Academy/VCF Operations Cloud Operations 8.x Professional (2V0-32.24)/Lab O4: Compliance Benchmarking Against CIS / DISA STIG
This lab targets VCF 9.0

Lab O4: Compliance Benchmarking Against CIS / DISA STIG

VCF 9.0Intermediatevcp-foundation⏱ 75 min

Objectives

  • Run VCF Operations compliance checks against CIS vSphere benchmark and remediate drift.

Prerequisites

VCF lab environment deployed and operational

Lab Environment

Standard VCF lab environment for Cloud Operations 8.x Professional

Tasks

Task 1 Lab O4: Compliance Benchmarking Against CIS / DISA STIG

Run VCF Operations compliance checks against CIS vSphere benchmark and remediate drift.

Step 1

Enable CIS benchmark in VCF Operations compliance module.

Step 2

Run baseline scan across all ESXi hosts + vCenter.

Step 3

Export findings and categorize by severity.

Step 4

Remediate top 20 high-severity items via host profiles / DSC.

Step 5

Schedule recurring monthly scan with drift alerts.

Validation Gate

Check: Verify lab completion

Expected: Lab exercise completed successfully

Common Errors

Applying CIS/DISA STIG benchmarks without understanding their impact
Fix: CIS and DISA STIG benchmarks are prescriptive security hardening standards. Some controls may impact functionality: disabling certain ESXi services (required for VCF operations), changing SSH timeouts (affects support bundle collection), or restricting TLS versions (breaks legacy integrations). Review each control's impact before enabling.
Running compliance checks only on ESXi hosts, not management VMs
Fix: Compliance benchmarks apply to: ESXi hosts, vCenter appliance, NSX Manager VMs, SDDC Manager VM, and other management components. Checking only ESXi hosts misses vulnerabilities in management VMs. Configure compliance profiles for each component type.
Treating compliance score as a binary pass/fail
Fix: A 95% compliance score with the 5% gap in critical controls (e.g., encryption at rest disabled) is worse than 85% with all critical controls met. Prioritize remediation by control severity: critical/high first, then medium/low. Map each control to the organization's risk assessment.

Final Validation

Lab completed successfully

✓ All steps completed → No errors observed

Cleanup / Restore

• Revert to snapshot if needed

Design Reflection (VCDX)

Compliance benchmarking demonstrates security architecture awareness. VCDX designs for regulated industries should map to specific benchmarks (CIS, DISA STIG) with documented exceptions.

⚠ Known Pitfalls (from Community KB)

Blindly applying DISA STIG hardening without testing — some controls break VCF functionality.
Celebrating 95% compliance while ignoring that the missing 5% includes critical controls.
Was this page useful?
Type to search. ↑ ↓ to move, Enter to open, Esc to close.