Academy/VCP-VCF 9.0 Administrator (2V0-17.25)/Lab: Apply Security Compliance Benchmark and Configure Chargeback
This lab targets VCF 9.0

Lab: Apply Security Compliance Benchmark and Configure Chargeback

VCF 9.0Intermediateadmincloud-opssecurity⏱ 90 min

Objectives

  • Enable and apply CIS ESXi security benchmark in VCF Operations
  • Analyze compliance findings and execute remediation workflows
  • Create custom compliance benchmarks for VCF-specific requirements
  • Configure costing rate cards for chargeback/showback reporting
  • Generate cost allocation reports per workload domain and business unit
  • Design a unified compliance + cost governance strategy for VCDX defense

Prerequisites

VCF Operations deployed with vCenter adapter collecting data (Lab 11 prerequisite)

Prior labs: vcp-admin-11

Required skills:

  • VCF Operations UI navigation
  • ESXi security hardening concepts
  • CIS benchmark framework understanding
  • Basic cost management principles

Lab Environment

Holodeck VCF pod with VCF Operations monitoring management domain. ESXi hosts in default (non-hardened) state for compliance testing.

Credentials

SystemUsernamePassword
VCF Operationsadmin
vCenteradministrator@vsphere.local

Tasks

Task 1 Enable CIS Compliance Benchmark and Analyze Findings

security

Security compliance is a key exam topic (Obj 4.3). CIS benchmarks provide industry-standard hardening checks for ESXi hosts. Understanding how VCF Operations automates compliance scanning is critical for both admin operations and VCDX defense.

Step 1
Navigate to VCF Operations → Compliance → Overview. Observe the current state — no benchmarks enabled means no compliance data.
Compliance dashboard shows 'No benchmarks enabled' or empty state.
VCF Operations ships with several benchmark content packs (CIS, DISA STIG, VMware hardening guide). These must be explicitly installed and enabled.
Step 2
Install CIS benchmark: Administration → Solutions → Repository → search 'CIS' → locate 'CIS ESXi 8 Benchmark' → Install.
Content pack status changes to 'Installed'.
VCF 9.0 uses ESXi 8.x hosts. Ensure you select the ESXi 8 benchmark, not older versions. The benchmark maps to CIS Controls v8 framework.
Selecting wrong ESXi version benchmark (7 vs 8)
Repository sync failure if VCF Operations has no internet access — use offline bundle import
Step 3
Enable benchmark: Compliance → Manage → select 'CIS ESXi 8 Benchmark' → Enable → apply to management cluster hosts.
Benchmark enabled, scope set to management cluster.
You can scope benchmarks per cluster, datacenter, or individual host. In production, apply to all clusters; in lab, start with management cluster.
Step 4
Wait for initial compliance scan (runs within 15 minutes). Navigate to Compliance → Overview → review per-host compliance status: green (compliant), yellow (partially), red (non-compliant).
Compliance dashboard shows percentage scores per host. Holodeck hosts typically score 40-60% on first scan.
Scan frequency is configurable. Default is every 24 hours. For lab testing, you can trigger a manual re-scan after remediation.
Step 5

Click a host with low compliance score. Expand findings list. For each finding, review: CIS control ID, description, current value, expected value, remediation command (esxcli or PowerCLI), severity level.

Detailed findings list with remediation guidance per control.
Common non-compliant items in Holodeck: SSH enabled (CIS 1.2), shell timeout not set (CIS 1.3), lockdown mode disabled (CIS 1.1), NTP not configured via chrony (CIS 2.1). These are expected in lab but would be violations in production.
Confusing 'Not Applicable' findings with 'Non-Compliant' — N/A means the control doesn't apply to this host configuration
Step 6
Export compliance report: Compliance → Reports → Generate → select 'CIS ESXi 8 Benchmark' → scope=management cluster → format=PDF. Review the report structure: executive summary, per-host details, remediation recommendations.
PDF report generated with compliance summary and detailed findings.
This report format is what auditors expect. In VCDX defense, reference this as evidence of automated compliance monitoring.

Validation Gate

Check: Compliance dashboard shows per-host compliance percentage with detailed findings

Expected: CIS ESXi 8 benchmark results visible for all management cluster hosts with specific control findings

Task 2 Execute Compliance Remediation Workflows

security

Knowing what's non-compliant is only half the story — remediation demonstrates operational competence. This task covers both manual and automated remediation approaches.

Step 1

Select a non-compliant finding with clear remediation: 'SSH service enabled' (CIS 1.2). Review the remediation command: esxcli system settings advanced set -o /UserVars/ESXiShellInteractiveTimeOut -i 900. Note the risk: disabling SSH breaks Holodeck lab access.

Remediation command displayed with risk assessment.
VCDX insight: This is a classic exam scenario — CIS says disable SSH, but VCF operations (SDDC Manager lifecycle) need SSH for host commissioning. The correct design answer is: enable SSH only during maintenance windows with audited access.
Blindly applying CIS remediation without understanding VCF dependencies — disabling SSH breaks SDDC Manager host management
Step 2
Remediate a safe finding: Set shell timeout. SSH to an ESXi host → run: esxcli system settings advanced set -o /UserVars/ESXiShellInteractiveTimeOut -i 900. This sets 15-minute shell timeout without breaking lab functionality.
Command succeeds. Setting applied to host.
Always remediate in a maintenance window. In production, use Host Profiles to push hardening settings consistently across all hosts.
Step 3
Trigger compliance re-scan: Compliance → select host → Rescan. Wait for scan to complete. Verify the remediated finding now shows 'Compliant'.
Compliance score increases. Shell timeout finding moves from red to green.
The delta between pre and post remediation scores is exactly what auditors want to see in a compliance improvement report.
Step 4
Document remediation exceptions: For findings that cannot be remediated (e.g., SSH must remain enabled for SDDC Manager), create a compliance exception record. In VCF Operations: Compliance → Manage → select finding → Suppress → add justification: 'Required for VCF lifecycle management per KB 123456'.
Finding marked as suppressed with documented justification.
Suppressed findings are excluded from compliance score but remain visible in audit trail. This is how you handle legitimate exceptions without inflating compliance numbers.
Suppressing findings without documented justification — auditors will flag this
Suppressing too many findings, making compliance scores meaningless
Step 5
Review Host Profiles approach: vCenter → Host Profiles → create profile from a hardened host. This captures security settings (firewall rules, service states, NTP, lockdown mode) as a baseline that can be applied to all hosts in a cluster for consistent compliance.
Host Profile created capturing security hardening settings.
Host Profiles + CIS benchmark = two-layer compliance. Host Profiles enforce the configuration, CIS benchmark validates it. Together they form a closed-loop compliance system.

Validation Gate

Check: At least one finding remediated and re-scan shows improved compliance score

Expected: Compliance percentage increased after remediation. Exception documented for unremediated findings.

Task 3 Create Custom Compliance Benchmark for VCF

security

CIS benchmarks are generic ESXi hardening. VCF environments have specific requirements (SDDC Manager connectivity, NSX VTEP MTU, vSAN network settings) that need custom compliance checks.

Step 1
Navigate to Compliance → Manage → Custom Benchmarks → Create New. Name='VCF 9.0 Operational Baseline'. Description='Custom compliance checks specific to VMware Cloud Foundation operational requirements'.
Empty custom benchmark created.
Custom benchmarks complement CIS — they don't replace it. Run both: CIS for generic ESXi hardening, custom for VCF-specific operational requirements.
Step 2

Add custom compliance checks (symptoms and alert definitions that map to compliance controls):

  1. vSAN Network MTU Check: Verify VMkernel adapter MTU >= 9000 for vSAN traffic
  2. SDDC Manager Connectivity: Verify ESXi host can reach SDDC Manager on port 443
  3. NTP Synchronization: Verify time drift < 5 seconds across all hosts
  4. vSAN Disk Health: Verify no disks in 'Degraded' or 'Absent' state
Custom compliance controls added to benchmark.
These custom checks catch VCF-specific misconfigurations that CIS benchmarks don't cover. NTP drift > 5s causes vSAN CMMDS issues; MTU mismatch causes vSAN performance degradation.
Step 3
Enable custom benchmark alongside CIS: Compliance → Manage → enable 'VCF 9.0 Operational Baseline' → apply to management cluster.
Both CIS and custom benchmarks active. Compliance dashboard shows combined results.
Running multiple benchmarks gives a more complete compliance picture. The combined score reflects both industry-standard hardening and VCF-specific operational health.
Step 4
Compare compliance views: Compliance → Overview → filter by benchmark. Review CIS score vs custom VCF score separately. Note which areas each benchmark catches that the other misses.
Two benchmark scores visible. CIS catches security hardening gaps; custom catches VCF operational gaps.
VCDX defense point: Explain your layered compliance strategy — industry-standard benchmarks for auditor satisfaction plus custom operational benchmarks for VCF health assurance.

Validation Gate

Check: Custom VCF compliance benchmark created, enabled, and producing compliance data alongside CIS

Expected: Two benchmarks active with separate compliance scores per host

Task 4 Configure Costing Rate Cards and Generate Business Unit Reports

manageability

Chargeback/showback is exam-relevant under Obj 4.3. Rate cards translate infrastructure consumption into business costs, enabling IT-as-a-service financial transparency.

Step 1
Navigate to VCF Operations → Administration → Cost Settings → Rate Card Editor. Review the default rate card structure: compute (CPU $/GHz/day, Memory $/GB/day), storage ($/GB/day), network ($/Mbps/day).
Rate Card Editor displays resource pricing categories.
Rate cards should reflect actual infrastructure costs: hardware amortization + power/cooling + licensing + operations overhead. A common formula: total monthly cost / total capacity = per-unit rate.
Setting unrealistically low rates that don't cover actual costs
Forgetting to include licensing costs (VCF per-core) in rate calculations
Step 2

Create tiered rate cards for different service levels:

  1. 'Standard Tier': CPU=$0.03/GHz/day, Memory=$0.008/GB/day, Storage=$0.003/GB/day
  2. 'Performance Tier': CPU=$0.06/GHz/day, Memory=$0.015/GB/day, Storage=$0.008/GB/day (vSAN all-flash)
  3. 'Mission Critical': CPU=$0.10/GHz/day, Memory=$0.025/GB/day, Storage=$0.015/GB/day (stretched cluster + HA)
Three rate cards created with tiered pricing.
Tiered rate cards map to VCF workload domain service levels. Standard = general workloads, Performance = database/analytics, Mission Critical = stretched cluster with SLA guarantees.
Step 3
Assign rate cards to clusters: Cost Settings → Assign. Map 'Standard Tier' to management cluster. In production, 'Performance Tier' would map to VI workload domain compute clusters, 'Mission Critical' to stretched clusters.
Rate cards assigned to clusters. Cost calculation begins.
VCF Operations needs 24-48 hours of data collection before cost reports are fully accurate. In lab, you'll see partial data immediately.
Step 4
Generate cost reports: Cost → Overview → review per-VM cost breakdown. Drill into a VM to see: daily compute cost, daily storage cost, total monthly projection. Navigate to Cost → Reports → Create → 'Monthly Cost by VM' → PDF.
Cost report generated showing per-VM resource consumption and projected costs.
The per-VM cost breakdown is what business unit leaders see in showback reports. It answers: 'How much does this application cost to run?'
Step 5
Configure cost allocation by business unit: Create custom groups in VCF Operations (Environment → Custom Groups) → group VMs by business unit using naming convention or tags. Generate cost report filtered by custom group to show per-department costs.
Cost report broken down by business unit/department.
Custom groups enable cost allocation without changing VM placement. Group by naming convention (e.g., 'fin-*' for finance), vSphere tags, or folder structure.
VMs without proper naming/tagging fall into 'Unallocated' bucket — enforce tagging policy
Shared infrastructure costs (management domain, NSX edges) need a fair allocation model
Step 6
Compare showback vs chargeback modes: Review the difference — showback displays costs for transparency without billing action; chargeback integrates with finance/ERP systems (ServiceNow, SAP) for actual cross-charging. In VCF Operations, configure: Cost → Settings → Mode = Showback (lab default).
Understanding of showback vs chargeback operational models.
Most organizations start with showback to build cost awareness, then transition to chargeback once teams accept the model. VCDX defense: explain this phased approach.

Validation Gate

Check: Tiered rate cards created, assigned to clusters, per-VM cost reports generated with business unit allocation

Expected: Cost dashboard shows per-VM costs with rate card pricing. Business unit cost allocation visible via custom groups.

Task 5 Unified Compliance + Cost Governance Strategy and VCDX Defense

manageability

Compliance and costing are two sides of governance. This task ties them together into a holistic operational model that demonstrates architect-level thinking for VCDX defense.

Step 1
Build a governance dashboard in VCF Operations: Create a custom dashboard (Dashboards → New) with widgets showing:
  1. Compliance Score by Cluster (scoreboard widget)
  2. Non-Compliant Findings Trend (line chart, 30 days)
  3. Monthly Cost by Workload Domain (bar chart)
  4. Cost per VM Trend (line chart, 90 days)
  5. Top 10 Most Expensive VMs (top-N widget)
Custom governance dashboard with compliance + cost widgets.
This single dashboard gives CIO-level visibility: are we secure AND cost-efficient? In VCDX defense, this demonstrates operational maturity.
Step 2

Create compliance-cost correlation: Using Super Metrics (from Lab 11), create a metric that calculates 'Cost of Non-Compliance' = (number of non-compliant findings) x (estimated remediation hours) x (engineer hourly rate). This quantifies the business impact of security debt.

Super Metric calculating cost of non-compliance.
Quantifying compliance debt in dollar terms gets executive attention faster than technical compliance scores. This is a powerful VCDX defense technique.
Step 3

Configure automated alerts for governance thresholds:

  1. Alert if compliance score drops below 80% on any cluster
  2. Alert if monthly cost exceeds budget threshold per business unit
  3. Alert if a VM runs without compliance scan for > 48 hours

Set notification channel to email (configured in Lab 11).

Three governance alerts configured with notification channels.
Proactive alerting prevents governance drift. Without alerts, compliance degrades as new hosts are added and configurations change.
Step 4

VCDX Defense Preparation — document and rehearse responses to these panelist questions:

  1. 'How do you balance security hardening (CIS) with operational needs (SSH access for troubleshooting)?'

Answer: Exception-based model. SSH disabled by default, enabled via change request during maintenance windows with audited access. SDDC Manager uses its own management path that doesn't require persistent SSH.

  1. 'What costing model justifies VCF investment to leadership?'

Answer: TCO comparison. VCF per-core licensing vs traditional vSphere + separate NSX + separate vSAN licensing. Show consolidated management reduces ops cost by 30-40%. Tiered rate cards demonstrate value-based pricing.

  1. 'A CIS finding says disable NTP client but VCF requires NTP. How do you handle this?'

Answer: This is a false positive — CIS checks generic NTP, but VCF requires chrony/NTP for vSAN CMMDS quorum. Document as exception with KB reference, suppress finding with justification.

  1. 'How do you handle shared infrastructure costs (management domain, NSX edges) in chargeback?'

Answer: Shared infrastructure costs allocated proportionally based on workload domain resource consumption. Management domain cost treated as platform overhead — either absorbed centrally or distributed evenly across business units.

Four VCDX defense responses documented and rehearsed.
The compliance-vs-operations tension is a favorite VCDX panelist topic. Having concrete examples from lab experience makes your defense credible.

Validation Gate

Check: Governance dashboard created, compliance-cost correlation configured, alerts set, VCDX defense responses prepared

Expected: Unified governance view operational with proactive monitoring and documented defense strategy

Final Validation

CIS compliance benchmark applied and remediated, custom VCF benchmark created, tiered costing configured with business unit allocation, unified governance dashboard operational.

✓ CIS ESXi 8 benchmark enabled and producing compliance data → Per-host compliance status visible with detailed findings

✓ At least one finding remediated with improved compliance score → Post-remediation re-scan shows improvement

✓ Custom VCF operational benchmark active → VCF-specific compliance checks producing results

✓ Tiered rate cards assigned to clusters → Per-VM cost calculations with tiered pricing

✓ Cost allocation by business unit configured → Custom groups showing per-department costs

✓ Governance dashboard with compliance + cost widgets → Unified view of security posture and cost efficiency

Cleanup / Restore

• Take snapshot 'post-compliance-costing'

• Note: Leave compliance benchmarks enabled for ongoing monitoring

Design Reflection (VCDX)

Panelist: How do you balance security hardening (CIS) with operational needs (SSH access for troubleshooting)? What costing model justifies VCF investment to leadership? How do you quantify security debt in business terms?

Requirements

  • Regulatory compliance reporting (CIS, DISA STIG, industry-specific)
  • Cost transparency per business unit with tiered service levels
  • Automated compliance monitoring with drift detection
  • Exception management with audit trail

Constraints

  • CIS benchmarks may flag VCF-required configurations as violations
  • Rate card accuracy depends on current hardware and licensing costs
  • Compliance remediation may require maintenance windows
  • Custom benchmarks need ongoing maintenance as VCF versions change

Assumptions

  • Compliance benchmarks updated with each VCF upgrade
  • Rate cards reviewed quarterly to reflect actual infrastructure costs
  • Business units accept showback model before chargeback transition
  • Host Profiles used to enforce consistent hardening across clusters

Risks

  • Over-hardening can break VCF operational workflows (SSH, NTP, firewall rules)
  • Inaccurate rate cards lead to billing disputes and loss of IT credibility
  • Compliance exceptions without proper documentation create audit exposure
  • Cost allocation model disputes between shared infrastructure consumers

Self-Assessment Discussion Prompts

  1. How would you handle a CIS finding that directly conflicts with VCF operational requirements?
  2. What's the difference between chargeback and showback, and when should each be used?
  3. How do you quantify the business impact of compliance debt to executive stakeholders?
  4. What's your approach to shared infrastructure cost allocation in a multi-tenant VCF environment?
  5. How would you design a compliance remediation workflow that minimizes operational disruption?

References

Was this page useful?
Type to search. ↑ ↓ to move, Enter to open, Esc to close.