An administrator wants to ensure that no user can view or modify VMs in a particular folder except the folder owner. What is the proper method to achieve this?
Correct. Assigning the folder owner the desired role on the folder with propagation set to 'All children' ensures the owner has the necessary permissions on the folder and all VMs within it, while other users, lacking explicit permissions, cannot view or modify the VMs.
Why this answer
To restrict access so only the folder owner can view or modify VMs in a folder, you assign the owner the desired role on the folder and set propagation to 'All children'. This ensures the permission is inherited by all VMs and sub-objects within the folder, giving the owner the necessary rights while others without explicit permissions are denied by default.
Exam trap
VCP-DCV often tests the misconception that vSphere supports explicit deny permissions — candidates who pick 'No Access' or a 'deny role' misunderstand that vSphere permissions are purely additive and inherited, with no deny mechanism.
How to eliminate wrong answers
Option A is wrong because vSphere permissions are additive and there is no explicit 'deny' — assigning No Access to all other users is impractical and does not scale, and it does not grant the owner access. Option B is wrong because assigning the Administrator role grants full administrative rights, which is excessive and does not restrict others; the requirement is about scoping access to the owner, not elevating them to admin. Option C is wrong because vSphere does not support global deny roles — roles are collections of privileges, and permissions are granted, not denied, so a 'deny' role cannot be created.