VCP-VVF Deploy Configure And Operate Vvf Practice Question
An administrator is auditing access control within a vSphere Foundation 9.0 environment. A specific group of security operators requires permission to view and manage VM snapshots across all production virtual machines, but they must not be allowed to power off virtual machines or modify networking settings. What is the best practice method to implement this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a custom vSphere role containing only the required snapshot privileges and assign it to the security group on the production VM folder with propagation enabled.
Role-based access control (RBAC) in vSphere requires creating a custom role with only the necessary privileges (e.g., Virtual Machine > State > Create Snapshot, Remove Snapshot) and assigning it to the security group on the folder or cluster level.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Modify the default 'No Access' role to include snapshot creation rights for the production cluster.
Why it's wrong here
The 'No Access' role cannot be modified; custom roles must be created instead.
- ✗
Assign the built-in Administrator role to the security group and remove individual permissions via advanced host policies.
Why it's wrong here
The built-in Administrator role grants full control, and removing permissions piecemeal is insecure and unsupported.
- ✗
Grant the security group Read-Only access at the vCenter root and enable snapshot delegation in Host Profiles.
Why it's wrong here
Read-Only access prevents creating or managing snapshots.
- ✓
Create a custom vSphere role containing only the required snapshot privileges and assign it to the security group on the production VM folder with propagation enabled.
Why this is correct
Custom roles enforce the principle of least privilege by bundling specific operational rights without granting broader administrative control.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
One of 517 original VCP-VVF practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official VMware exam blueprint
This VCP-VVF practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-VVF exam.