How can an administrator exclude Encryption rights from a support engineer?
A.
Clone the role Virtual machine power user, remove Cryptographic operations privileges.
B.
Clone the role Administrator and assign to the support engineer.
C.
Clone the role Virtual machine power user and assign to the support engineer.
D.
Clone the role No cryptography administrator and select privileges only for the support engineer.
Correct : https://docs.vmware.com/en/VMware-vSphere/6.5/com.vmware.vsphere.security.doc/GUID-17568345-E59E-43A8-A811-92F8BE9C7719.html
https://pubs.vmware.com/vsphere-6-5/index.jsp?topic=%2Fcom.vmware.wssdk.pg.doc%2FPG_VM_Encryption.14.4.html
D is correct
https://docs.vmware.com/en/VMware-vSphere/6.5/com.vmware.vsphere.security.doc/GUID-17568345-E59E-43A8-A811-92F8BE9C7719.html
By default, the user with the vCenter Server Administrator role has all privileges. The No cryptography administrator role does not have the following privileges that are required for cryptographic operations.
Add Cryptographic Operations privileges.
Global > Diagnostics
Host > Inventory > Add host to cluster
Host > Inventory > Add standalone host
Host > Local operations > Manage user groups