VCP-DCV vSphere Security Practice Question
An administrator is configuring role-based access control in vCenter Server 7.0. A new security policy requires that users can only view the inventory and cannot perform any changes. The administrator creates a custom role with only read-only privileges. Which two actions must the administrator take to ensure the role is effective for a group of users? (Choose two.)
⚠ Common exam trap
The trap here is forgetting that vCenter permissions require the group to be recognized by SSO before it can be assigned a role, and assuming that assigning at the root without propagation is sufficient.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure the users are members of an Active Directory group that is added to vCenter Single Sign-On as a group.
To grant a group of users read-only access to the entire vCenter inventory, the administrator must first ensure the group is known to vCenter Single Sign-On, typically by adding the Active Directory group as an SSO group. Then, the read-only role should be assigned to that group at the root folder with 'Propagate to children' enabled. This ensures all group members inherit view-only permissions on all current and future objects. Individual assignments or overly permissive roles do not meet the requirement efficiently or securely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Grant the users the 'Administrator' role at the root folder to ensure they can see all objects.
Why it's wrong here
Granting the Administrator role provides full control, including the ability to modify and delete objects, which violates the requirement that users can only view the inventory. The Administrator role is far too permissive and would allow changes. The correct approach is to use a read-only role, not an administrative one, to meet the security policy.
- ✓
Ensure the users are members of an Active Directory group that is added to vCenter Single Sign-On as a group.
Why this is correct
For the role to apply to a group of users, the group must be recognized by vCenter Single Sign-On. Adding the Active Directory group as a vSphere SSO group allows permissions to be assigned to that group. Then, assigning the role to the group at the root folder with propagation grants all members the desired access. Without SSO group configuration, the group cannot be used in permission assignments.
- ✗
Set the users' login to use a read-only mode in the vSphere Client.
Why it's wrong here
There is no 'read-only mode' login setting in the vSphere Client. Access control is enforced through roles and permissions assigned to users or groups. The vSphere Client does not have a global read-only mode for individual users. Therefore, this option is not a valid method to restrict users to view-only access; permissions must be configured instead.
- ✓
Assign the role to the users on the root folder with 'Propagate to children' enabled.
Why this is correct
Assigning the read-only role at the root folder with propagation ensures that the permission is inherited by all child objects, giving the users read-only access to the entire inventory. This is the most efficient way to grant view-only access across the board. Without propagation, the permission would apply only to the root folder itself, and users would not see or access child objects.
- ✗
Assign the role to the users on each individual VM and host object.
Why it's wrong here
Assigning the role individually to each VM and host is labor-intensive and error-prone, especially in large environments. It also does not guarantee that new objects will be covered. The requirement is to grant read-only access to the inventory, and assigning at the root with propagation is the correct and scalable method. Individual assignments are unnecessary and inefficient.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 281 original VCP-DCV practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official VMware exam blueprint
This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.