Courseiva
vSphere Security →hardMultiple Select

VCP-DCV vSphere Security Practice Question

Which TWO statements about vCenter Single Sign-On (SSO) are true? (Choose two.)

⚠ Common exam trap

VCP-DCV often tests whether candidates know SSO is identity-source-agnostic (not AD-only) and that SAML 2.0 — not Kerberos — is the token protocol between vCenter services, so candidates who overgeneralize Kerberos pick the wrong option.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It supports multiple identity sources such as Active Directory and LDAP

Option A is correct because vCenter Single Sign-On supports multiple identity sources, including Active Directory (integrated Windows authentication), LDAP, and local SSO identity sources, allowing authentication against different user directories. Option E is correct because SSO issues SAML 2.0 tokens that are used to authenticate and authorize users across vCenter services and other vSphere components, enabling single sign-on without re-entering credentials. Option B is not correct because SSO does not rely on Kerberos as its authentication mechanism; it uses SAML tokens and can use various identity sources, though Kerberos may be involved in some Active Directory scenarios, it is not the defining authentication method. Option C is not correct because SSO does not store user passwords in plaintext; credentials are handled securely and passwords are not stored in plaintext for authentication. Option D is not correct because SSO does not require a Windows Active Directory domain; it can function with local SSO users or other supported identity sources such as LDAP.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    It supports multiple identity sources such as Active Directory and LDAP

    Why this is correct

    vCenter SSO federates authentication by connecting to external identity sources, including Active Directory over LDAP or Integrated Windows Authentication, and native LDAP directories. This satisfies the stem's requirement for a true SSO statement, since SSO's core function is brokering credentials across vSphere components via configured identity sources rather than storing accounts locally.

  • ✗

    It uses Kerberos to authenticate users to vCenter Server

    Why it's wrong here

    vCenter SSO issues its own SAML tokens after authenticating against an identity source; Kerberos is only one optional mechanism via Integrated Windows Authentication, not the authentication method itself. It is tempting because Kerberos underpins IWA, which is the correct choice when transparent domain logon to vCenter Server is required.

  • ✗

    It stores user passwords in plaintext for faster authentication

    Why it's wrong here

    vCenter Single Sign-On stores password hashes, never plaintext, and hashing is not a performance shortcut. Plaintext storage would be a security defect. SSO is correct for centralised authentication and token issuance across vCenter components, not credential storage.

  • ✗

    It requires a Windows Active Directory domain to function

    Why it's wrong here

    vCenter SSO ships with its own embedded identity source and can authenticate against OpenLDAP or an integrated directory, so a Windows Active Directory domain is not a prerequisite. It is tempting because AD over LDAP is a common identity source in enterprise deployments, making it the right choice when centralised Windows credentials are wanted.

  • ✓

    It uses SAML 2.0 tokens for authentication between vCenter services

    Why this is correct

    vCenter SSO issues SAML 2.0 bearer tokens through its Security Token Service, letting vCenter services and dependent components validate identity without re-authenticating against an identity source. This satisfies the stem's requirement for a true SSO statement, since SAML 2.0 is the actual token format used for service-to-service authentication.

About these practice questions

One of 281 original VCP-DCV practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official VMware exam blueprint

This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.