Courseiva
vSphere SecuritymediumMultiple SelectObjective-mapped

vSphere Trust Authority: ESXi Attestation, TPM, and Key Provider Services

Which THREE security features are available in vSphere Trust Authority (vTA)?

Quick Answer

Key provider services for virtual machines being one of the correct answers reflects vSphere Trust Authority's core purpose: it exists to be a trusted, hardware-attested source that key-consuming components, like encrypted VMs, can rely on for cryptographic key material, rather than relying directly on an external, unattested key management server. vTA achieves this trust through attestation, verifying that ESXi hosts are running genuine, untampered VMware code before those hosts are allowed to interact with the trusted infrastructure at all; a host that fails attestation is not treated as trustworthy enough to receive keys or run sensitive workloads. This tight coupling, attestation establishing which hosts can be trusted, and key provisioning then flowing only to hosts that passed that check, is what distinguishes vTA's model from a standard KMS deployment, where any host configured to reach the key server can typically request keys without that extra layer of hardware and software integrity verification. Because vTA sits between the hosts and the actual key infrastructure, it functions as a policy and trust broker as much as a key service. When a question describes vSphere features centered on verifying host integrity before granting access to encryption keys or sensitive operations, expect attestation and key provisioning to appear together as complementary, not competing, capabilities of vSphere Trust Authority.

⚠ Common exam trap

A common mix-up: candidates confuse general vSphere security features (like vMotion encryption or AD integration) with vTA-specific capabilities, which are narrowly focused on attestation and key provider services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Attestation of ESXi hosts

VSphere Trust Authority (vTA) uses attestation to verify the integrity of ESXi hosts before allowing them to interact with trusted infrastructure. This attestation process confirms that the host is running genuine, untampered VMware code, which is a core security feature of vTA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Attestation of ESXi hosts

    Why this is correct

    vTA attests host integrity.

  • Integration with Active Directory for authentication

    Why it's wrong here

    vTA does not handle AD integration.

  • Trusted Platform Module (TPM) based attestation

    Why this is correct

    vTA uses TPM for attestation.

  • Encryption of vMotion traffic

    Why it's wrong here

    vMotion encryption is separate from vTA.

  • Key provider services for virtual machines

    Why this is correct

    vTA acts as a key server.

About these practice questions

This VCP-DCV question is part of Courseiva's 498-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on VCP-DCV

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An organization is using vSphere Trust Authority (vTA) to secure ESXi hosts. A newly added ESXi host fails to attest with the Trust Authority. The administrator verifies that the host is connected to the vTA cluster and the trust relationship is configured. What is the most likely cause of the attestation failure?

medium
  • A.The Trust Authority's network is isolated from the ESXi host's management network.
  • B.The ESXi host is not in the same cluster as the Trust Authority.
  • C.The ESXi host does not have a virtual Trusted Platform Module (vTPM) attached.
  • D.The TPM on the ESXi host is disabled or not properly initialized.

Why D: VTA attestation requires the ESXi host's TPM to be enabled and properly initialized. Option A is incorrect because the administrator verified that the host is connected to the vTA cluster, so network isolation is unlikely. Option B is incorrect because the ESXi host does not need to be in the same cluster as the Trust Authority; trust is configured separately. Option C is incorrect because vTA relies on the host's physical TPM, not a virtual TPM (vTPM).

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.