Courseiva
IT Architectures Technologies StandardshardMultiple ChoiceObjective-mapped

VCP-VVF IT Architectures Technologies Standards Practice Question

An infrastructure architect is configuring network security standards for a vSphere Foundation 9.0 environment. They want to ensure that all virtual machine traffic traversing a vSphere Distributed Switch cannot be sniffed by compromised guest operating systems using promiscuous mode. Which configuration setting must be enforced?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Set Promiscuous Mode, MAC Address Changes, and Forged Transmits to 'Reject' at the distributed port group security policy level.

Port group security policies on the vSphere Distributed Switch include Promiscuous Mode, MAC Address Changes, and Forged Transmits, which should be set to 'Reject' to prevent sniffing and spoofing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Set Promiscuous Mode, MAC Address Changes, and Forged Transmits to 'Reject' at the distributed port group security policy level.

    Why this is correct

    Correct. Rejecting these settings prevents unauthorized packet capture and traffic spoofing at the virtual switch port level.

  • Configure IP Source Guard on the physical switch access ports.

    Why it's wrong here

    IP Source Guard prevents IP spoofing on physical switches but does not configure vSphere port group security.

  • Deploy an external hardware tap appliance inline with the physical uplinks.

    Why it's wrong here

    Hardware taps capture physical wire traffic; they do not secure virtual switch switching policies.

  • Enable BPDU Guard on all physical uplink switch ports connected to the ESXi host NICs.

    Why it's wrong here

    BPDU Guard protects physical switches from loops caused by unauthorized switches, not guest VM sniffing.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This VCP-VVF question is part of Courseiva's 517-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official VMware exam blueprint

This VCP-VVF practice question is part of Courseiva's free VMware certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VCP-VVF exam.