ESXi Host Security Hardening Best Practices
Which THREE security hardening measures should be applied to an ESXi host? (Choose three.)
Quick Answer
The answer is to disable ESXi Shell and SSH services, enable lockdown mode, and apply a host profile. These three measures directly reduce the attack surface by eliminating unnecessary remote access points, enforce strict authentication through lockdown mode, and ensure consistent security baselines across all hosts via host profiles. On the VMware Certified Professional Data Center Virtualization VCP-DCV exam, this question tests your understanding of the principle of least privilege and configuration drift prevention—common traps include confusing SNMP (a monitoring tool, not a security control) with a hardening measure, or thinking that increasing memory workload improves security. Remember that any service left running, especially SSH, is a potential entry vector for attackers. A useful memory tip is “Lock, Disable, Profile”—lockdown mode restricts direct access, disable shell and SSH services, and use a host profile to lock in those settings across your cluster.
⚠ Common exam trap
VCP-DCV often tests the confusion between performance tuning (like memory allocation) and security hardening, and may include distractors like SNMP v3 which is a management protocol, not a hardening measure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable lockdown mode
Option B is correct because enabling lockdown mode restricts direct root access to an ESXi host, forcing all administrative actions through vCenter Server or an authorized privileged account, which reduces the attack surface from unauthorized local or remote logins. Option D is correct because applying a host profile enforces a consistent, validated set of security configuration settings (such as firewall rules, services, and authentication policies) across ESXi hosts, preventing configuration drift that could introduce vulnerabilities. Option E is correct because disabling the ESXi Shell and SSH services closes unneeded remote-access channels that attackers could exploit; these services should only be enabled temporarily for troubleshooting and then disabled again. Option A is not a security hardening measure—increasing memory for management VMs is a performance/resource tuning action and does not reduce the host's attack surface. Option C, while SNMPv3 does provide authentication and encryption compared to earlier SNMP versions, is not one of the three required hardening measures here and enabling SNMP at all can expose management information, so it is not selected as a correct answer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase memory resource allocation for management VMs
Why it's wrong here
Memory allocation for management VMs is a capacity and performance tuning decision, not a security control; it neither restricts access nor reduces exposed services on the host. Hardening concerns disabling unnecessary services, locking down DCUI and SSH, and enforcing strict permissions. Extra memory would be relevant when management appliances are resource-starved.
- ✓
Enable lockdown mode
Why this is correct
Lockdown mode forces all administrative access through vCenter Server or an authorised directory, blocking direct root logins to the host. This satisfies the hardening requirement by removing the local bypass path an attacker would otherwise use after obtaining host credentials.
- ✗
Enable SNMP v3
Why it's wrong here
SNMP v3 adds authentication and encryption for monitoring traffic, but it is an observability protocol, not a hardening control for the hypervisor itself. The hardening guidance targets disabling unused services and restricting access; enabling an agent expands the attack surface. SNMP v3 would be chosen where encrypted monitoring polling is genuinely required.
- ✓
Apply a host profile for security settings
Why this is correct
A host profile captures the hardened baseline — services, firewall rules, NTP, authentication — and enforces it across every ESXi host. This satisfies the requirement for consistent, auditable configuration by detecting drift and remediating it automatically, rather than relying on manual per-host changes.
- ✓
Disable ESXi Shell and SSH services
Why this is correct
The ESXi Shell and SSH are administrative interfaces that broaden the attack surface if left running. Disabling both removes remote command-line access, so an attacker who compromises credentials cannot obtain a root shell. This directly satisfies the hardening requirement to minimise exposed management services.
Go deeper
Related to this question
About these practice questions
One of 281 original VCP-DCV practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on VCP-DCV
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security audit reveals that an ESXi host has been compromised due to an attacker gaining root access via the DCUI. The host is configured with a default DCUI password. Which security best practice should have been implemented to prevent this?
hard- ✓ A.Configure the DCUI lockdown mode to 'Normal'
- B.Disable the DCUI service
- C.Set a strong password for the root account
- D.Disable SSH access
Why A: DCUI Lockdown Mode 'Normal' disables direct root access via the Direct Console User Interface (DCUI) by requiring authentication through vCenter Single Sign-On (SSO). This prevents an attacker from using the default or weak DCUI password to gain root access, as the root account is no longer accepted for DCUI login. The mode still allows authorized vCenter administrators to access the host via the DCUI using their SSO credentials, maintaining manageability while eliminating the root password attack vector.
Variation 2. Which TWO of the following are best practices for securing ESXi hosts? (Choose two.)
medium- A.Grant the root user direct permissions on all hosts.
- B.Disable the ESXi firewall to simplify management.
- ✓ C.Enable lockdown mode on the host.
- D.Allow DCUI access from trusted management networks.
- ✓ E.Configure Active Directory integration for host authentication.
Why C: Option C is correct because enabling lockdown mode on an ESXi host restricts direct root access through the DCUI, ESXi Shell, and SSH, forcing all administrative actions through vCenter Server or an authorized privileged account, which enforces centralized authentication and auditing. Option E is correct because integrating ESXi hosts with Active Directory lets administrators authenticate with named domain accounts and assign roles via vSphere permissions, eliminating shared local root credentials and enabling accountability and centralized account lifecycle management. The unmarked options are not best practices: granting the root user direct permissions on all hosts (A) violates least privilege and removes accountability, disabling the ESXi firewall (B) exposes management and service ports to unnecessary risk, and allowing DCUI access from trusted management networks (D) is weaker than disabling or tightly restricting DCUI access, since lockdown mode is the preferred control.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official VMware exam blueprint
This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.