Courseiva

VCP-DCV · domain

vSphere Security

This domain covers vSphere security hardening and operations: vMotion and VM encryption, KMS and vSphere Trust Authority, ESXi host security, permissions and SSO, and upgrade security implications. Questions are scenario-based, asking you to identify the additional configuration, component, or consideration needed to meet a stated security requirement.

34 questions9 easy16 medium9 hard

Focused practice

Practice vSphere Security questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about vSphere Security

Be able to configure and troubleshoot vMotion encryption, VM encryption with an external KMS, and ESXi host hardening. The single most important thing: know that enabling encryption at one layer does not automatically encrypt traffic or data at another, so verify every required component.

Enabling vMotion encryption at cluster level and the required ESXi host and VMkernel configuration

VM encryption architecture using external KMS, vSphere Trust Authority, and encrypted vMotion

ESXi host security features including lockdown mode, secure boot, and TPM-based attestation

vCenter SSO authentication, permissions, roles, and certificate or PSC upgrade considerations

Watch out for

Common vSphere Security exam traps

  • ▸Assuming cluster-level vMotion encryption alone is sufficient, without configuring the VMkernel adapter or host-level encryption settings.
  • ▸Confusing VM encryption with vSAN encryption or vSphere Trust Authority, and mixing up which component manages keys.
  • ▸Overlooking that external PSC deployments are deprecated in vSphere 7.0, affecting upgrade and security planning.

Question index

All vSphere Security questions (34)

Click any question to see the full explanation, or start a practice session above.

1

An administrator wants to ensure that no user can view or modify VMs in a particular folder except the folder owner. What is the proper method to achieve this?

Easy
2

Which TWO statements about vCenter Single Sign-On (SSO) are true? (Choose two.)

Hard
3

An administrator is configuring role-based access control in a vSphere 8 environment with a single vCenter Server. A user must be able to create and delete virtual machines in a specific cluster, but must not be able to modify the cluster's HA or DRS settings. Permissions should be assigned at the cluster level and must not propagate to other clusters. Which approach should the administrator take?

Medium
4

A financial institution operates a vSphere 7.0 environment with three vCenter Servers in linked mode, each managing separate clusters. The company uses vSAN encryption with an external KMS appliance from a third-party vendor. The KMS appliance has a certificate that expires every two years. The storage administrator recently renewed the KMS certificate as per the vendor's instructions. After the renewal, the vCenter Server's 'Key Management Servers' view shows the KMS status as 'Unhealthy'. The administrator attempts to decrypt a test virtual machine, but the operation fails with an error: 'No key providers are available'. The KMS appliance is reachable from the vCenter Server, and the new certificate is installed on the KMS. The administrator has confirmed that the KMS IP address and port are correctly configured in vCenter. What is the most likely cause of the failure?

Hard
5

A large financial institution runs a vSphere 7.0 environment with 100 ESXi hosts and 2,000 VMs. The security team has identified that several VMs are vulnerable to a critical side-channel attack that requires disabling hyperthreading on the ESXi hosts. The administrator needs to implement a solution that minimizes performance impact while ensuring compliance. The environment uses DRS clusters with varying workloads: some VMs are CPU-intensive (financial modeling) and others are memory-bound (database servers). The administrator cannot afford to take hosts offline for maintenance during business hours. The change must be implemented within 48 hours. Which course of action should the administrator take?

Hard
6

An administrator is configuring role-based access control in vCenter Server 7.0. A new security policy requires that users can only view the inventory and cannot perform any changes. The administrator creates a custom role with only read-only privileges. Which two actions must the administrator take to ensure the role is effective for a group of users? (Choose two.)

Medium
7

A vSphere administrator wants to restrict direct console access to an ESXi host to authorized administrators only, without interrupting running virtual machines. Which feature should the administrator enable?

Easy
8

A retail company's vSphere 8 environment uses vCenter Single Sign-On (SSO) with an external identity provider via SAML. The security team wants to enforce multi-factor authentication (MFA) for all administrators logging into vCenter Server. Which SSO configuration should the administrator implement?

Medium
9

Which TWO of the following are valid methods to restrict access to the ESXi host's Direct Console User Interface (DCUI) to authorized administrators only?

Medium
10

A company requires all vMotion traffic to be encrypted. The vSphere administrator enables vMotion encryption at the cluster level. What else must be configured to ensure vMotion operations are encrypted?

Medium
11

A company wants to integrate vCenter Server with an external identity source to allow users to authenticate using their corporate credentials. The administrator must ensure that authentication traffic is encrypted. Which solution should the administrator implement?

Easy
12

A vSphere administrator needs to ensure that all virtual machine disks are encrypted at rest. The environment uses a KMS cluster with multiple KMIP-compliant servers. The administrator has already configured a storage policy with encryption enabled. However, newly created VMs on a particular datastore still show unencrypted disks. What is the most likely cause?

Medium
13

A vSphere administrator wants to prevent users in a custom role from powering off virtual machines that have Fault Tolerance enabled. Which privilege must be removed from the custom role?

Easy
14

A healthcare provider's vSphere 8 environment must encrypt all VM files at rest. The security team requires that encryption keys be stored on a hardware security module (HSM) and that the vCenter Server never hold the keys in its database. An administrator configures a Key Provider and enables VM encryption. Which component is responsible for storing the encryption keys?

Medium
15

A security team requires that all vCenter Server administrative logins be validated against an external identity source, but they also want to retain the ability to log in with the local SSO administrator account during a directory service outage. An administrator has already added the Active Directory identity source to vCenter Single Sign-On. Which configuration should the administrator apply to meet both requirements?

Medium
16

A company runs a critical e-commerce platform on a vSphere 7 cluster with ESXi hosts connected to a vSAN datastore. The environment uses vSphere Trust Authority (vTA) and VM encryption with an external KMS. Recently, after a successful vTA attestation, one of the VMs (WebServer-01) failed to power on with the error: 'Unable to decrypt the encrypted virtual machine upon re-registration. Reason: The KMS server is unreachable.' The administrator verifies that other encrypted VMs on the same host power on successfully. The KMS cluster consists of two servers: KMS-01 and KMS-02, both accessible from the management network. The administrator checks the VM's configuration and finds that it uses a custom storage policy with encryption. What is the most likely cause of this specific VM's failure?

Hard
17

Which TWO actions are required to enable vSphere VM encryption? (Choose two.)

Easy
18

A vSphere environment uses Active Directory for authentication. The administrator notices that users from a specific AD group cannot log in to the vCenter Server, although other AD users can. The group is added to vCenter Server with the correct permissions. What is the most likely cause?

Hard
19

An administrator is adding an ESXi host to vCenter Server and is prompted to verify the host's certificate thumbprint. The administrator compares it to the output above and it matches. However, the add operation fails with a certificate verification error. What else could be the issue?

Medium
20

A security administrator notices that a virtual machine (VM) running a legacy application is experiencing network connectivity issues after enabling Network I/O Control (NIOC) on the distributed switch. The VM is in a high-priority traffic class for management traffic. What is the most likely cause of the issue?

Medium
21

An administrator notices that HTTP connections to the ESXi host are timing out frequently. Based on the exhibit, which configuration change would most likely resolve the issue?

Medium
22

A company uses an external Platform Services Controller (PSC) in a vSphere 6.7 environment. They plan to upgrade to vSphere 7.0. Which security-related consideration is most important?

Hard
23

A security audit requires that all ESXi hosts in a vSphere 7.0 environment use encrypted connections for remote logging. An administrator configures the syslog service on each host to send logs to a central server. Which setting should be enabled to ensure the logs are transmitted over TLS?

Easy
24

An administrator wants to configure the ESXi host firewall to allow connections only from a specific management subnet. How can this be achieved?

Easy
25

An administrator runs the command shown in the exhibit on a vCenter Server appliance. What is the primary purpose of the Machine ID?

Easy
26

An administrator is troubleshooting a failed attempt to add an ESXi host to a vCenter Server domain. The error message states: 'The host's certificate has been tampered with or is invalid.' What is the most likely cause?

Easy
27

A company is implementing vSphere 7.0 and wants to encrypt all vMotion traffic between ESXi hosts in a cluster. The cluster is not using any other encryption features. What is the minimum requirement to enable vMotion encryption?

Medium
28

A multinational corporation runs a vSphere environment with 100 ESXi hosts managed by a single vCenter Server. The security team mandates that all virtual machine disks (VMDKs) must be encrypted at rest. The administrator enables vSphere Virtual Machine Encryption and creates a Key Management Server (KMS) cluster. After encrypting a test VM, the VM powers on successfully, but the administrator notices that the VM's configuration files (VMX, NVRAM) are not encrypted. The security policy requires that all VM files, including configuration files, be encrypted. The administrator checks the VM storage policy and sees that the policy is set to 'VM Encryption Policy' with 'Disk Encryption' enabled. What should the administrator do to ensure the entire VM is encrypted?

Hard
29

A vSphere administrator needs to ensure that vCenter Server can authenticate users against an Active Directory over LDAP identity source. The environment uses vCenter Server 7.0. Which two configurations are required to successfully add the identity source? (Choose two.)

Hard
30

An organization is implementing vSphere Trust Authority for sensitive workloads. The administrator must configure the trusted ESXi hosts to attest to vCenter Server. Which component is responsible for performing attestation?

Hard
31

During a security audit, it is found that the vCenter Server is using the default self-signed certificate. The administrator is tasked to replace it with a certificate from an enterprise CA. What is the first step after obtaining the CA-signed certificate?

Medium
32

An organization is using vSphere Trust Authority (vTA) to secure ESXi hosts. A newly added ESXi host fails to attest with the Trust Authority. The administrator verifies that the host is connected to the vTA cluster and the trust relationship is configured. What is the most likely cause of the attestation failure?

Medium
33

Order the steps to take a snapshot of a virtual machine.

Medium
34

Which THREE security hardening measures should be applied to an ESXi host? (Choose three.)

Medium

Frequently asked questions

What does the vSphere Security domain cover on the VCP-DCV exam?
Be able to configure and troubleshoot vMotion encryption, VM encryption with an external KMS, and ESXi host hardening. The single most important thing: know that enabling encryption at one layer does not automatically encrypt traffic or data at another, so verify every required component.
How many questions are in this domain?
This page lists all 34 vSphere Security questions in the VCP-DCV question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only vSphere Security questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
vmware-vcp-dcv VMWARE-VCP-DCV vsphere security Practice Questions