image for the entire cluster.

271
MCQmedium

A vSphere administrator is troubleshooting a VM that is experiencing excessive disk latency. The VM is on a datastore accessed via NFS over a 1GbE network. The host shows high network utilization. Which action should be taken to improve performance?

A.Enable Storage I/O Control on the datastore.
B.Convert the datastore from NFS to VMFS.
C.Increase the memory reservation for the VM.
D.Upgrade the network link to 10GbE or enable multiple NICs with teaming.
AnswerD

NFS traffic traverses the 1GbE link, so high network utilisation saturates the path and inflates disk latency. Upgrading to 10GbE, or teaming multiple NICs, raises aggregate throughput and relieves that bottleneck, directly addressing the constrained network link.

Why this answer

The VM is experiencing excessive disk latency due to high network utilization on the 1GbE link. Since NFS storage traffic is entirely network-bound, upgrading to 10GbE or enabling multiple NICs with teaming increases the available bandwidth, reduces congestion, and directly addresses the root cause of the latency. This is the most effective action because the bottleneck is at the network layer, not the storage protocol or VM configuration.

Exam trap

The trap here is that candidates may assume Storage I/O Control (SIOC) can solve any storage latency issue, but SIOC only manages contention at the storage array level, not network bandwidth limitations, which is the actual bottleneck in this NFS scenario.

How to eliminate wrong answers

Option A is wrong because Storage I/O Control (SIOC) manages storage queue depth and I/O shares at the datastore level, but it does not increase network bandwidth or resolve a saturated 1GbE link; it is designed for VMFS datastores with multiple VMs contending for storage resources, not for NFS network congestion. Option B is wrong because converting from NFS to VMFS changes the storage protocol but does not increase network throughput; the 1GbE bottleneck remains, and VMFS over iSCSI or Fibre Channel would still suffer from the same network limitation. Option C is wrong because increasing the memory reservation for the VM does not affect network I/O or disk latency; memory reservations guarantee physical RAM but have no impact on storage path bandwidth or network utilization.

272
MCQhard

Refer to the exhibit. The performance data shows MEMCTL at 5% and SWPOUT at 2%. What does this indicate about the host?

A.The host is over-committed on memory, causing ballooning and swapping.
B.The host is experiencing CPU contention.
C.The host has network congestion.
D.The host has high storage latency.
AnswerA

MEMCTL at 5% reflects the balloon driver reclaiming guest memory, while SWPOUT at 2% confirms the hypervisor is swapping to disk. Together these counters indicate the host has over-committed physical memory beyond what its workload demands, so ESXi is actively reclaiming pages to satisfy the configured memory constraint.

Why this answer

MEMCTL at 5% indicates the ESXi host's memory balloon driver (vmmemctl) is actively reclaiming memory from virtual machines, while SWPOUT at 2% shows the host is swapping guest memory to disk. Together, these values confirm the host is over-committed on memory, forcing the hypervisor to use both ballooning and swapping to free up memory for VMs.

Exam trap

The trap here is that candidates may confuse memory over-commitment indicators (MEMCTL, SWPOUT) with CPU or storage performance metrics, leading them to select CPU contention or storage latency options instead of recognizing the specific memory reclamation counters.

How to eliminate wrong answers

Option B is wrong because CPU contention is measured by metrics like %RDY, %CSTP, or CPU ready time, not MEMCTL or SWPOUT. Option C is wrong because network congestion is indicated by dropped packets, high latency, or errors on virtual switches, not memory-related counters. Option D is wrong because high storage latency is shown by metrics such as KAVG, DAVG, or QAVG in esxtop, not by memory ballooning or swap rates.

273
Multi-Selecthard

Which THREE vSphere features directly contribute to performance and scaling of virtualized workloads? (Select THREE.)

Select 3 answers
A.vSphere vMotion
B.Storage I/O Control (SIOC)
C.vSphere DRS
D.vSphere Fault Tolerance
E.vSphere HA
AnswersA, B, C

vSphere vMotion enables live migration of running workloads between hosts, supporting load balancing across a cluster without downtime. This directly satisfies the scaling constraint by allowing distributed resource scheduler to redistribute virtual machines, preventing host contention and maintaining performance as demand shifts across the virtualized environment.

Why this answer

vSphere vMotion (A) is correct because it enables live migration of running VMs between hosts with no downtime, which supports performance and scaling by allowing workload redistribution and maintenance without service interruption. Storage I/O Control (B) is correct because it enforces per-VM or per-datastore I/O shares and limits during congestion, directly managing storage performance and preventing noisy-neighbor effects in scaled environments. vSphere DRS (C) is correct because it continuously balances CPU and memory load across hosts in a cluster using vMotion, directly improving performance and enabling horizontal scaling. Fault Tolerance (D) and vSphere HA (E) are not correct here because they primarily provide availability and rapid recovery from host failures, not direct performance or scaling optimization of virtualized workloads.

Exam trap

VCP-DCV often tests the distinction between availability features (HA, FT) and performance/scaling features (vMotion, DRS, SIOC) — candidates may incorrectly include HA or FT because they are prominent vSphere capabilities, but they do not directly improve performance or scaling.

274
MCQeasy

A company is deploying a new vSphere 8 environment. The administrator needs to provide a centralized management interface for configuring and monitoring ESXi hosts and virtual machines. Which vSphere component fulfills this requirement?

A.vSphere Update Manager
B.vCenter Server
C.vSphere Client
D.ESXi host
AnswerB

vCenter Server is the centralized management platform for vSphere. It provides a single interface to manage ESXi hosts, virtual machines, datastores, and networking. It also enables advanced features like DRS, HA, and vMotion. The administrator can use the vSphere Client to connect to vCenter Server for all management tasks.

Why this answer

vCenter Server is the centralized management component of vSphere. It provides a single interface to manage ESXi hosts, virtual machines, and other resources, and enables advanced features like DRS, HA, and vMotion. The vSphere Client is just a UI, while ESXi and Update Manager serve different roles.

Exam trap

The trap here is confusing the vSphere Client (the user interface) with vCenter Server (the management platform), or assuming that an ESXi host can provide centralized management.

275
MCQmedium

An administrator notices that after applying a vLCM image to a cluster, some hosts fail compliance with error: 'Host does not have required add-on'. What is the most likely cause?

A.The add-on is not present in the vLCM depot.
B.The vCenter license does not include vLCM.
C.The host is not in maintenance mode during the check.
D.The host does not have internet access to download the add-on.
AnswerA

An add-on compliance failure means the desired image references an add-on component that the vLCM depot cannot resolve, so hosts report it as missing. Adding the required add-on to the depot, or removing it from the image specification, restores compliance.

Why this answer

vLCM image compliance checks compare the host's installed software against the desired image, including base image, components, and add-ons. The error 'Host does not have required add-on' means the image references an add-on (e.g., a vendor add-on like NSX or a custom add-on) that is not available in the configured depot. Without the add-on in the depot, vLCM cannot remediate the host to match the image.

Exam trap

VCP-DCV often tests the misconception that compliance errors relate to maintenance mode or licensing, when the specific 'required add-on' message points to depot content availability.

How to eliminate wrong answers

Option B is wrong because vLCM is included in all vSphere editions that support it (Enterprise Plus and above); a license issue would produce a different error, not a missing add-on. Option C is wrong because maintenance mode is required for remediation, not for compliance checking — compliance can be evaluated while the host is running. Option D is wrong because hosts do not download add-ons directly from the internet; vLCM uses the depot configured in vCenter (online or offline), so internet access on the host is irrelevant.

276
MCQmedium

Refer to the exhibit. What is the cause of the non-compliance?

A.The host has an outdated firmware version
B.The compliance scan failed
C.The host's hardware is not supported
D.The host is running an older ESXi version than desired
AnswerD

Compliance against a desired-state baseline fails when the host's actual ESXi build does not match the specified target version. Running an older ESXi version than the image requires is precisely the drift that marks the host non-compliant.

Why this answer

In vSphere Lifecycle Manager (vLCM) image-based compliance, a host is marked non-compliant when its installed ESXi version does not match the version specified in the desired image. The exhibit shows a version mismatch between the host's current ESXi build and the target image, which is the direct cause of non-compliance. Firmware, scan failures, and hardware support are separate checks that would produce different error indicators.

Exam trap

The trap is conflating firmware compliance with ESXi version compliance — candidates see 'non-compliant' and pick firmware, but the exhibit's version mismatch specifically points to an older ESXi build.

How to eliminate wrong answers

Option A is wrong because outdated firmware is reported under the firmware add-on compliance check, not as a general ESXi version non-compliance, and the exhibit points to a version delta. Option B is wrong because a failed compliance scan produces a 'scan error' or 'unknown' state, not a definitive non-compliant result with a version mismatch. Option C is wrong because unsupported hardware would prevent the host from being added to the cluster or image at all, rather than showing a version-based non-compliance.

277
MCQmedium

An administrator is planning a new vSphere deployment and wants to use a storage architecture that presents file-level storage over the network, supports VMware vStorage APIs for Array Integration (VAAI) primitives, and allows multiple ESXi hosts to access the same datastore concurrently. Which storage type best matches these requirements?

A.iSCSI software adapter LUN
B.VMFS on a Fibre Channel LUN
C.NFS 3.1 datastore
D.Virtual Volumes (vVols) on NFS
AnswerC

NFS is a file-level storage protocol presented over the network. ESXi supports NFS 3.1 and NFS 4.1 datastores, and NFS 3.1 supports VAAI primitives such as full-file clone and space reservation. Multiple ESXi hosts can mount the same NFS export concurrently and use it as a shared datastore for HA and vMotion, matching all the stated requirements.

Why this answer

NFS is the file-level network storage protocol in vSphere. NFS 3.1 datastores support VAAI primitives and can be mounted by multiple ESXi hosts simultaneously, enabling shared storage for HA and vMotion. Fibre Channel and iSCSI are block-level, and vVols is an array-integration framework, so NFS best matches the requirements.

Exam trap

The trap here is assuming that any shared datastore technology meets the file-level requirement; block protocols like Fibre Channel and iSCSI are shared but operate at the block layer, not the file layer.

278
MCQhard

An administrator creates a DRS rule to separate two VMs (VM1 and VM2) using a 'Should' rule (separate VMs). After the rule is created, VM1 is manually vMotioned to a host that already runs VM2. What is the expected behavior?

A.VM1 remains on the host and a compliance violation is logged.
B.DRS automatically migrates VM1 to a compliant host.
C.The target host is placed into maintenance mode.
D.VM1 is powered off to prevent performance issues.
AnswerA

A 'Should' rule is a soft preference, not a hard constraint. DRS permits the manual vMotion, keeps VM1 where placed, and records a compliance violation against the rule in the cluster's DRS compliance view, leaving remediation to the administrator.

Why this answer

A 'Should' rule in DRS is a soft rule, meaning it is not strictly enforced. If an administrator manually vMotion's VM1 to a host running VM2, DRS will not automatically migrate it away; instead, it will log a compliance violation. The VM remains on the host, and the violation is recorded for review.

Exam trap

VCP-DCV often tests the difference between 'Must' and 'Should' DRS rules, and candidates may incorrectly assume that all rules are automatically enforced.

How to eliminate wrong answers

Option B is wrong because DRS does not automatically migrate VMs for 'Should' rules; it only provides recommendations. Option C is wrong because maintenance mode is not triggered by rule violations. Option D is wrong because DRS never powers off VMs to resolve rule violations.

279
Multi-Selecthard

A vSphere administrator is troubleshooting performance issues in a cluster with 4 ESXi hosts, each with 2 sockets of 16-core CPUs (32 logical processors per host). The cluster runs 80 VMs, each with 4 vCPUs, and users report slow application response. The administrator observes high CPU ready time on the VMs. Which TWO actions would be most effective in reducing CPU ready time while maintaining performance? (Choose two.)

Select 2 answers
A.Increase the CPU shares for all VMs to high priority.
B.Reduce the number of vCPUs per VM to match actual workload demand.
C.Add more ESXi hosts to the cluster to increase the total number of physical cores.
D.Enable CPU affinity for all VMs to pin them to specific physical cores.
E.Disable hyperthreading on all hosts to ensure each vCPU maps to a physical core.
AnswersB, C

Reducing vCPU count per VM decreases the number of virtual CPUs that the host scheduler must co-schedule, which can significantly lower CPU ready time. Many workloads do not require all allocated vCPUs, and over-provisioning vCPUs leads to co-scheduling overhead and increased ready time. Right-sizing VMs to their actual demand reduces contention and improves scheduling efficiency.

Why this answer

High CPU ready time indicates that VMs are waiting for physical CPU resources. Reducing vCPU count per VM lowers co-scheduling demands and contention, while adding hosts increases the total physical cores available, both directly reducing ready time. The other options either do not address the root cause or can worsen performance by restricting scheduling flexibility or reducing capacity.

Exam trap

The trap here is thinking that adjusting CPU shares or enabling affinity will reduce ready time, when in fact shares only redistribute contention and affinity can limit scheduler flexibility, often increasing ready time.

280
MCQeasy

A vSphere administrator is using vSphere Lifecycle Manager (vLCM) to manage an ESXi cluster. The administrator wants to check the compliance status of the cluster against the desired image without making any changes. Which vLCM operation should the administrator perform?

A.Scan
B.Export
C.Remediate
D.Import
AnswerA

Scanning checks each host's current state against the desired image and reports compliance without applying any changes. It is a read-only operation that provides the compliance status. This is exactly what the administrator needs to verify compliance without modifying hosts.

Why this answer

The Scan operation in vLCM evaluates each host's software and firmware against the desired image and produces a compliance status without making changes. Remediation would apply updates, while import and export deal with image management rather than compliance checking. Therefore, scanning is the correct operation to assess compliance safely.

Exam trap

The trap here is confusing scanning with remediation; scanning only reports compliance, while remediation actually applies the desired state.

281
MCQhard

A company is deploying a high-performance database workload on vSphere. The storage array supports NVMe over RDMA (NVMe-oF) and iSCSI. The workload requires extremely low latency and high IOPS. The network is dedicated 25 Gbps Ethernet with RoCE v2 support. Which storage protocol should be recommended, and why?

A.NFS, because it supports advanced features like Storage DRS
B.NVMe over RDMA, because it provides direct memory access and lower CPU overhead
C.Fibre Channel, because it is the fastest protocol available
D.iSCSI, because it is simpler to configure and does not require RDMA support
AnswerB

NVMe over RDMA performs direct memory access between host and array, bypassing much of the TCP/IP stack. On the dedicated 25 Gbps RoCE v2 fabric this cuts CPU overhead and latency, meeting the workload's extremely low latency and high IOPS requirement.

Why this answer

NVMe over RDMA (NVMe-oF with RoCE v2) provides direct memory access between the host and storage target, bypassing much of the TCP/IP stack and dramatically reducing CPU overhead and latency. For a high-IOPS, low-latency database workload on a dedicated 25 Gbps RoCE-capable network, this is the optimal choice. It leverages the existing RDMA fabric to deliver near-local NVMe performance.

Exam trap

VCP-DCV often tests the assumption that Fibre Channel is always the fastest option; candidates must recognize that NVMe over RDMA can surpass FC in latency and CPU efficiency when the fabric supports it.

How to eliminate wrong answers

Option A is wrong because NFS is a file-level protocol with higher latency and does not provide the block-level, low-latency access a high-performance database requires; Storage DRS is a vSphere feature unrelated to protocol speed. Option C is wrong because Fibre Channel, while fast and mature, is not inherently faster than NVMe-oF and would require separate FC HBAs and switching, ignoring the available 25 Gbps RoCE infrastructure. Option D is wrong because iSCSI runs over TCP and lacks RDMA's direct memory access, resulting in higher CPU utilization and latency — the opposite of what the workload demands.

Page 3

Page 4 of 4

All pages