Courseiva
Deploy Configure And Operate VvfmediumMultiple ChoiceObjective-mapped

VCP-VVF Deploy Configure And Operate Vvf Practice Question

An administrator is auditing access control within a vSphere Foundation 9.0 environment. A specific group of security operators requires permission to view and manage VM snapshots across all production virtual machines, but they must not be allowed to power off virtual machines or modify networking settings. What is the best practice method to implement this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a custom vSphere role containing only the required snapshot privileges and assign it to the security group on the production VM folder with propagation enabled.

Role-based access control (RBAC) in vSphere requires creating a custom role with only the necessary privileges (e.g., Virtual Machine > State > Create Snapshot, Remove Snapshot) and assigning it to the security group on the folder or cluster level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Modify the default 'No Access' role to include snapshot creation rights for the production cluster.

    Why it's wrong here

    The 'No Access' role cannot be modified; custom roles must be created instead.

  • Assign the built-in Administrator role to the security group and remove individual permissions via advanced host policies.

    Why it's wrong here

    The built-in Administrator role grants full control, and removing permissions piecemeal is insecure and unsupported.

  • Grant the security group Read-Only access at the vCenter root and enable snapshot delegation in Host Profiles.

    Why it's wrong here

    Read-Only access prevents creating or managing snapshots.

  • Create a custom vSphere role containing only the required snapshot privileges and assign it to the security group on the production VM folder with propagation enabled.

    Why this is correct

    Custom roles enforce the principle of least privilege by bundling specific operational rights without granting broader administrative control.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 517 original VCP-VVF practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official VMware exam blueprint

This VCP-VVF practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-VVF exam.