Courseiva
vSphere SecuritymediumMultiple ChoiceObjective-mapped

VCP-DCV vSphere Security Practice Question

During a vulnerability scan, an ESXi host is found to have the SSLv3 protocol enabled. The administrator wants to disable SSLv3 and enforce TLS 1.2 for all network services on the host. Which approach is most effective?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Set the advanced system option 'SSLv3.Enabled' to false and 'TLSv1.2.Enabled' to true.

The most effective approach is to set the advanced system option 'SSLv3.Enabled' to false and 'TLSv1.2.Enabled' to true. This directly modifies the ESXi host's SSL/TLS configuration. Option A is incorrect because vCenter Server's TLS settings do not override the host's own configuration. Option B is incorrect because the DCUI does not have a direct setting to enforce TLS 1.2; it only allows basic security settings. Option C is incorrect because disabling services does not change the protocol version used by remaining services.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Update the TLS configuration in vCenter Server and reboot the host.

    Why it's wrong here

    Updating TLS configuration in vCenter Server does not directly affect the ESXi host's own TLS settings; each host must be configured individually.

  • Change the host's security settings in the DCUI to require TLS 1.2.

    Why it's wrong here

    The DCUI does not provide a setting to require TLS 1.2; it is for basic host configuration but not SSL/TLS protocol selection.

  • Disable all unnecessary services on the host via the DCUI.

    Why it's wrong here

    Disabling unnecessary services does not change the SSL/TLS protocol version enabled; it only stops those services.

  • Set the advanced system option 'SSLv3.Enabled' to false and 'TLSv1.2.Enabled' to true.

    Why this is correct

    Setting the advanced system options 'SSLv3.Enabled' to false and 'TLSv1.2.Enabled' to true directly controls which protocols are used by the host's network services.

About these practice questions

This VCP-DCV question is part of Courseiva's 498-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.