Courseiva

CCNA vSphere Security Questions

34 questions · vSphere Security · All types, answers revealed

1
MCQeasy

An administrator wants to ensure that no user can view or modify VMs in a particular folder except the folder owner. What is the proper method to achieve this?

A.Use the No Access permission on the folder for all other users.
B.Assign the folder owner with Administrator role on the folder.
C.Create a global role that denies access to all VMs except the folder owner.
D.On the folder, assign permissions to the folder owner with the desired role and ensure propagation is set to 'All children'.
AnswerD

Correct. Assigning the folder owner the desired role on the folder with propagation set to 'All children' ensures the owner has the necessary permissions on the folder and all VMs within it, while other users, lacking explicit permissions, cannot view or modify the VMs.

Why this answer

To restrict access so only the folder owner can view or modify VMs in a folder, you assign the owner the desired role on the folder and set propagation to 'All children'. This ensures the permission is inherited by all VMs and sub-objects within the folder, giving the owner the necessary rights while others without explicit permissions are denied by default.

Exam trap

VCP-DCV often tests the misconception that vSphere supports explicit deny permissions — candidates who pick 'No Access' or a 'deny role' misunderstand that vSphere permissions are purely additive and inherited, with no deny mechanism.

How to eliminate wrong answers

Option A is wrong because vSphere permissions are additive and there is no explicit 'deny' — assigning No Access to all other users is impractical and does not scale, and it does not grant the owner access. Option B is wrong because assigning the Administrator role grants full administrative rights, which is excessive and does not restrict others; the requirement is about scoping access to the owner, not elevating them to admin. Option C is wrong because vSphere does not support global deny roles — roles are collections of privileges, and permissions are granted, not denied, so a 'deny' role cannot be created.

2
Multi-Selecthard

Which TWO statements about vCenter Single Sign-On (SSO) are true? (Choose two.)

Select 2 answers
A.It supports multiple identity sources such as Active Directory and LDAP
B.It uses Kerberos to authenticate users to vCenter Server
C.It stores user passwords in plaintext for faster authentication
D.It requires a Windows Active Directory domain to function
E.It uses SAML 2.0 tokens for authentication between vCenter services
AnswersA, E

vCenter SSO federates authentication by connecting to external identity sources, including Active Directory over LDAP or Integrated Windows Authentication, and native LDAP directories. This satisfies the stem's requirement for a true SSO statement, since SSO's core function is brokering credentials across vSphere components via configured identity sources rather than storing accounts locally.

Why this answer

Option A is correct because vCenter Single Sign-On supports multiple identity sources, including Active Directory (integrated Windows authentication), LDAP, and local SSO identity sources, allowing authentication against different user directories. Option E is correct because SSO issues SAML 2.0 tokens that are used to authenticate and authorize users across vCenter services and other vSphere components, enabling single sign-on without re-entering credentials. Option B is not correct because SSO does not rely on Kerberos as its authentication mechanism; it uses SAML tokens and can use various identity sources, though Kerberos may be involved in some Active Directory scenarios, it is not the defining authentication method.

Option C is not correct because SSO does not store user passwords in plaintext; credentials are handled securely and passwords are not stored in plaintext for authentication. Option D is not correct because SSO does not require a Windows Active Directory domain; it can function with local SSO users or other supported identity sources such as LDAP.

Exam trap

VCP-DCV often tests whether candidates know SSO is identity-source-agnostic (not AD-only) and that SAML 2.0 — not Kerberos — is the token protocol between vCenter services, so candidates who overgeneralize Kerberos pick the wrong option.

3
MCQmedium

An administrator is configuring role-based access control in a vSphere 8 environment with a single vCenter Server. A user must be able to create and delete virtual machines in a specific cluster, but must not be able to modify the cluster's HA or DRS settings. Permissions should be assigned at the cluster level and must not propagate to other clusters. Which approach should the administrator take?

A.Assign the built-in Administrator role to the user on the cluster so that VM creation and deletion are permitted, and rely on the cluster boundary to prevent changes to other clusters.
B.Create a custom role that includes the Virtual machine > Inventory > Create and Remove permissions plus the Host > Configuration > HA and DRS permissions, and assign it to the user on the cluster.
C.Create a custom role with the Virtual machine > Inventory > Create and Remove permissions, and assign it to the user on the vCenter Server root folder with propagation enabled.
D.Create a custom role with only the Virtual machine > Inventory > Create and Remove permissions, and assign it to the user on the cluster without selecting the propagate option.
AnswerD

A custom role containing only the Virtual machine > Inventory > Create and Remove permissions allows the user to create and delete VMs without granting host configuration privileges. Assigning the role at the cluster level without propagation scopes the permission to that cluster and prevents it from being inherited by other clusters or by objects within them, which matches the requirement precisely. This follows least privilege while meeting the operational need.

Why this answer

Least privilege requires a custom role with only the Virtual machine > Inventory > Create and Remove privileges, because those are the operations the user needs. Assigning the role at the cluster level without propagation confines the permission to that cluster, so other clusters are unaffected. Including HA and DRS privileges or using the built-in Administrator role would grant excessive rights, and assigning at the root folder with propagation would spread the permission too broadly.

Exam trap

The trap here is assuming that assigning a role at the cluster level automatically prevents changes to cluster configuration, when the role's privileges, not the assignment scope, determine what actions are allowed.

4
MCQhard

A financial institution operates a vSphere 7.0 environment with three vCenter Servers in linked mode, each managing separate clusters. The company uses vSAN encryption with an external KMS appliance from a third-party vendor. The KMS appliance has a certificate that expires every two years. The storage administrator recently renewed the KMS certificate as per the vendor's instructions. After the renewal, the vCenter Server's 'Key Management Servers' view shows the KMS status as 'Unhealthy'. The administrator attempts to decrypt a test virtual machine, but the operation fails with an error: 'No key providers are available'. The KMS appliance is reachable from the vCenter Server, and the new certificate is installed on the KMS. The administrator has confirmed that the KMS IP address and port are correctly configured in vCenter. What is the most likely cause of the failure?

A.The vSAN encryption keys were lost during the certificate renewal
B.The KMS cluster in vCenter needs to be recreated
C.The new KMS certificate has not been imported into the vCenter Server trust store
D.The vCenter Server services need to be restarted
AnswerC

vCenter validates the KMS server's certificate against its trust store. Renewing the certificate creates a new certificate chain, so the old trusted entry no longer matches, leaving the KMS Unhealthy and no key providers available. Importing the renewed certificate restores trust.

Why this answer

The most likely cause is that the new KMS certificate was not imported into the vCenter Server trust store. Even though the KMS appliance is reachable and the new certificate is installed on the KMS, vCenter Server must trust the KMS certificate to establish a secure connection. Without the certificate in the trust store, vCenter considers the KMS unhealthy, leading to the 'No key providers are available' error.

The vSAN encryption keys are not lost during certificate renewal—they remain stored on the KMS. Recreating the KMS cluster is unnecessary because the configuration is still valid, and restarting vCenter services would not resolve the trust issue.

5
MCQhard

A large financial institution runs a vSphere 7.0 environment with 100 ESXi hosts and 2,000 VMs. The security team has identified that several VMs are vulnerable to a critical side-channel attack that requires disabling hyperthreading on the ESXi hosts. The administrator needs to implement a solution that minimizes performance impact while ensuring compliance. The environment uses DRS clusters with varying workloads: some VMs are CPU-intensive (financial modeling) and others are memory-bound (database servers). The administrator cannot afford to take hosts offline for maintenance during business hours. The change must be implemented within 48 hours. Which course of action should the administrator take?

A.Use a vSphere DRS rule to disable hyperthreading for all VMs in the cluster, avoiding the need to modify host BIOS.
B.Place each host in maintenance mode individually, disable hyperthreading in the host BIOS, reboot the host, and then move to the next host. Rebalance VMs after all hosts are updated.
C.Delay the change and schedule a maintenance window for the next month when business impact is lower.
D.Disable hyperthreading on all hosts simultaneously using a vSphere Cluster feature, then reboot all hosts at once during off-peak hours.
AnswerB

Hyperthreading is a BIOS setting, so disabling it requires a host reboot. Sequentially placing each host in maintenance mode lets DRS evacuate VMs to remaining hosts, avoiding downtime, then rebalancing after all 100 hosts are updated within the 48-hour window.

Why this answer

Disabling hyperthreading to mitigate side-channel attacks (e.g., L1TF or MDS) requires a host BIOS change, which necessitates a reboot. The only supported method in vSphere 7.0 is to place each host into maintenance mode, change the BIOS setting, reboot, and then repeat for all hosts. This approach minimizes performance impact by allowing VMs to be migrated via vMotion and avoids simultaneous downtime, meeting the 48-hour requirement without taking all hosts offline during business hours.

Exam trap

The trap here is that candidates mistakenly believe hyperthreading can be disabled via a vSphere software setting (like a DRS rule or cluster feature) without a host reboot, when in reality it requires a physical BIOS change and reboot per host.

How to eliminate wrong answers

Option A is wrong because vSphere DRS rules cannot disable hyperthreading at the VM or host level; hyperthreading is a hardware feature controlled only via BIOS or host-level CPU configuration, and DRS rules only influence VM placement and resource allocation. Option C is wrong because delaying the change for a month violates the explicit requirement to implement the fix within 48 hours, and the security vulnerability demands immediate remediation. Option D is wrong because there is no vSphere Cluster feature to disable hyperthreading across all hosts simultaneously; disabling hyperthreading requires a BIOS change and reboot per host, and rebooting all hosts at once would cause total cluster downtime, violating the constraint of no business-hour outages.

6
Multi-Selectmedium

An administrator is configuring role-based access control in vCenter Server 7.0. A new security policy requires that users can only view the inventory and cannot perform any changes. The administrator creates a custom role with only read-only privileges. Which two actions must the administrator take to ensure the role is effective for a group of users? (Choose two.)

Select 2 answers
A.Grant the users the 'Administrator' role at the root folder to ensure they can see all objects.
B.Ensure the users are members of an Active Directory group that is added to vCenter Single Sign-On as a group.
C.Set the users' login to use a read-only mode in the vSphere Client.
D.Assign the role to the users on the root folder with 'Propagate to children' enabled.
E.Assign the role to the users on each individual VM and host object.
AnswersB, D

For the role to apply to a group of users, the group must be recognized by vCenter Single Sign-On. Adding the Active Directory group as a vSphere SSO group allows permissions to be assigned to that group. Then, assigning the role to the group at the root folder with propagation grants all members the desired access. Without SSO group configuration, the group cannot be used in permission assignments.

Why this answer

To grant a group of users read-only access to the entire vCenter inventory, the administrator must first ensure the group is known to vCenter Single Sign-On, typically by adding the Active Directory group as an SSO group. Then, the read-only role should be assigned to that group at the root folder with 'Propagate to children' enabled. This ensures all group members inherit view-only permissions on all current and future objects.

Individual assignments or overly permissive roles do not meet the requirement efficiently or securely.

Exam trap

The trap here is forgetting that vCenter permissions require the group to be recognized by SSO before it can be assigned a role, and assuming that assigning at the root without propagation is sufficient.

7
MCQeasy

A vSphere administrator wants to restrict direct console access to an ESXi host to authorized administrators only, without interrupting running virtual machines. Which feature should the administrator enable?

A.Lockdown mode
B.Enable DRS
C.Configure a host profile
D.Disable SSH service
AnswerA

Lockdown mode restricts the ESXi DCUI and SSH to users in the Exception Users list, enforced through host permissions. It applies immediately without rebooting or evacuating VMs, satisfying the constraint of restricting console access while leaving running virtual machines untouched.

Why this answer

Lockdown mode restricts direct console access to an ESXi host to only users with administrator privileges, while allowing running VMs to continue unaffected. It enforces that all management access must go through vCenter Server, enhancing security without disrupting workloads.

Exam trap

VCP-DCV often tests the difference between lockdown mode and other access controls like SSH disabling, and candidates may think disabling SSH is sufficient for console restriction.

How to eliminate wrong answers

Option B is wrong because DRS (Distributed Resource Scheduler) is for load balancing and resource allocation across hosts, not for restricting console access. Option C is wrong because a host profile is a configuration template for host settings, not an access control mechanism. Option D is wrong because disabling SSH only blocks SSH access, but does not restrict direct console access via the DCUI (Direct Console User Interface) or other methods; lockdown mode is specifically designed for that purpose.

8
MCQmedium

A retail company's vSphere 8 environment uses vCenter Single Sign-On (SSO) with an external identity provider via SAML. The security team wants to enforce multi-factor authentication (MFA) for all administrators logging into vCenter Server. Which SSO configuration should the administrator implement?

A.Configure vCenter SSO to use Integrated Windows Authentication (IWA) and enable Kerberos pre-authentication.
B.Configure the identity provider to require MFA and set the vCenter SSO to use the external identity provider as the authentication source.
C.Enable Smart Card Authentication in vCenter SSO and require administrators to use smart cards.
D.Set the vCenter SSO password policy to require complex passwords and frequent changes.
AnswerB

When vCenter SSO is configured to use an external identity provider via SAML, authentication is delegated to that provider. If the identity provider enforces MFA, administrators must complete MFA to log in. This approach centralizes MFA enforcement and meets the requirement without additional vCenter configuration.

Why this answer

To enforce MFA for vCenter administrators, the most effective method is to delegate authentication to an external identity provider that already enforces MFA. When vCenter SSO is configured to use that provider via SAML, MFA becomes mandatory for all logins. Other options either do not provide MFA or are not aligned with the existing SAML integration.

Exam trap

The trap here is thinking that enabling password policies or smart cards alone fulfills MFA, when MFA specifically requires multiple authentication factors, often best enforced by the external identity provider.

9
Multi-Selectmedium

Which TWO of the following are valid methods to restrict access to the ESXi host's Direct Console User Interface (DCUI) to authorized administrators only?

Select 2 answers
A.Disable SSH access on the host to prevent remote DCUI access.
B.Enable lockdown mode and add only authorized administrators to the Exception Users list.
C.Remove the root user from the DCUI local users list.
D.Set the advanced option 'DCUI.Access' to a list of authorized users.
E.Configure Active Directory integration and use group policy to disable DCUI.
AnswersB, D

Lockdown mode blocks all users except those on the Exception Users list from accessing the DCUI, satisfying the requirement to permit only authorised administrators. Adding administrators to that list grants them the explicit exemption needed, while all other accounts are denied by default.

Why this answer

Option B is correct because enabling lockdown mode restricts direct host access (including the DCUI) so that only users on the Exception Users list—authorized administrators—can log in to the DCUI and other local management interfaces. Option D is correct because the advanced setting 'DCUI.Access' explicitly defines which local users are permitted to access the Direct Console User Interface, so setting it to a list of authorized users restricts DCUI access to exactly those accounts. Option A is not correct because SSH is a separate remote shell service and disabling it has no effect on DCUI access, which is a local console interface.

Option C is not correct because the root user cannot simply be removed from the DCUI local users list in the manner described; DCUI access is controlled via lockdown mode and DCUI.Access, not by deleting root from a list. Option E is not correct because Active Directory integration and group policy do not provide a supported mechanism to disable the DCUI on an ESXi host.

Exam trap

VCP-DCV often tests the confusion between SSH/ESXi Shell access and DCUI access — candidates assume disabling SSH locks the console, but the DCUI is a separate interface controlled by lockdown mode and DCUI.Access.

10
MCQmedium

A company requires all vMotion traffic to be encrypted. The vSphere administrator enables vMotion encryption at the cluster level. What else must be configured to ensure vMotion operations are encrypted?

A.Allocate at least 4 GB of additional memory for cryptographic operations.
B.Upgrade all ESXi hosts to version 7.0 or later.
C.Enable VM Encryption also.
D.Ensure all VMs have virtual hardware version 11 or later.
AnswerD

Virtual hardware version 11 or later is required to support encrypted vMotion.

Why this answer

For vMotion encryption to work, the virtual machine must have hardware version 11 or later. This requirement is documented for vSphere 6.5 and later, which support vMotion encryption. Option A is incorrect because there is no requirement to allocate additional memory for vMotion encryption; cryptographic operations for vMotion are handled by the host's CPU.

Option B is incorrect because vMotion encryption is supported on ESXi 6.5 and later, not specifically version 7.0 or later. Option C is incorrect because VM Encryption is a separate feature that encrypts the VM's files at rest, not vMotion traffic. Therefore, ensuring VMs have virtual hardware version 11 or later is necessary for encrypted vMotion.

11
MCQeasy

A company wants to integrate vCenter Server with an external identity source to allow users to authenticate using their corporate credentials. The administrator must ensure that authentication traffic is encrypted. Which solution should the administrator implement?

A.Local OS authentication on vCenter Server
B.Active Directory over NTLM
C.Active Directory over LDAPS
D.Active Directory over LDAP
AnswerC

LDAPS wraps LDAP authentication traffic in TLS, encrypting credentials and queries between vCenter Server and the directory. Binding to Active Directory over plain LDAP would leave authentication traffic unencrypted, so LDAPS satisfies the stated encryption requirement for the external identity source.

Why this answer

Active Directory over LDAPS uses LDAP over SSL/TLS, which encrypts authentication traffic between vCenter Server and the AD domain controller. This meets the requirement for encrypted authentication. LDAPS typically uses port 636 and requires proper certificates on the domain controllers.

This is the correct solution for integrating vCenter with an external identity source while ensuring encryption.

Exam trap

VCP-DCV often tests the difference between LDAP and LDAPS; candidates may pick LDAP thinking it's sufficient, but the exam requires encryption, so LDAPS is the correct choice.

How to eliminate wrong answers

Option A is wrong because local OS authentication uses local accounts on the vCenter Server appliance, not corporate credentials, and does not integrate with an external identity source. Option B is wrong because Active Directory over NTLM does not encrypt authentication traffic by default; NTLM can be encrypted with signing/sealing, but it is not the standard secure LDAP method and is generally less secure. Option D is wrong because Active Directory over LDAP (without SSL) sends credentials in plaintext, which does not meet the encryption requirement.

12
MCQmedium

A vSphere administrator needs to ensure that all virtual machine disks are encrypted at rest. The environment uses a KMS cluster with multiple KMIP-compliant servers. The administrator has already configured a storage policy with encryption enabled. However, newly created VMs on a particular datastore still show unencrypted disks. What is the most likely cause?

A.The datastore is a vSAN datastore, which does not support VM-level encryption.
B.The KMS cluster must have at least two KMS servers to function correctly.
C.The datastore is formatted with VMFS6, which does not support encryption.
D.The storage policy with encryption is not assigned to the VMs or their home namespace.
AnswerD

Encryption is enforced through the VM storage policy, not the datastore itself. If that policy is not assigned to the VMs or their home namespace, their disks remain unencrypted despite the KMS cluster and policy existing.

Why this answer

Even when a storage policy with encryption is configured, it must be explicitly assigned to the VMs or their home namespace (the VM's configuration and swap files). If the policy is not assigned, the VM will be created using the default datastore policy, which typically does not include encryption, resulting in unencrypted disks. The administrator must ensure the encryption-enabled policy is applied to the VM during creation or via a storage policy-based management (SPBM) assignment.

Exam trap

The trap here is that candidates assume configuring a storage policy with encryption is sufficient, but they forget that the policy must be explicitly assigned to the VM or its home namespace for encryption to take effect.

How to eliminate wrong answers

Option A is wrong because vSAN datastores fully support VM-level encryption (encryption at rest) when a KMS is configured and the appropriate storage policy is applied; vSAN does not preclude encryption. Option B is wrong because a KMS cluster can function with a single KMS server, though multiple servers are recommended for high availability; the question states a KMS cluster is already configured, so this is not the cause of unencrypted disks. Option C is wrong because VMFS6 fully supports VM-level encryption; encryption is a feature of the vSphere platform and the storage policy, not the VMFS version.

13
MCQeasy

A vSphere administrator wants to prevent users in a custom role from powering off virtual machines that have Fault Tolerance enabled. Which privilege must be removed from the custom role?

A.VirtualMachine.State.Suspend
B.VirtualMachine.Interrupt.PowerOff
C.VirtualMachine.Interrupt.Reset
D.VirtualMachine.Interrupt.PowerOn
AnswerB

Removing VirtualMachine.Interrupt.PowerOff directly blocks the power-off action on any VM the role applies to, including Fault Tolerance–enabled ones. Fault Tolerance itself imposes no separate privilege gate, so the standard power-off privilege is the sole control satisfying the stem's constraint.

Why this answer

The privilege VirtualMachine.Interrupt.PowerOff directly controls the ability to power off a virtual machine, including those with Fault Tolerance enabled. Removing this privilege from a custom role prevents users from performing a power-off operation on any VM, including FT-protected ones. Other privileges like Suspend, Reset, or PowerOn do not govern the power-off action, so they are irrelevant to this requirement.

Exam trap

VCP-DCV often tests the exact privilege name for a given operation, and candidates may confuse similar-sounding privileges like Suspend, Reset, or PowerOn with PowerOff, leading to incorrect answers.

How to eliminate wrong answers

Option A is wrong because VirtualMachine.State.Suspend controls suspending a VM, not powering it off; suspending an FT VM is a different operation and does not satisfy the requirement. Option C is wrong because VirtualMachine.Interrupt.Reset controls resetting a VM, which is a restart operation, not a power-off. Option D is wrong because VirtualMachine.Interrupt.PowerOn controls powering on a VM, which is the opposite of powering off and does not prevent the undesired action.

14
MCQmedium

A healthcare provider's vSphere 8 environment must encrypt all VM files at rest. The security team requires that encryption keys be stored on a hardware security module (HSM) and that the vCenter Server never hold the keys in its database. An administrator configures a Key Provider and enables VM encryption. Which component is responsible for storing the encryption keys?

A.The vCenter Server's VMware Postgres database.
B.The Key Management Server (KMS) configured as a standard key provider.
C.The ESXi host's ramdisk, which persists across reboots.
D.A vSphere Trust Authority attestation service running on the ESXi host.
AnswerB

A standard key provider, such as a KMS, stores encryption keys externally on an HSM or key server, not in the vCenter Server database. When VM encryption is enabled, ESXi hosts request keys from the KMS via the vCenter Server, but the keys are never persisted in vCenter. This meets the requirement that keys reside on an HSM.

Why this answer

VM encryption requires a key provider to store keys externally. A standard key provider, typically a KMS with an HSM, holds the keys outside vCenter and ESXi. vCenter brokers key requests but does not store keys. The ESXi ramdisk is volatile, and Trust Authority handles attestation, not key storage.

Thus, the KMS is the correct component.

Exam trap

The trap here is assuming that vCenter Server stores encryption keys because it manages the encryption process, when in fact keys are held externally by the KMS.

15
MCQmedium

A security team requires that all vCenter Server administrative logins be validated against an external identity source, but they also want to retain the ability to log in with the local SSO administrator account during a directory service outage. An administrator has already added the Active Directory identity source to vCenter Single Sign-On. Which configuration should the administrator apply to meet both requirements?

A.Configure the Active Directory identity source as the default identity source and grant the AD domain admins the Administrator role on the root folder.
B.Add the Active Directory identity source, then assign the AD security group the Global Permissions Administrator role, and leave the default identity source as the local SSO domain.
C.Add the Active Directory identity source, set it as the default identity source, and keep the local SSO administrator account available for emergency access.
D.Set the identity source type to 'Active Directory over LDAP' and enable 'Use Windows session authentication'.
AnswerC

Setting the directory as the default identity source makes vCenter Single Sign-On present that domain first and validate administrative logins against it, satisfying the external-validation requirement. The local SSO administrator account is not deleted by adding an identity source, so it remains usable for break-glass access if the directory becomes unreachable, which satisfies the second requirement without weakening normal operations.

Why this answer

The requirement has two parts: external validation for administrative logins and a usable local fallback. Setting the added Active Directory source as the default identity source directs SSO to validate against the directory by default, while the built-in SSO administrator account persists and can still authenticate locally. Disabling or removing the local account would break the fallback requirement, and leaving the local domain as default would not enforce external validation.

Exam trap

The trap here is assuming that adding an Active Directory identity source to vCenter Single Sign-On automatically disables or removes the local SSO administrator account.

16
MCQhard

A company runs a critical e-commerce platform on a vSphere 7 cluster with ESXi hosts connected to a vSAN datastore. The environment uses vSphere Trust Authority (vTA) and VM encryption with an external KMS. Recently, after a successful vTA attestation, one of the VMs (WebServer-01) failed to power on with the error: 'Unable to decrypt the encrypted virtual machine upon re-registration. Reason: The KMS server is unreachable.' The administrator verifies that other encrypted VMs on the same host power on successfully. The KMS cluster consists of two servers: KMS-01 and KMS-02, both accessible from the management network. The administrator checks the VM's configuration and finds that it uses a custom storage policy with encryption. What is the most likely cause of this specific VM's failure?

A.The vCenter Server's KMS cluster configuration has been deleted, affecting all VMs but not this one.
B.The storage policy used by the VM has been modified and no longer includes encryption.
C.The vTA attestation process failed for the VM's host, but the error message is misleading.
D.The VM's encryption key was retrieved from a different KMS server that is now unavailable, and the key ID in the VM's metadata points to that KMS server.
AnswerD

Correct. The VM's encryption key may have been issued by a specific KMS server (e.g., KMS-01) that is now unreachable, while the KMS cluster overall is accessible. Other VMs may have keys from a different, reachable server (e.g., KMS-02), explaining why they power on successfully.

Why this answer

The error 'Unable to decrypt the encrypted virtual machine upon re-registration. Reason: The KMS server is unreachable' indicates that the ESXi host cannot contact the KMS server to retrieve the VM's encryption key. Since other encrypted VMs on the same host power on successfully, the host can reach the KMS cluster, but this specific VM's encryption key may have been issued by a different KMS server (e.g., an older or alternative KMS) that is now unavailable.

The key ID stored in the VM's metadata points to that unreachable server, causing the failure. Option A is incorrect because if the vCenter KMS cluster configuration were deleted, all VMs would be affected. Option B is incorrect because modifying the storage policy does not change the existing encryption key; the VM remains encrypted with its original key.

Option C is incorrect because vTA attestation is separate from KMS key retrieval; the error message is specific to KMS unavailability.

17
Multi-Selecteasy

Which TWO actions are required to enable vSphere VM encryption? (Choose two.)

Select 2 answers
A.Configure a Key Management Server (KMS) or native key provider
B.Enable SSH on each ESXi host to manage encryption keys
C.Disable vMotion on the cluster
D.Assign an encryption storage policy to the virtual machine or enable encryption on the VM
E.Place the ESXi hosts in lockdown mode
AnswersA, D

vSphere VM encryption requires a key provider before any disk can be encrypted; either an external Key Management Server or the native key provider supplies the keys. This satisfies the stem's prerequisite of establishing key management, without which encryption cannot be enabled.

Why this answer

vSphere VM encryption requires a key provider to supply the encryption keys, so option A is correct: you must configure a Key Management Server (KMS) or a vSphere Native Key Provider and add it to the vCenter Server before any VM can be encrypted. Option D is also correct because, after the key provider is trusted, you must actually apply encryption by assigning a VM encryption storage policy to the virtual machine (or enabling encryption on the VM), which triggers the encryption of the VM's files and disks. Option B is not required: SSH access to ESXi hosts is not used to manage encryption keys, since key management is handled through the KMS/Native Key Provider and vCenter.

Option C is not required: vMotion remains fully supported with encrypted VMs and does not need to be disabled. Option E is not required: lockdown mode is a security hardening setting for host access and has no role in enabling VM encryption.

Exam trap

The trap is selecting operational or security-hardening steps (SSH, lockdown mode, disabling vMotion) as if they were encryption prerequisites; only the key provider and the encryption policy/action are required.

18
MCQhard

A vSphere environment uses Active Directory for authentication. The administrator notices that users from a specific AD group cannot log in to the vCenter Server, although other AD users can. The group is added to vCenter Server with the correct permissions. What is the most likely cause?

A.The users are not members of the vCenter Single Sign-On domain
B.The user accounts have expired passwords
C.The group is nested within another group
D.The domain of the group is not configured as an identity source in vCenter Single Sign-On
AnswerD

vCenter Single Sign-On only authenticates principals from identity sources it has been configured with. If that AD domain was never added as an identity source, its groups resolve to nothing, so members fail to log in despite correct vCenter permissions.

Why this answer

The most likely cause is that the domain of the group is not configured as an identity source in vCenter Single Sign-On. Even if the group is added with correct permissions in vCenter Server, vCenter SSO must be able to authenticate users against the domain. Without the domain listed as an identity source, vCenter cannot validate the credentials of users from that group, causing authentication failures for all users in that domain.

Exam trap

The trap here is that candidates often assume that adding a group to vCenter permissions is sufficient for authentication, overlooking the prerequisite that the group's domain must first be registered as an identity source in vCenter Single Sign-On.

How to eliminate wrong answers

Option A is wrong because vCenter Single Sign-On domains are not the same as Active Directory domains; users are not members of the SSO domain unless they are explicitly created there, and the question states the users are from an AD group, meaning they are AD users, not SSO domain users. Option B is wrong because expired passwords would affect individual users, not an entire group, and the symptom is that all users from the specific group cannot log in, which points to a domain-level issue rather than individual password expiration. Option C is wrong because nested groups are fully supported in Active Directory and vCenter Server; if the group is nested within another group, the permissions would still apply as long as the parent group has the correct permissions, and this would not cause a complete authentication failure for all users in the group.

19
MCQmedium

An administrator is adding an ESXi host to vCenter Server and is prompted to verify the host's certificate thumbprint. The administrator compares it to the output above and it matches. However, the add operation fails with a certificate verification error. What else could be the issue?

A.The vCenter Server's certificate is invalid
B.The certificate has expired
C.The certificate is not signed by a trusted Certificate Authority
D.The certificate common name does not match the hostname
AnswerD

Thumbprint matching only proves the certificate's authenticity, not its identity. vCenter also validates that the certificate's common name or subject alternative name matches the hostname or IP used to add the host, so a mismatch there still triggers verification failure despite the correct thumbprint.

Why this answer

When adding an ESXi host to vCenter Server, the thumbprint verification ensures the host's certificate fingerprint matches what is expected, but it does not validate the certificate's subject attributes. If the certificate's Common Name (CN) does not match the ESXi host's FQDN or IP address used during the add operation, vCenter Server will reject the connection with a certificate verification error, even if the thumbprint is correct. This is because vCenter Server performs hostname verification as part of TLS/SSL certificate validation to prevent man-in-the-middle attacks.

Exam trap

The trap here is that candidates assume thumbprint verification alone guarantees certificate validity, overlooking that vCenter Server also performs hostname matching as part of TLS certificate validation.

How to eliminate wrong answers

Option A is wrong because the vCenter Server's certificate is not directly involved in the host certificate verification during the add operation; the error is about the ESXi host's certificate. Option B is wrong because an expired certificate would typically cause a different error (e.g., 'certificate has expired') and would not pass thumbprint verification if the thumbprint was generated from the current certificate. Option C is wrong because vCenter Server does not require the ESXi host's certificate to be signed by a trusted CA for thumbprint verification; it only checks the thumbprint match, and the error here is specifically about hostname mismatch, not trust chain issues.

20
MCQmedium

A security administrator notices that a virtual machine (VM) running a legacy application is experiencing network connectivity issues after enabling Network I/O Control (NIOC) on the distributed switch. The VM is in a high-priority traffic class for management traffic. What is the most likely cause of the issue?

A.NIOC is blocking the VM's MAC address due to a security policy.
B.The VM is assigned to the management traffic class, but its traffic should be in a different class, causing bandwidth throttling.
C.The VM is using jumbo frames, which are not supported with NIOC.
D.The virtual switch has promiscuous mode enabled, which conflicts with NIOC.
AnswerB

Misclassifying the legacy VM's traffic as management places it under Network I/O Control's management share allocation, which throttles bandwidth when the physical uplinks are saturated. NIOC enforces per-traffic-class shares, so traffic belonging in a virtual machine class instead competes against management reservations, producing the connectivity issues described.

Why this answer

Network I/O Control (NIOC) on a vSphere Distributed Switch enforces bandwidth allocation based on traffic classes such as management, vMotion, iSCSI, and VM traffic. If a VM's traffic is incorrectly classified into the management traffic class, it is subject to that class's share, reservation, and limit, which can throttle the VM's bandwidth and cause connectivity issues. The most likely cause is misclassification of the VM's traffic into the wrong NIOC traffic class.

Exam trap

The trap is assuming NIOC blocks traffic or conflicts with MTU/promiscuous settings — the real issue is traffic-class misclassification causing bandwidth throttling.

How to eliminate wrong answers

Option A is wrong because NIOC does not block MAC addresses; MAC-based security is handled by port-level security policies (allow/promiscuous/MAC changes), not NIOC. Option C is wrong because NIOC is independent of MTU settings; jumbo frames are supported with NIOC as long as the MTU is configured consistently on the vSwitch, VMkernel, and physical uplinks. Option D is wrong because promiscuous mode is a security policy on port groups and does not conflict with NIOC bandwidth allocation.

21
MCQmedium

An administrator notices that HTTP connections to the ESXi host are timing out frequently. Based on the exhibit, which configuration change would most likely resolve the issue?

A.Increase maxKeepAliveTimeout to a higher value, such as 180
B.Restart the rhttpproxy service
C.Set useProxy to true and specify a proxy server
D.Set maxKeepAliveTimeout to 0 to disable keepalive
AnswerA

Raising maxKeepAliveTimeout extends how long ESXi holds idle HTTP connections open before closing them, directly addressing the frequent timeouts caused by premature connection teardown under the exhibit's load. The constraint is persistent client sessions needing longer idle windows, which the default timeout cuts short.

Why this answer

Increasing maxKeepAliveTimeout to a higher value, such as 180, would most likely resolve the issue of HTTP connections timing out frequently. The maxKeepAliveTimeout setting controls how long the ESXi host's reverse proxy (rhttpproxy) keeps an HTTP connection open for keep-alive requests. If it is too low, connections may time out prematurely, causing frequent timeouts.

Increasing it allows longer-lived connections.

Exam trap

The trap is thinking that restarting the service or disabling keep-alive solves the problem, when the actual fix is to adjust the timeout value. Candidates may also confuse this with proxy settings, which are unrelated to inbound connection timeouts.

How to eliminate wrong answers

Option B is wrong because restarting the rhttpproxy service might temporarily alleviate the issue but does not address the root cause of frequent timeouts due to a low timeout value. Option C is wrong because setting useProxy to true and specifying a proxy server is for environments where ESXi must use a proxy to reach external resources; it does not affect inbound HTTP connection timeouts. Option D is wrong because setting maxKeepAliveTimeout to 0 disables keep-alive, which would cause connections to close after each request, likely worsening the timeout issue.

22
MCQhard

A company uses an external Platform Services Controller (PSC) in a vSphere 6.7 environment. They plan to upgrade to vSphere 7.0. Which security-related consideration is most important?

A.The external PSC will automatically convert to an embedded PSC during upgrade.
B.The external PSC is deprecated; it must be converged into the vCenter Server.
C.The SSL certificates for the PSC must be reissued from a new CA.
D.The STS certificates need to be replaced with custom ones immediately after upgrade.
AnswerB

External Platform Services Controller deployments are deprecated in vSphere 7.0, so the PSC services must be converged into the vCenter Server during upgrade. This convergence is the critical security and supportability consideration for the migration.

Why this answer

In vSphere 7.0, external Platform Services Controllers (PSC) are deprecated and must be converged into the vCenter Server during upgrade. This convergence simplifies management and improves security by reducing the attack surface. The upgrade process requires a topology change to embedded PSC.

Exam trap

VCP-DCV often tests the deprecation of external PSC and the requirement to converge, but candidates may assume automatic conversion or focus on certificate issues instead.

How to eliminate wrong answers

Option A is wrong because the external PSC does not automatically convert; a manual convergence process is required before or during upgrade. Option C is wrong because while certificates are important, reissuing from a new CA is not a mandatory security consideration for the upgrade; existing certificates can often be reused. Option D is wrong because STS certificates do not need immediate replacement after upgrade; they are managed automatically and only need replacement if they expire or are compromised.

23
MCQeasy

A security audit requires that all ESXi hosts in a vSphere 7.0 environment use encrypted connections for remote logging. An administrator configures the syslog service on each host to send logs to a central server. Which setting should be enabled to ensure the logs are transmitted over TLS?

A.Set the syslog.global.logHost parameter to tcp://logserver.example.com:1514 and enable the ESXi firewall rule for syslog.
B.Set the syslog.global.logHost parameter to ssl://logserver.example.com:1514.
C.Set the syslog.global.logHost parameter to ssl://logserver.example.com:514.
D.Set the syslog.global.logHost parameter to udp://logserver.example.com:514 and enable log signing.
AnswerB

The ssl:// prefix in syslog.global.logHost instructs ESXi to use TLS for remote logging. Port 1514 is commonly used for secure syslog. This configuration ensures logs are encrypted in transit. The administrator must also ensure the remote server supports TLS on that port. This meets the requirement for encrypted connections. No additional firewall rule is needed if the default rules allow outbound syslog.

Why this answer

To encrypt remote syslog traffic from ESXi, configure the syslog.global.logHost parameter with the ssl:// prefix and the correct port, typically 1514. This uses TLS to protect log data in transit. Other protocols like tcp:// or udp:// do not provide encryption, and log signing does not encrypt.

The ssl:// setting directly satisfies the requirement for encrypted connections.

Exam trap

The trap here is using tcp:// or udp:// and assuming they provide encryption, when only ssl:// enables TLS for syslog.

24
MCQeasy

An administrator wants to configure the ESXi host firewall to allow connections only from a specific management subnet. How can this be achieved?

A.Enable vSphere HA and set it to control management traffic.
B.Use the ESXi firewall settings to define allowed IP addresses for the required services.
C.Configure the DCUI to restrict management access.
D.Set the firewall to enabled and allow all incoming connections.
AnswerB

Defining allowed IP addresses per service in the ESXi firewall directly enforces the management-subnet restriction, since each rule's allowedIP list filters inbound traffic at the host level. This satisfies the stem's requirement to permit connections only from that subnet, without relying on external network controls.

Why this answer

ESXi's built-in firewall allows you to restrict each service (e.g., SSH, vSphere Client, vMotion) to specific IP addresses or subnets via the 'Allowed IP addresses' list in the firewall ruleset. By editing the ruleset for the management services and specifying the management subnet, you limit connections to only those sources.

Exam trap

The trap is thinking that vSphere HA, DCUI, or a blanket firewall enablement can restrict management access by subnet; only the per-ruleset allowed IP list in the ESXi firewall does this.

How to eliminate wrong answers

Option A is wrong because vSphere HA is a clustering availability feature and has nothing to do with firewall or management traffic filtering. Option C is wrong because the DCUI is a local console interface for host configuration and does not provide IP-based access restrictions for network services. Option D is wrong because enabling the firewall and allowing all incoming connections does the opposite of restricting access to a specific subnet.

25
MCQeasy

An administrator runs the command shown in the exhibit on a vCenter Server appliance. What is the primary purpose of the Machine ID?

A.To calculate workload distribution in DRS
B.To identify an ESXi host to vCenter Server
C.To serve as a unique identifier for the vCenter Server instance in SSO
D.To uniquely identify a virtual machine for vMotion
AnswerC

The Machine ID uniquely identifies each vCenter Server instance within the Single Sign-On domain, distinguishing it from other nodes during authentication and replication. This satisfies the requirement of a unique SSO identifier for the vCenter Server instance.

Why this answer

The Machine ID serves as a unique identifier for the vCenter Server instance within VMware SSO (Single Sign-On) and is used for certificate management. It is not related to workload distribution in DRS (option A), ESXi host identification (option B), or virtual machine identification for vMotion (option D). Therefore, option C is correct.

26
MCQeasy

An administrator is troubleshooting a failed attempt to add an ESXi host to a vCenter Server domain. The error message states: 'The host's certificate has been tampered with or is invalid.' What is the most likely cause?

A.The vCenter Server's account lockout policy has been triggered.
B.The ESXi host's SSH keys have been rotated.
C.The ESXi host's certificate has expired.
D.The ESXi host's certificate thumbprint does not match the thumbprint stored in vCenter Server.
AnswerD

vCenter stores the ESXi thumbprint captured at first connection; any mismatch, such as after a host certificate regeneration or reinstall, triggers the tampered-or-invalid error. The stored thumbprint no longer matches the host's presented certificate, blocking the add.

Why this answer

The error 'The host's certificate has been tampered with or is invalid' occurs when the ESXi host presents a certificate whose thumbprint does not match the thumbprint that vCenter Server has stored for that host. This mismatch can happen if the host's certificate was replaced (e.g., due to a reinstall or manual rotation) without updating the vCenter Server's trusted store. vCenter Server verifies the host's identity by comparing the SHA-1 or SHA-256 thumbprint of the presented certificate against its stored record; a mismatch triggers this specific error.

Exam trap

The trap here is that candidates often confuse certificate expiration with thumbprint mismatch, but the error message 'tampered with or invalid' specifically points to a thumbprint mismatch rather than a date-based validity issue.

How to eliminate wrong answers

Option A is wrong because an account lockout policy would produce a different error, such as 'Login failed' or 'Access denied', not a certificate tampering message. Option B is wrong because SSH keys are used for SSH authentication, not for the SSL/TLS certificate validation that occurs during host addition to vCenter Server; rotating SSH keys does not affect certificate thumbprint matching. Option C is wrong because an expired certificate would generate an error like 'Certificate has expired' or 'Certificate is not yet valid', not a 'tampered with or invalid' message, which specifically indicates a thumbprint mismatch rather than a validity period issue.

27
MCQmedium

A company is implementing vSphere 7.0 and wants to encrypt all vMotion traffic between ESXi hosts in a cluster. The cluster is not using any other encryption features. What is the minimum requirement to enable vMotion encryption?

A.A VM Encryption Key Management Server must be configured.
B.The ESXi hosts must be joined to an Active Directory domain.
C.The ESXi hosts must have a host profile applied with encryption enabled.
D.The cluster must be configured with Enhanced vMotion Compatibility (EVC).
AnswerC

A host profile applied with encryption enabled is the minimum requirement because it ensures consistent encryption policy across the cluster, leveraging default certificate trust.

Why this answer

In vSphere 7.0, enabling vMotion encryption does not require Active Directory, a Key Management Server, Enhanced vMotion Compatibility (EVC), or host profiles. The minimum requirement is simply to configure the vMotion encryption policy on each ESXi host (set to 'Required' or 'Opportunistic'). No additional infrastructure or profiles are needed.

Exam trap

Candidates often mistakenly believe that vMotion encryption requires external configuration such as host profiles, AD, or a KMS. In reality, it uses built-in certificate trust and can be enabled directly on each host without any additional setup.

How to eliminate wrong answers

Option A is wrong because a VM Encryption Key Management Server is required for encrypting virtual machine disks (VM-level encryption), not for vMotion traffic; vMotion encryption uses Kerberos from Active Directory, not a KMS. Option C is wrong because a host profile is a management tool for applying consistent configurations across hosts, but it is not a prerequisite for enabling vMotion encryption; the encryption setting can be configured directly on each host via advanced system parameters (e.g., 'VMkernel.Boot.vmotionEncryption'). Option D is wrong because Enhanced vMotion Compatibility (EVC) ensures CPU compatibility for live migrations but has no role in encrypting vMotion traffic; EVC does not provide any encryption or authentication mechanism.

28
MCQhard

A multinational corporation runs a vSphere environment with 100 ESXi hosts managed by a single vCenter Server. The security team mandates that all virtual machine disks (VMDKs) must be encrypted at rest. The administrator enables vSphere Virtual Machine Encryption and creates a Key Management Server (KMS) cluster. After encrypting a test VM, the VM powers on successfully, but the administrator notices that the VM's configuration files (VMX, NVRAM) are not encrypted. The security policy requires that all VM files, including configuration files, be encrypted. The administrator checks the VM storage policy and sees that the policy is set to 'VM Encryption Policy' with 'Disk Encryption' enabled. What should the administrator do to ensure the entire VM is encrypted?

A.Modify the VM storage policy to include encryption of VM home files
B.Enable encryption on the datastore where the VM resides
C.Add a second KMS cluster for redundancy
D.Enable vSphere Host Encryption on each ESXi host
AnswerA

The VM storage policy's VM Encryption Policy encrypts only VMDKs by default; VM home files (VMX, NVRAM) require the separate 'Encrypt VM home files' setting. Enabling that component in the policy satisfies the mandate that configuration files be encrypted at rest.

Why this answer

The VM storage policy 'VM Encryption Policy' with only 'Disk Encryption' enabled encrypts VMDK files but not the VM configuration files (VMX, NVRAM, logs, etc.). To encrypt all VM files, the storage policy must include the 'Encrypt VM home files' option, which applies encryption to the entire VM home directory on the datastore. This ensures compliance with the security mandate for full VM encryption at rest.

Exam trap

The trap here is that candidates assume 'VM Encryption Policy' with 'Disk Encryption' covers all VM files, but VMware explicitly separates disk encryption from home file encryption in the storage policy settings.

How to eliminate wrong answers

Option B is wrong because datastore-level encryption (e.g., vSAN encryption or Storage DRS encryption) is a separate feature that encrypts the entire datastore, but it does not selectively encrypt VM home files when using VM Encryption Policy; the policy must explicitly include home file encryption. Option C is wrong because adding a second KMS cluster provides redundancy for key management but does not affect which VM files are encrypted; the encryption scope is defined by the storage policy, not the KMS topology. Option D is wrong because vSphere Host Encryption encrypts host memory and vMotion traffic, not VM files at rest on the datastore; it does not address VMDK or configuration file encryption.

29
Multi-Selecthard

A vSphere administrator needs to ensure that vCenter Server can authenticate users against an Active Directory over LDAP identity source. The environment uses vCenter Server 7.0. Which two configurations are required to successfully add the identity source? (Choose two.)

Select 2 answers
A.Upload a trusted root CA certificate for the LDAP server's SSL certificate.
B.Provide the bind user's credentials with sufficient privileges to read the directory.
C.Configure the identity source to use Integrated Windows Authentication (IWA).
D.Enable FIPS mode on vCenter Server before adding the identity source.
E.Specify the base distinguished name (DN) for user and group searches.
AnswersB, E

vCenter Server uses a bind user to connect to the LDAP directory and search for users and groups. The bind user must have read access to the directory. Without valid credentials, the identity source cannot be queried. This is a required configuration for Active Directory over LDAP. The bind user can be a dedicated service account with minimal read-only privileges.

Why this answer

To add an Active Directory over LDAP identity source in vCenter Server 7.0, you must provide the base DN for searches and a bind user with read access. These allow vCenter Server to query the directory for authentication. IWA is a different identity source type, FIPS mode is unrelated, and a trusted CA certificate is only needed if using LDAPS, which is not specified here.

Exam trap

The trap here is assuming that a CA certificate is always required for LDAP, when it is only needed for LDAPS or StartTLS, which are not specified.

30
MCQhard

An organization is implementing vSphere Trust Authority for sensitive workloads. The administrator must configure the trusted ESXi hosts to attest to vCenter Server. Which component is responsible for performing attestation?

A.The administrator's workstation
B.A separate vCenter Server instance acting as the Trust Authority
C.The Key Provider (KMS) server
D.The trusted ESXi hosts themselves
AnswerB

Correct. A separate vCenter Server instance acting as the Trust Authority performs attestation of ESXi hosts.

Why this answer

VSphere Trust Authority uses a dedicated vCenter Server instance (Trust Authority vCenter) to perform attestation of ESXi hosts. Option A is incorrect because the administrator's workstation is not part of the trust chain and does not perform attestation. Option C is incorrect because the Key Provider (KMS) server is used for encryption key management, not for host attestation.

Option D is incorrect because the trusted ESXi hosts themselves are the subjects of attestation; they do not perform attestation.

31
MCQmedium

During a security audit, it is found that the vCenter Server is using the default self-signed certificate. The administrator is tasked to replace it with a certificate from an enterprise CA. What is the first step after obtaining the CA-signed certificate?

A.Convert the certificate and private key into PEM format and place them in the appropriate directory.
B.Use the vSphere Web Client to upload the certificate.
C.Import the private key into the Windows Certificate Store.
D.Restart the VMware Certificate Service.
AnswerA

vCenter expects PEM files for certificates and keys.

Why this answer

The certificate must be in a format that vCenter can use; typically, it needs to be combined with the private key. Option B is premature before preparing the certificate. Option C is incorrect because certificate import is done via certificate management tools, not vSphere Web Client.

Option D is incorrect because the private key is included in the signed certificate generation process, not imported separately.

32
MCQmedium

An organization is using vSphere Trust Authority (vTA) to secure ESXi hosts. A newly added ESXi host fails to attest with the Trust Authority. The administrator verifies that the host is connected to the vTA cluster and the trust relationship is configured. What is the most likely cause of the attestation failure?

A.The Trust Authority's network is isolated from the ESXi host's management network.
B.The ESXi host is not in the same cluster as the Trust Authority.
C.The ESXi host does not have a virtual Trusted Platform Module (vTPM) attached.
D.The TPM on the ESXi host is disabled or not properly initialized.
AnswerD

Attestation requires a healthy, enabled TPM to produce the quoted measurements the Trust Authority verifies. If the TPM is disabled or uninitialised, the host cannot generate valid attestation evidence, so the vTA cluster rejects it even though connectivity and trust configuration are correct.

Why this answer

vSphere Trust Authority attestation depends on a functioning, properly initialized TPM 2.0 on each ESXi host. The host's TPM measures the boot process (UEFI Secure Boot, bootloader, VMkernel modules) and produces quotes that the Trust Authority verifier compares against a trusted baseline. If the TPM is disabled in BIOS/UEFI or has not been initialized (no Endorsement Key taken ownership), the host cannot produce valid attestation quotes, so attestation fails even though the trust relationship and network connectivity are fine.

Exam trap

VCP-DCV often tests the distinction between host-level TPM (physical, required for vTA attestation) and guest-level vTPM (virtual, used for VM encryption), so candidates who see 'TPM' and pick the vTPM option fall into the trap.

How to eliminate wrong answers

Option A is wrong because network isolation would prevent the host from reaching the vTA cluster at all, but the question states the host is already connected to the vTA cluster and the trust relationship is configured, so connectivity is not the issue. Option B is wrong because vSphere Trust Authority is explicitly designed to attest hosts outside the Trust Authority cluster — the Trusted Cluster and the Trust Authority cluster are separate by design, so co-location is not required. Option C is wrong because vTPM is a virtual machine feature for guest OS encryption (e.g., Windows BitLocker in a VM); ESXi hosts use a physical discrete or firmware TPM, not a vTPM, so this option confuses guest-level and host-level TPM concepts.

33
Drag & Dropmedium

Order the steps to take a snapshot of a virtual machine.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct order for taking a snapshot in VMware vSphere is to first initiate the snapshot by right-clicking the VM and selecting 'Snapshot > Take Snapshot', then in the dialog provide a name and optional description, select whether to snapshot the virtual machine's memory and whether to quiesce the file system, and finally confirm by clicking OK. This sequence ensures that all necessary parameters are set before the snapshot is created.

34
Multi-Selectmedium

Which THREE security hardening measures should be applied to an ESXi host? (Choose three.)

Select 3 answers
A.Increase memory resource allocation for management VMs
B.Enable lockdown mode
C.Enable SNMP v3
D.Apply a host profile for security settings
E.Disable ESXi Shell and SSH services
AnswersB, D, E

Lockdown mode forces all administrative access through vCenter Server or an authorised directory, blocking direct root logins to the host. This satisfies the hardening requirement by removing the local bypass path an attacker would otherwise use after obtaining host credentials.

Why this answer

Option B is correct because enabling lockdown mode restricts direct root access to an ESXi host, forcing all administrative actions through vCenter Server or an authorized privileged account, which reduces the attack surface from unauthorized local or remote logins. Option D is correct because applying a host profile enforces a consistent, validated set of security configuration settings (such as firewall rules, services, and authentication policies) across ESXi hosts, preventing configuration drift that could introduce vulnerabilities. Option E is correct because disabling the ESXi Shell and SSH services closes unneeded remote-access channels that attackers could exploit; these services should only be enabled temporarily for troubleshooting and then disabled again.

Option A is not a security hardening measure—increasing memory for management VMs is a performance/resource tuning action and does not reduce the host's attack surface. Option C, while SNMPv3 does provide authentication and encryption compared to earlier SNMP versions, is not one of the three required hardening measures here and enabling SNMP at all can expose management information, so it is not selected as a correct answer.

Exam trap

VCP-DCV often tests the confusion between performance tuning (like memory allocation) and security hardening, and may include distractors like SNMP v3 which is a management protocol, not a hardening measure.

Ready to test yourself?

Try a timed practice session using only vSphere Security questions.