VCP Professional Standards & Ethics 5 — Questions and Answers
Question 1: A VMware engineer is asked to conduct a penetration test on a client's vSphere environment. Before beginning, which ethical and legal requirement must be satisfied?
- Verbal approval from the IT manager is sufficient
- A written, signed authorization from the appropriate organizational authority must be obtained (Correct answer)
- Approval from VMware directly is required before any testing
- Notification to all end users in the environment is mandatory
Correct answer: A written, signed authorization from the appropriate organizational authority must be obtained
Penetration testing without explicit written authorization constitutes unauthorized access, regardless of intent.
Question 2: A VMware professional discovers that a colleague has copied a portion of a commercial script without a license for use in a client's production environment. The ethical obligation is to:
- Use the script since the colleague took the legal risk
- Report the unlicensed use to the appropriate manager and recommend obtaining a proper license (Correct answer)
- Rewrite the script slightly to obscure its origin
- Ignore it since software licensing is a legal department concern
Correct answer: Report the unlicensed use to the appropriate manager and recommend obtaining a proper license
Using unlicensed commercial software violates intellectual property law and must be reported so that a proper license can be obtained.
Question 3: When a VMware administrator is unsure whether a specific action in a client environment is within the scope of their engagement, the best course of action is to:
- Proceed since hesitation delays the project
- Pause and clarify scope with the client or engagement manager before taking action (Correct answer)
- Take the action and document it as exploratory testing
- Consult colleagues who might have done similar work
Correct answer: Pause and clarify scope with the client or engagement manager before taking action
Acting outside defined scope without authorization can violate client trust and legal agreements; scope clarification must precede action.
Question 4: A VMware professional working remotely has access to a client's entire virtual infrastructure. Using that access to examine systems unrelated to the project is:
- Acceptable if no changes are made
- An ethical and likely legal violation of authorized access boundaries (Correct answer)
- Standard practice for understanding the full environment
- Permitted if the professional has a security background
Correct answer: An ethical and likely legal violation of authorized access boundaries
Access to systems beyond project scope—even read-only—violates the principle of authorized access and the client's trust.
Question 5: A VCP professional is asked by a client to recommend VMware licensing options. The professional's obligation is to recommend the option that:
- Maximizes VMware revenue to maintain the partnership tier
- Best fits the client's technical and business requirements, regardless of revenue impact (Correct answer)
- Is easiest to implement from a technical standpoint
- Aligns with what competitors have recommended
Correct answer: Best fits the client's technical and business requirements, regardless of revenue impact
A professional's primary obligation is to the client's best interest, not to vendor revenue or ease of implementation.
Question 6: A VMware engineer is asked to implement a monitoring solution that would surveil employee activity beyond system performance metrics. The professional should:
- Implement it without question since the employer directs all infrastructure work
- Verify that the surveillance is legally authorized, compliant with policy, and disclosed appropriately before implementing (Correct answer)
- Refuse all monitoring implementations as privacy violations
- Implement technical monitoring only and ignore the employee activity component
Correct answer: Verify that the surveillance is legally authorized, compliant with policy, and disclosed appropriately before implementing
Employee surveillance systems must comply with applicable law, organizational policy, and appropriate disclosure requirements before implementation.
Question 7: After completing a vSphere project, a VMware professional retains client environment diagrams for use as portfolio samples. This action is:
- Acceptable if names and IP addresses are redacted
- Ethically and legally problematic without explicit client permission, even when sanitized (Correct answer)
- Standard professional practice in the IT industry
- Permitted under implied license for non-competitive use
Correct answer: Ethically and legally problematic without explicit client permission, even when sanitized
Client environment documentation is proprietary and may not be retained or used as portfolio material without explicit written permission from the client.
A VMware engineer is asked to conduct a penetration test on a client's vSphere environment.
Before beginning, which ethical and legal requirement must be satisfied?