VCP-DCV vSphere Security Practice Question
Which TWO statements about vCenter Single Sign-On (SSO) are true? (Choose two.)
⚠ Common exam trap
VCP-DCV often tests whether candidates know SSO is identity-source-agnostic (not AD-only) and that SAML 2.0 — not Kerberos — is the token protocol between vCenter services, so candidates who overgeneralize Kerberos pick the wrong option.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It supports multiple identity sources such as Active Directory and LDAP
Option A is correct because vCenter Single Sign-On supports multiple identity sources, including Active Directory (integrated Windows authentication), LDAP, and local SSO identity sources, allowing authentication against different user directories. Option E is correct because SSO issues SAML 2.0 tokens that are used to authenticate and authorize users across vCenter services and other vSphere components, enabling single sign-on without re-entering credentials. Option B is not correct because SSO does not rely on Kerberos as its authentication mechanism; it uses SAML tokens and can use various identity sources, though Kerberos may be involved in some Active Directory scenarios, it is not the defining authentication method. Option C is not correct because SSO does not store user passwords in plaintext; credentials are handled securely and passwords are not stored in plaintext for authentication. Option D is not correct because SSO does not require a Windows Active Directory domain; it can function with local SSO users or other supported identity sources such as LDAP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It supports multiple identity sources such as Active Directory and LDAP
Why this is correct
vCenter SSO federates authentication by connecting to external identity sources, including Active Directory over LDAP or Integrated Windows Authentication, and native LDAP directories. This satisfies the stem's requirement for a true SSO statement, since SSO's core function is brokering credentials across vSphere components via configured identity sources rather than storing accounts locally.
- ✗
It uses Kerberos to authenticate users to vCenter Server
Why it's wrong here
vCenter SSO issues its own SAML tokens after authenticating against an identity source; Kerberos is only one optional mechanism via Integrated Windows Authentication, not the authentication method itself. It is tempting because Kerberos underpins IWA, which is the correct choice when transparent domain logon to vCenter Server is required.
- ✗
It stores user passwords in plaintext for faster authentication
Why it's wrong here
vCenter Single Sign-On stores password hashes, never plaintext, and hashing is not a performance shortcut. Plaintext storage would be a security defect. SSO is correct for centralised authentication and token issuance across vCenter components, not credential storage.
- ✗
It requires a Windows Active Directory domain to function
Why it's wrong here
vCenter SSO ships with its own embedded identity source and can authenticate against OpenLDAP or an integrated directory, so a Windows Active Directory domain is not a prerequisite. It is tempting because AD over LDAP is a common identity source in enterprise deployments, making it the right choice when centralised Windows credentials are wanted.
- ✓
It uses SAML 2.0 tokens for authentication between vCenter services
Why this is correct
vCenter SSO issues SAML 2.0 bearer tokens through its Security Token Service, letting vCenter services and dependent components validate identity without re-authenticating against an identity source. This satisfies the stem's requirement for a true SSO statement, since SAML 2.0 is the actual token format used for service-to-service authentication.
Go deeper
Related to this question
About these practice questions
One of 281 original VCP-DCV practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official VMware exam blueprint
This VCP-DCV practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-DCV exam.