VCP-DCV vSphere Security Practice Question
An administrator is troubleshooting a failed attempt to add an ESXi host to a vCenter Server domain. The error message states: 'The host's certificate has been tampered with or is invalid.' What is the most likely cause?
⚠ Common exam trap
Test-takers frequently confuse certificate expiration with thumbprint mismatch, but the error message 'tampered with or invalid' specifically points to a thumbprint mismatch rather than a date-based validity issue.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The ESXi host's certificate thumbprint does not match the thumbprint stored in vCenter Server.
The error 'The host's certificate has been tampered with or is invalid' occurs when the ESXi host presents a certificate whose thumbprint does not match the thumbprint that vCenter Server has stored for that host. This mismatch can happen if the host's certificate was replaced (e.g., due to a reinstall or manual rotation) without updating the vCenter Server's trusted store. vCenter Server verifies the host's identity by comparing the SHA-1 or SHA-256 thumbprint of the presented certificate against its stored record; a mismatch triggers this specific error.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The vCenter Server's account lockout policy has been triggered.
Why it's wrong here
Account lockout governs authentication attempts, not certificate trust; it cannot corrupt or invalidate an ESXi host certificate. It is tempting because lockouts do block host additions, but only after repeated credential failures, producing a distinct authentication error rather than a tampered-certificate warning.
- ✗
The ESXi host's SSH keys have been rotated.
Why it's wrong here
Rotating SSH keys affects remote shell authentication only and leaves the TLS certificate presented to vCenter untouched. Key rotation is the correct action when SSH access fails after a security hardening cycle, not when certificate validation fails.
- ✗
The ESXi host's certificate has expired.
Why it's wrong here
An expired certificate produces a distinct expiry or validity-period error, not a tampering or invalid-signature message. Expiry is tempting because certificate problems commonly cause host-add failures, but vCenter reports tampering when the certificate's signature or thumbprint does not match the expected CA-issued value.
- ✓
The ESXi host's certificate thumbprint does not match the thumbprint stored in vCenter Server.
Why this is correct
vCenter stores the ESXi thumbprint captured at first connection; any mismatch, such as after a host certificate regeneration or reinstall, triggers the tampered-or-invalid error. The stored thumbprint no longer matches the host's presented certificate, blocking the add.
Go deeper
Related to this question
About these practice questions
This VCP-DCV question is part of Courseiva's 281-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.