Courseiva
vSphere Security →easyMultiple Select

VCP-DCV vSphere Security Practice Question

Which TWO actions are required to enable vSphere VM encryption? (Choose two.)

⚠ Common exam trap

The trap is selecting operational or security-hardening steps (SSH, lockdown mode, disabling vMotion) as if they were encryption prerequisites; only the key provider and the encryption policy/action are required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a Key Management Server (KMS) or native key provider

vSphere VM encryption requires a key provider to supply the encryption keys, so option A is correct: you must configure a Key Management Server (KMS) or a vSphere Native Key Provider and add it to the vCenter Server before any VM can be encrypted. Option D is also correct because, after the key provider is trusted, you must actually apply encryption by assigning a VM encryption storage policy to the virtual machine (or enabling encryption on the VM), which triggers the encryption of the VM's files and disks. Option B is not required: SSH access to ESXi hosts is not used to manage encryption keys, since key management is handled through the KMS/Native Key Provider and vCenter. Option C is not required: vMotion remains fully supported with encrypted VMs and does not need to be disabled. Option E is not required: lockdown mode is a security hardening setting for host access and has no role in enabling VM encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure a Key Management Server (KMS) or native key provider

    Why this is correct

    vSphere VM encryption requires a key provider before any disk can be encrypted; either an external Key Management Server or the native key provider supplies the keys. This satisfies the stem's prerequisite of establishing key management, without which encryption cannot be enabled.

  • ✗

    Enable SSH on each ESXi host to manage encryption keys

    Why it's wrong here

    SSH access plays no part in vSphere VM encryption; keys are managed through the Key Management Server (KMS) cluster and vCenter, with encryption performed by the ESXi hosts themselves. Enabling SSH is tempting as a general host-management or troubleshooting step, but it neither generates nor stores encryption keys.

  • ✗

    Disable vMotion on the cluster

    Why it's wrong here

    vMotion is unrelated to encryption and disabling it removes migration capability without enabling anything. Tempting because encryption involves cluster-wide key management, and it would be correct when troubleshooting migration failures, but enabling VM encryption requires a key provider and encryption mode configured on the cluster.

  • ✓

    Assign an encryption storage policy to the virtual machine or enable encryption on the VM

    Why this is correct

    Encryption is enforced per virtual machine through a VM storage policy that carries the encryption capability, or by enabling encryption directly on the VM. Without this assignment, the VM's files remain unencrypted even when a KMS is configured.

  • ✗

    Place the ESXi hosts in lockdown mode

    Why it's wrong here

    Lockdown mode restricts direct ESXi host access; it neither provides nor enables encryption. Tempting because encryption is a security hardening measure, and it would be correct when tightening host access, but VM encryption requires a KMS-backed key provider registered with vCenter and hosts.

About these practice questions

One of 281 original VCP-DCV practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official VMware exam blueprint

This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.