VCP-VVF Deploy Configure And Operate Vvf Practice Question
An administrator is configuring role-based access control (RBAC) in a vSphere Foundation 9.0 environment and needs to grant a user permission to manage virtual machines within a specific folder, but inherited permissions from the root vCenter level are granting too many privileges. How should the administrator resolve this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable permission inheritance on the specific folder object or assign the No Access role at that level.
To override inherited permissions, administrators can select 'Propagate' as unchecked when assigning a restricted role on a specific object, or explicitly assign a 'No Access' role to neutralize inherited privileges.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Edit the global vCenter configuration file to block all role inheritance globally.
Why it's wrong here
Global blocking of inheritance would break vCenter access control entirely.
- ✗
Delete the root-level permissions and recreate all user accounts from scratch.
Why it's wrong here
Deleting root permissions would lock out administrators and is extremely destructive.
- ✓
Disable permission inheritance on the specific folder object or assign the No Access role at that level.
Why this is correct
Unchecking propagation or assigning 'No Access' at a lower level effectively restricts or stops permission inheritance.
- ✗
Move the user account to a separate Active Directory organizational unit without vSphere integration.
Why it's wrong here
Moving users in AD does not alter vCenter permission evaluation unless SSO groups are modified.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
One of 517 original VCP-VVF practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official VMware exam blueprint
This VCP-VVF practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-VVF exam.