VMware vSphere 8.x Professional (VCP-DCV 2022) — Question 107
An administrator wants to implement virtual machine encryption.
Which component encrypts the virtual machine files?
Answer options
- A. Certificate
- B. Data encryption key (DEK)
- C. Key encryption key (KEK)
- D. Key management server (KMS)
Correct answer: B
Explanation
The Data Encryption Key (DEK) is specifically designed to encrypt the virtual machine files, ensuring their security. The Certificate is used for identity verification, while the Key Encryption Key (KEK) is used to encrypt the DEK itself. The Key Management Server (KMS) is responsible for managing and storing keys but does not directly encrypt the virtual machine files.