A multinational corporation runs a vSphere environment with 100 ESXi hosts managed by a single vCenter Server. The security team mandates that all virtual machine disks (VMDKs) must be encrypted at rest. The administrator enables vSphere Virtual Machine Encryption and creates a Key Management Server (KMS) cluster. After encrypting a test VM, the VM powers on successfully, but the administrator notices that the VM's configuration files (VMX, NVRAM) are not encrypted. The security policy requires that all VM files, including configuration files, be encrypted. The administrator checks the VM storage policy and sees that the policy is set to 'VM Encryption Policy' with 'Disk Encryption' enabled. What should the administrator do to ensure the entire VM is encrypted?
The VM storage policy's VM Encryption Policy encrypts only VMDKs by default; VM home files (VMX, NVRAM) require the separate 'Encrypt VM home files' setting. Enabling that component in the policy satisfies the mandate that configuration files be encrypted at rest.
Why this answer
The VM storage policy 'VM Encryption Policy' with only 'Disk Encryption' enabled encrypts VMDK files but not the VM configuration files (VMX, NVRAM, logs, etc.). To encrypt all VM files, the storage policy must include the 'Encrypt VM home files' option, which applies encryption to the entire VM home directory on the datastore. This ensures compliance with the security mandate for full VM encryption at rest.
Exam trap
The trap here is that candidates assume 'VM Encryption Policy' with 'Disk Encryption' covers all VM files, but VMware explicitly separates disk encryption from home file encryption in the storage policy settings.
How to eliminate wrong answers
Option B is wrong because datastore-level encryption (e.g., vSAN encryption or Storage DRS encryption) is a separate feature that encrypts the entire datastore, but it does not selectively encrypt VM home files when using VM Encryption Policy; the policy must explicitly include home file encryption. Option C is wrong because adding a second KMS cluster provides redundancy for key management but does not affect which VM files are encrypted; the encryption scope is defined by the storage policy, not the KMS topology. Option D is wrong because vSphere Host Encryption encrypts host memory and vMotion traffic, not VM files at rest on the datastore; it does not address VMDK or configuration file encryption.