VCP-VVF Deploy Configure And Operate Vvf Practice Question
An administrator is managing user permissions in vSphere Foundation 9.0. Which TWO practices are recommended when assigning roles and permissions? (Choose two)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign permissions to Active Directory/OpenID groups rather than individual user accounts.
Best practices for RBAC include assigning permissions to Active Directory groups rather than individual users, and assigning roles at the highest appropriate inventory level to minimize management overhead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Assign permissions to Active Directory/OpenID groups rather than individual user accounts.
Why this is correct
Using groups simplifies access management when personnel change.
- ✗
Assign permissions to individual users at the virtual machine level for every single VM.
Why it's wrong here
Micro-managing permissions per VM creates excessive administrative overhead.
- ✗
Modify the built-in Administrator role directly to add custom security auditing privileges.
Why it's wrong here
Built-in roles are read-only and cannot be modified; custom roles should be created instead.
- ✓
Assign roles at the highest logical inventory level (such as datacenter or folder) to leverage inheritance.
Why this is correct
Leveraging permission inheritance reduces the need to re-apply roles at lower levels.
- ✗
Grant all developers the global Administrator role to ensure zero operational friction.
Why it's wrong here
Granting administrator privileges globally violates fundamental security principles.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
This VCP-VVF question is part of Courseiva's 517-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official VMware exam blueprint
This VCP-VVF practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-VVF exam.