Courseiva
vSphere Security →mediumMultiple Select

VCP-DCV vSphere Security Practice Question

An administrator is configuring role-based access control in vCenter Server 7.0. A new security policy requires that users can only view the inventory and cannot perform any changes. The administrator creates a custom role with only read-only privileges. Which two actions must the administrator take to ensure the role is effective for a group of users? (Choose two.)

⚠ Common exam trap

The trap here is forgetting that vCenter permissions require the group to be recognized by SSO before it can be assigned a role, and assuming that assigning at the root without propagation is sufficient.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensure the users are members of an Active Directory group that is added to vCenter Single Sign-On as a group.

To grant a group of users read-only access to the entire vCenter inventory, the administrator must first ensure the group is known to vCenter Single Sign-On, typically by adding the Active Directory group as an SSO group. Then, the read-only role should be assigned to that group at the root folder with 'Propagate to children' enabled. This ensures all group members inherit view-only permissions on all current and future objects. Individual assignments or overly permissive roles do not meet the requirement efficiently or securely.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Grant the users the 'Administrator' role at the root folder to ensure they can see all objects.

    Why it's wrong here

    Granting the Administrator role provides full control, including the ability to modify and delete objects, which violates the requirement that users can only view the inventory. The Administrator role is far too permissive and would allow changes. The correct approach is to use a read-only role, not an administrative one, to meet the security policy.

  • ✓

    Ensure the users are members of an Active Directory group that is added to vCenter Single Sign-On as a group.

    Why this is correct

    For the role to apply to a group of users, the group must be recognized by vCenter Single Sign-On. Adding the Active Directory group as a vSphere SSO group allows permissions to be assigned to that group. Then, assigning the role to the group at the root folder with propagation grants all members the desired access. Without SSO group configuration, the group cannot be used in permission assignments.

  • ✗

    Set the users' login to use a read-only mode in the vSphere Client.

    Why it's wrong here

    There is no 'read-only mode' login setting in the vSphere Client. Access control is enforced through roles and permissions assigned to users or groups. The vSphere Client does not have a global read-only mode for individual users. Therefore, this option is not a valid method to restrict users to view-only access; permissions must be configured instead.

  • ✓

    Assign the role to the users on the root folder with 'Propagate to children' enabled.

    Why this is correct

    Assigning the read-only role at the root folder with propagation ensures that the permission is inherited by all child objects, giving the users read-only access to the entire inventory. This is the most efficient way to grant view-only access across the board. Without propagation, the permission would apply only to the root folder itself, and users would not see or access child objects.

  • ✗

    Assign the role to the users on each individual VM and host object.

    Why it's wrong here

    Assigning the role individually to each VM and host is labor-intensive and error-prone, especially in large environments. It also does not guarantee that new objects will be covered. The requirement is to grant read-only access to the inventory, and assigning at the root with propagation is the correct and scalable method. Individual assignments are unnecessary and inefficient.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 281 original VCP-DCV practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official VMware exam blueprint

This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.