VCP-VVF Deploy Configure And Operate Vvf Practice Question
An administrator is troubleshooting identity and access management in vSphere Foundation 9.0 where Active Directory over LDAP is used as an Identity Provider. Users report intermittent login failures with 'Invalid Credentials' errors even though their passwords are correct. Which THREE troubleshooting steps should the administrator perform? (Choose three.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check the vCenter Single Sign-On logs (`sso.log`) located in `/var/log/vmware/sso/` for LDAP binding errors.
Troubleshooting AD over LDAP issues involves verifying identity source settings, checking clock synchronization across domain controllers and vCenter, and testing group membership mappings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Check the vCenter Single Sign-On logs (`sso.log`) located in `/var/log/vmware/sso/` for LDAP binding errors.
Why this is correct
The SSO logs provide detailed error codes regarding LDAP connection timeouts and binding failures.
- ✓
Verify that time synchronization (NTP) is accurate across the vCenter Server Appliance, ESXi hosts, and Active Directory Domain Controllers.
Why this is correct
Kerberos and LDAP authentication depend heavily on tight time synchronization; clock drift causes token validation failures.
- ✓
Validate that the LDAP bind account credentials have not expired and retain read access to the user search base DN.
Why this is correct
If the bind account password changes or expires, vCenter loses the ability to query AD.
- ✗
Convert the identity source to use Local OS users instead of Active Directory.
Why it's wrong here
Switching to local OS users does not troubleshoot or resolve an Active Directory integration problem.
- ✗
Reinstall the vCenter Server Appliance from scratch to regenerate the security token service (STS) certificates.
Why it's wrong here
Reinstalling vCenter is a drastic measure and unnecessary for troubleshooting LDAP binding issues.
About these practice questions
Courseiva writes every VCP-VVF question from scratch — 517 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official VMware exam blueprint
This VCP-VVF practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-VVF exam.