VCP-DCV vSphere Security Practice Question
Which TWO actions are required to enable vSphere VM encryption? (Choose two.)
⚠ Common exam trap
The trap is selecting operational or security-hardening steps (SSH, lockdown mode, disabling vMotion) as if they were encryption prerequisites; only the key provider and the encryption policy/action are required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a Key Management Server (KMS) or native key provider
vSphere VM encryption requires a key provider to supply the encryption keys, so option A is correct: you must configure a Key Management Server (KMS) or a vSphere Native Key Provider and add it to the vCenter Server before any VM can be encrypted. Option D is also correct because, after the key provider is trusted, you must actually apply encryption by assigning a VM encryption storage policy to the virtual machine (or enabling encryption on the VM), which triggers the encryption of the VM's files and disks. Option B is not required: SSH access to ESXi hosts is not used to manage encryption keys, since key management is handled through the KMS/Native Key Provider and vCenter. Option C is not required: vMotion remains fully supported with encrypted VMs and does not need to be disabled. Option E is not required: lockdown mode is a security hardening setting for host access and has no role in enabling VM encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure a Key Management Server (KMS) or native key provider
Why this is correct
vSphere VM encryption requires a key provider before any disk can be encrypted; either an external Key Management Server or the native key provider supplies the keys. This satisfies the stem's prerequisite of establishing key management, without which encryption cannot be enabled.
- ✗
Enable SSH on each ESXi host to manage encryption keys
Why it's wrong here
SSH access plays no part in vSphere VM encryption; keys are managed through the Key Management Server (KMS) cluster and vCenter, with encryption performed by the ESXi hosts themselves. Enabling SSH is tempting as a general host-management or troubleshooting step, but it neither generates nor stores encryption keys.
- ✗
Disable vMotion on the cluster
Why it's wrong here
vMotion is unrelated to encryption and disabling it removes migration capability without enabling anything. Tempting because encryption involves cluster-wide key management, and it would be correct when troubleshooting migration failures, but enabling VM encryption requires a key provider and encryption mode configured on the cluster.
- ✓
Assign an encryption storage policy to the virtual machine or enable encryption on the VM
Why this is correct
Encryption is enforced per virtual machine through a VM storage policy that carries the encryption capability, or by enabling encryption directly on the VM. Without this assignment, the VM's files remain unencrypted even when a KMS is configured.
- ✗
Place the ESXi hosts in lockdown mode
Why it's wrong here
Lockdown mode restricts direct ESXi host access; it neither provides nor enables encryption. Tempting because encryption is a security hardening measure, and it would be correct when tightening host access, but VM encryption requires a KMS-backed key provider registered with vCenter and hosts.
Go deeper
Related to this question
About these practice questions
One of 281 original VCP-DCV practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official VMware exam blueprint
This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.