Q# 1

Refer to the exhibit.

Which VMware SD-WAN Edge High Availability deployment is being used”?

A. Enhanced HA
B. Fault Domain HA
D. Standard HA

Correct Answer: C

Q# 2

Which feature is required to prevent a split-brain condition for a branch in an Enhanced HA

A. Split-Brain Detection
B. SD-WAN Service Reachable on the private overlay
C. Cloud VPN

Correct Answer: B

Q# 3

A technician at a customer site is deploying VMware SD-WAN Edge 620 notices that the Edge LED is
shown amber.

What is the meaning of this LED color?

A. Edge is still booting.
B. DNS is not reachable from the Edge.
C. Edge is not activated.
D. Internet is not available from the Edge

Correct Answer: D

Q# 4

Which statement is true about the VMware SD-WAN Gateway roles and assignments?

A. Primary Gateway cannot be used as Super gateway for Edge-to-Edge communication, even it all the Edges have a common Primary gateway
B. The SD-WAN Orchestrator assigns the Gateways to the Edge automatically when it comes up based Oil (lie location of the Edge Branch-to-branch will choose the right Gateway automatically
C. If the Primary Gateway goes down. Cloud internet traffic would failover to Secondary gateway automatically
D. The Primarily and Secondary Gateways share the load fur both internet traffic and VPN traffic

Correct Answer: A

Q# 5

Which port is used for communication between VMware SD-WAN Edge and Orchestrator if there are no tunnels established to the Gateways?

A. UDF 2426
B. TCP 80
C. TCP 443
D. UDP 500

Correct Answer: B

Q# 6

During a security-related discussion, an administrator determines that guest users not be able to access any resources on the corporate network.

Which VMware SD-WAN feature can achieve this goal in the most scalable and manageable way?

A. Segments
B. Business Policy
D. Firewall

Correct Answer: A

Q# 7

A service provider needs to upgrade a gateway to a new software version. Which step in needed to complete the upgrade process?

A. Re-assign the Gateway to a new gateway Pool with the appropriate software version, and then run `sudo apt-get update\\’\\’ from the Gateway console.

B. Create a new disk partition to save the new software image to, modify the boot order via the Gateway BIOS to boot to the new partition, and then reboot the gateway.

C. From the Orchestrator, select the check-box next to the appropriate gateway, choose `\\’Assign Software image”, and then select the version for the upgrade.

D. Copy the new image to/var/lib/velocloud/software_update.tar, and then run the upgrade the script from the console.

Correct Answe: B

Q# 8

Which statement describes a characteristic of VMware SU-WAN Edge (VCL) clustering?

A. One VCE cluster can be formed with both virtual and hardware at the same lime
B. A VCE cluster requires one dedicated interface for HA sync
C. VCF clusters member sync flow tables between themselves.
D. VCE cluster members should have unique IP addresses on its WAN interfaces

Correct Answer: C

Q# 9

Company A has recently acquired Company B and needs to establish network connectivity. Company A has only Cisco for firewalls and VPN. Company B is using VMware SD-WAN. Which VMware SD-WAN Cloud VPN solution should an administrator configure to establish connectivity?

A. Branch to Non VMware SD-WAN Site.
B. Branch to SD-WAN Hub
C. Branch to Main Office VPN
D. Branch to Branch VPN

Correct Answer: A

Q# 10

A customer is looking to have Quality of Service (QoS), resource allocations, link/path steering, and error correction applied automatically based on applications. Which component of VMware SD-WAN helps the customer achieve this requirement?

A. Overlay Flow Control
B. High Availability Configuration
C. Business Policy Framework
D. Branch Site Topologies

Correct Answer: C

Q# 11

A service provider wants to offer a common service from its data center via VMware SD-WAN Partner Gateway to many customers with overlapping IP addresses. Which configuration must be implemented?

A. Define multiple segments tor each customer
B. Enable NAT hand off under hand off static routes configuration
C. Enable tag type QinQ under hand off interface configuration
D. Configure source policy-based NAT under business- policies configuration

Correct Answer: A

Q# 12

The VMware SD-WAN solution is comprised of Orchestrator, Gateway, and Edge. The architecture ensures separation and secure communication between the management, control, and data plane of the solution. The management plane consists of the VMware SD-WAN Orchestrator, and the control plane is comprised of the VMware SO-WAN Gateway/Controller. Which statement correctly describes this situation?

A. VMware SD-WAN Edges/Gateways establishes a Transport Layer Security (TLS) 1 2 encrypted session to the VMware SU-WAN Orchestrator

B. To make the entire solution to work property, TCP port 443 and HOP port 500 and UDP port 4500 are required to open in the firewall rule, if Edge is deployed behind a Firewall.

C. There is impact on data plane when the Edge loses connectivity to the management plane. The operator only loses the visibility of the Edge from Orchestrator and cannot make configuration changes on the Edge until the management plane connectivity is resumed.

D. Traffic between VMware SD-WAN Edges and from VMware SD-WAN Edges to VMware SD-WAN Gateways uses VMware SD-WAN Management Protocol (VCMP) tunneling over User Datagram Protocol (UDP) port 2427. secured with Internet Protocol Security (IPSec)

Correct Answer: D

5V0-31.20 Q&As


An administrator has been tasked with enabling north/south routing and the consumption of additional network services by deploying an NSX Edge Clusterinto a VMware Cloud Foundation deployment The following information is available:

1. There is only one Workload Domain.
2. The Workload domain contains two vSphere Clusters.
3. One of the vSphere Clusters is a Stretched Cluster
4. All hosts within the Workload Domain are identical.
5. The physical network uses both the Border Gateway Protocol (BGP) and Bidirectional forwarding detection (BFD) protocol

Which statement is true when considering the deployment of an NSX Edge Cluster in this situation?

A. The NSX Edge cluster cannot be deployed onto the Stretched Cluster.
B. The Small form factor must be selected when deploying the NSX Edge cluster.
C. The Default profile type must be selected when deploying the NSX Edge cluster.
D. BDF must be selected when deploying the NSX Edge cluster.


Which prerequisite is correct for vRealize Automation when deploying vRealize Suite components using vRealize Suite Lifecycle Manager?

A. Configure the vRealize Suite Lifecycle Manager appliance to use the ESXi host as an NTP source.
B. Run an external vRealize Orchestrator workflow.
C. Deploy vRealize Operations Manager before vRealize Automation.
D. Deploy Workspace ONE Access before vRealize Automation


An administrator creates a vSphere with Tanzu namespace.
Which two limits can be defined in namespace? (Choose two )

A. Limits on CPU
B. Limits on memory
C. Limits on NIOC
D. Limits on the load balancer
E. Limits on storage IOPS


Where can NSX T be used in VMware Cloud Foundation?

A. in an external cluster
B. Only with consolidated architectures
C. In all architectures
D. Only with standard architectures


Which two statements regarding MTU size should be considered prior to execute a deployment of VMware Cloud Foundation? (Choose two.)

A. MTU of 1600 is a minimum for TFP VLANs
B. MTU of 1500 is a minimum for TEP VLANs
C. MTU of 9000is a minimum for all non-managementVLANs
D. MTU of 9000 is recommended for all non-management VLANs
E. MTU of 1500 is recommended for all non-management VLANs


Which sizing tool is available for calculating management domain storage requirements?

A. VMware Configuration Maximums
B. Virtualization Assessment Package
C. VMware Compatibility Guide
D. vSAN ReadyNode Sizer


An administrator has been tasked with adding capacity to an existing workload domain. The new hosts have hosts arrived but will need to be prepared before they can be added to VMware Which two steps must be performed to facilitate imaging with the VMware Imaging Appliance? (Choose
two )

A. Configure Legacy boot mode in BIOS.
B. Ensure that UEFl is enabled in BIOS.
C. Configure the hosts to boot from SAN.
D. Configure option 43 on DHCP servers
E. Configure the hosts to PXE boot


The administrator for an existing VMware Cloud Foundation instance has one management domain (sfom01) and one workload domain (sfo-w01). The workload domain consists of two vSphere clusters (sfow01-ci01 and sfo-w01-cl02) using vSAN as principle storage.

The workload domain also includes an NSX-T Edge Cluster deployed in the default cluster(sfo-w01-c01) of the workload domain. The first cluster (sfo-w01-c01) rack1, and the second cluster (sfo-w01-c01) resides in rack 1.

A new project is underway, and the capacity of the second cluster (sfo-w0I cl02) of the workload domain that will be consumed by realizing automation needs to be expanded Rack 1 is at capacity. Eight additional hosts have been placed in rack 2 and cabled within the new rack. The network architecture is an L3 spine-leaf architecture.

Which cluster expansion type should be selected when expanding the second cluster using the SDDC Manager UI?

A. L2 uniform
B. L2 non-uniform
C. L2 non-uniform and L3
D. L3 non-uniform and L2


What is the benefit of placing vRealize Suite I lifecycle Manager on the cross-region Application Virtual Network?

A. vRealize Suite Lifecycle Manager cannot be placed on the cross-region network as it is reserved for Workload VMs only.
B. SDDC Manager uses the cross-region network to deploy vRealize Log Insight and vRealize Automation Proxy Servers, and this is not configurable.
C. vRealize Suite Lifecycle Manager can be deployed in cluster mode
D. After recovery, an administrator can continue using the same IP address, DNS record, and routing configuration


An administrator wants to configure a stretched cluster and needs to configure vMotion, Which type of network connection is supported for vMotion?

A. The vSphere vMotion network must be routed between sites.
B. The vSphere vMotion network must be stretched via VMware MCX
C. The vSpherevMotionnetwork must be routed via VPN.
D. The vSphere vMotion network must be routed via VMware HCX.


An administrator has deleted an NSX manager application from the management domain by accident and now needs to restore the NSX Manager application as soon as possible.
Which three steps are necessary to accomplish this goal? (Choose three)

A. Refresh the SSH Keys that are stored in the SDDC Manager inventory
B. Deploy a new NSX Manager appliance.
C. Restore a known good configuration.
D. Download and decrypt the encrypted backup file from the SF IP server
E. Create a JSON file containing the NSX Manager configuration, and insert an API access token
F. Configure the new NSX Manager appliance with SFTP server settings.


Which step should be followed to restore SDDC Manager using the OVF tool?

A. Retrieve the DNS name or IP address of a host m the management Domain
B. Use the host s DNS name in the host password_vault-JSON, and this will display the root password
C. Install the OVF Tool on a system in the VI Workload domain.
D. Move the SDDC Manager VM into the VI Workload Resource Pool.

VMware VCP-SEC 2021 Certifications 2V0-81.20 exam test


Which file can be used to validate reply authentication was enabled for Carbon Black Cloud?

A. C:\Program Files\Confer\repcii.ini
B. C:\Program Files\Confer\config.ini
C. C:\Program Files\Confer\cfg.ini
D. C:\Program Files\Confer\cli.ini

Correct Answer: A


An administrator has added a new ESXi host to a vCenter Server Cluster with NSX-T Data Center already working. The
administrator installed NSX-T Data Center components in the new ESXi.

When the administrator deploys a new VM in the host, connectivity tests good with ping, but SSH session traffic is erratic. The VDS and NSX-T Data Center configuration is the same as each ESXI in the Cluster, but only VMs in the new ESXI is having problems.

What should the administrator do to address the problem?

A. Verify VLAN connection in each physical uplink.
B. Verify MTU configuration in each physical uplink.
C. Change VDS MTU to 1500 in each physical uplink.
D. Change VDS MTU to 2000 in each physical uplink.

Correct Answer: B


In an NSX-T Data Center deployment, when assigning user rights, what right would an administrator assign to a user to
administer security compliance policies?

A. Auditor
B. Security Engineer
C. NSX Administrator
D. Security Administrator

Correct Answer: D


A company has deployed a new application. Users are complaining they cannot connect. The
the administrator suspects there is an issue with the Distributed Firewall (DFW).

What three steps can be taken to troubleshoot the DFW? (Choose three.)

A. The administrator should confirm that SLOT 2, which is used by the DFW, is configured under the vNICs of the VMs.
B. The administrator should configure vRealize Log Insight using the Insight agent as the type and review the DFW rule
logs in vRealize Log Insight.
C. The administrator should confirm if the DFW rule is set to log, and then look on the hypervisor where the VMs reside
and look at logs at /var/log/dfwpktlogs.log.
D. The administrator should verify firewall rules exist to permit traffic and verify the hit counters are increasing.
E. The administrator should configure vRealize Log Insight using Syslog as the type and review the DFW rule logs in
vRealize Log Insight.

Correct Answer: CDE


An administrator is trying to secure Workspace ONE components with firewall rules.
What port and protocol does the administrator need to allow for Secure LDAP to Active Directory?

A. 389/TCP
B. 3389/TCP
C. 636/TCP
D. 1433/TCP

Correct Answer: C


An administrator is updating NSX Distributed Firewall rules. The administrator did the Publish a few
minutes ago and is now receiving calls about lost connections. The administrator has decided to roll-back
the configuration.

Where can the administrator see past saved configurations to perform the rollback?

A. Go to System > Distributed Firewall > Configurations > View
B. Go to Security > Distributed Firewall > ACTIONS > Configurations – View
C. Go to System > Distributed Firewall > Rolling back > View
D. Go to Inventory > Distributed Firewall > ACTIONS > Configurations – View

Correct Answer: A


Considering the NSX Manager Node, what is VMware\\’s recommended size for typical production deployment?

A. small appliance for deployments with up to 64 hosts
B. medium appliance for deployments with up to 64 hosts
C. medium appliance for deployments with up to 128 hosts
D. small appliance for deployments with up to 32 hosts

Correct Answer: B


In what order are NSX-T Distributed Firewall configurable rules categories processed?

A. Emergency, Ethernet, Environment, Infrastructure, Application
B. Ethernet, Environment, Infrastructure, Application, Emergency
C. Ethernet, Emergency, Infrastructure, Environment, Application
D. Emergency, Ethernet, Infrastructure, Environment, Application

Correct Answer: C


What command does an administrator use on an ESXi Transport Node to check connectivity with the management

A. esxcli network IP connection list 1234
B. esxcli firewall IP connection list | grep 1234
C. esxcli ip connection 1234
D. esxcli network IP connection list | grep 1234

Correct Answer: D


Which three statements are correct for Active Directory integration with Identity Firewalls (IDFW) in an NSX-T Data
Center deployment? (Choose three.)

A. The IDFW can be used on both physical and virtual servers as long as the supported operating system is installed.
B. The Thin Agent must be enabled in VMWare tools as it is not enabled by default.
C. The IDFW can be used for Virtual Desktops (VDI) or Remote desktop sessions (RDSH support).
D. Identity-based groups can be used as the source or destination in DFW rules.
E. User identity information is provided by the NSX Guest Introspection Thin Agent.

Correct Answer: CDE


Which is the name of the default policy that is applied to all applications in Workspace ONE Access?

A. primary_policy
B. default_policy
C. default_access_policy_set
D. default_application_policy

Correct Answer: C


What are two valid time limit selections when creating a Last Seen compliance policy in Workspace ONE UEM?
(Choose two.)

A. Hours
B. Minutes
C. Days
D. Weeks
E. Months

Correct Answer: BC

Take the free VMware 2v0-71.21 exam practice



Which role is required to enable data protection in Tanzu Mission Control?\

A. cluster. admin
B. clusters. admin
C. cluster.edit
D. cluster. manage

Correct Answer: A


What is the definition of Tanzu Kubernetes Grid Instance?

A. Management cluster and Tanzu Kubernetes clusters
B. Management cluster and Tanzu Operations
C. Management cluster and Tanzu Build Service
D. Management cluster and kubeadm

Correct Answer: A


What is the advantage of connecting the Tanzu Kubernetes Grid (TKG) CLI to a vSphere with Tanzu Supervisor

A. Tanzu Kubernetes clusters can be managed with the vCenter Server Graphical User Interface console.
B. Kubernetes objects can be created via the vCenter Server VAMI interface.
C. Tanzu Kubernetes clusters can be managed with ESXi Host Client.
D. Tanzu Kubernetes clusters can be deployed to vSphere with Tanzu and manage their lifecycle directly
from the TKG CLI.

Correct Answer: D


Which step must be taken to enable Kubernetes auditing on a Tanzu Kubernetes cluster?

A. Set the ENABLE_AUDIT_LOGGING variable to ‘true’ before deploying the cluster
B. Run systemctl start auditd and systemctl enable auditd on the master node
C. Audit is enabled by default on every Tanzu cluster
D. Edit /etc/Kubernetes/audit-policy.YAML and set ENABLE_AUDIT variable to ‘1’ on the master node

Correct Answer: A


What are two ClusterAPI providers being used in Tanzu Kubernetes Grid? (Choose two.)


Correct Answer: AB


An architect is designing the infrastructure for multiple applications and needs to ensure isolation and control over
resources and permissions assigned to each application team.

Which is the easiest and least expensive way to satisfy these requirements?

A. Use dedicated Supervisor Cluster per application
B. Use dedicated vSphere Namespace per application
C. Use dedicated vSphere Pod per application
D. Use dedicated Kubernetes Deployments per each application

Correct Answer: B


Which prerequisite must be configured before starting the Tanzu workload management enablement wizard?

A. Content library
B. Tanzu Mission Control
C. Storage policy
D. Tanzu Build Service

Correct Answer: A


Which method is supported to change the Kubernetes version for Tanzu Kubernetes clusters on VMware vSphere with

A. Upgrade by incremental Kubernetes version e.g. 1.17 to 1.18
B. Change the major version, e.g. from v1.18 to v2.0
C. Decrease Kubernetes version e.g. 1.18 to 1.17
D. Upgrade by skipping Kubernetes version e.g. 1.16 to 1.18

Correct Answer: A


A Tanzi Mission Control administrator would like to enforce the following container controls:
Require Digest. Name-Tag Allowlist. To which type of policies do these controls belong?

A. Security
B. Registry
C. Access
D. Network

Correct Answer: B


A customer needs to use Kubernetes and wants to use a networking solution, Andrea. Which product from the Tanzu portfolio should the customer use?

A. Tanzu Application Catalog
B. Tanzu Kubernetes Grid
C. Tanzu Mission Control
D. Tanzu Observability

Correct Answer: B


What command would an administrator use to upgrade the Tanzu Management Cluster?

A. apt-get install -y kubeadm
B. tkg management-upgrade
C. tanzu-upgrade-mgt
D. tkg upgrade management-cluster

Correct Answer: D


Which is the correct statement describing the characteristic of a pod?

A. Pod is the smallest entity managed by Docker.
B. Pod can contain only one container.
C. Containers in a pod start and stop together.
D. Pod is deployed directly on the virtual machine.

Correct Answer: C

Question # 1

On which platform is CloudBase-Init used to execute user-provided scripts? (Choose the best answer.)

A. Linux
B. MacOS
C. Kubernetes
D. Windows

Correct Answer: D

Question # 2

An administrator creates multiple flavor mappings and names them as follows:
Small: vCenter / Datacenter:datacenter-1 – cpu = 1, memory = 2 GB AWS-West-1 / us-west-1 = t2.micro
Medium: vCenter / Datacenter:datacenter-1 – cpu = 2, memory = 4 GB AWS-West-1 / us-west-1 = t2.small
Where would the administrator use those named mappings to allow users to select image sizes? (Choose the best

A. Cloud zones
B. Projects
C. Cloud templates
D. Custom forms

Correct Answer: B

Question # 3

An administrator will use the vRealize Automation Code Stream Smart Templates to trigger pipeline testing when there
are code changes in GitHub.

Which template should the administrator use? (Choose the best answer.)

A. Continuous Delivery
B. Cloud Template
C. Blank Canvas
D. Continuous Integration

Correct Answer: D

Question # 4

The administrator is tasked with creating a number of different content sources in Service Broker so that multiple types
of catalog, items can be created.

What is the only public cloud template that can be selected as a content source in Service Broker? (Choose the best

A. Google Cloud Deployment Manager templates
B. Alibaba Cloud Resource Orchestration Service templates
C. AWS CloudFormation templates
D. Azure Resource Manager (ARM) templates

Correct Answer: C

Question # 5

An administrator configured flavor mapping for use in a multi-tier application cloud template.
What are the sizing options allowed in vSphere when creating a new flavor mapping? (Choose the best answer.)

A. Number of CPUs only
B. Memory and number of CPUs
C. Disks only
D. Memory only

Correct Answer: B

Question # 6

Refer to the exhibit.

An administrator is testing a newly created Windows 2016 cloud template in Cloud Assembly. While using the Test
option from within the cloud template, the attached error appears.

What is a possible cause for this error message? (Choose the best answer.)

A. During the machine allocation phase, Cloud Assembly could not find enough resources.
B. The network profile created did not have the correct capability tag.
C. The administrator did not associate a cloud zone to the project.
D. The administrator did not add a cloud account.

Correct Answer: C

Question # 7

What is the purpose of a cloud zone? (Choose the best answer.)

A. A cloud zone is used to segregate resources for provisioning within a cloud account.
B. A cloud zone is a method of connecting to a type of resource provider.
C. A cloud zone is a simplified user interface for users who do not need full access to developing and building cloud
D. A cloud zone is used for organizing users and groups.

Correct Answer: A

Question # 8

An administrator is debugging a multi-machine cloud template deployment and the following error occurs:
“Customization operation failed. Customization specification with name [vCenter_Windows] was not found.”

Where can the administrator identify the phase of the provisioning lifecycle and the machine for which this error
occurred? (Choose the best answer.)

A. Deployments > History
B. Deployments > Topology
C. Cloud Assembly > Design
D. Service Broker > Deployments

Correct Answer: A

Question # 9

Refer to the exhibit.

A new vRealize Automation user is logging in for the first time. Upon login, the user is presented with the attached

Which step must the Organization Administrator take to resolve the issue? (Choose the best answer.)

A. Assign the user a Content Developer role
B. Assign the user the Directory Administrator role
C. Assign the user the Organization Member role
D. Assign the user a Service role

Correct Answer: D

Question # 10

Refer to the exhibit.

An administrator receives the error in the attached screenshot when attempting to add a cloud account. What is a
possible cause of this error? (Choose the best answer.)

A. The username and password are incorrect.
B. The hostname uses a URL instead of an IP address/FQDN.
C. There is an invalid certificate for the vCenter.
D. A Cloud account exists with the same name.

Correct Answer: B

Question # 11

What are two prerequisites for a vRealize Automation standard deployment? (Choose two.)

A. IPv4 addresses
B. DHCP server
C. IPv6 addresses
D. Load Balancer
E. DNS server

Correct Answer: AE

Question # 12

What is the main difference between vRealize Orchestrator non-persistent logs and persistent logs? (Choose the best

A. Time Synchronization of logs
B. Storing of events in the database
C. Log Insight forwarding configuration
D. Logging level configuration

Correct Answer: B


5V0-21.21Q&As – VMware HCI Master Specialist Dumps


An architect is designing for a production vSAN cluster, and the customer introduced these requirements
related to File Services: A minimum of 12 files were shared. 30TB NFS capacity to mount workload VMs.
What should be the architect\\’s recommendations?

A. Point out the risks regarding putting the hosts in maintenance mode in terms of FSVM.
B. Confirm all of the requirements and move forward with the physical design.
C. Raise concerns regarding support when running VMs on an NFS share as risk.
D. Highlight the required number of nodes required for the vSAN cluster as a constraint.

Correct Answer: D


An 8-Node vSAN Stretched Cluster (4+4+1) with a single disk group has a policy with PFTT=1 (mirrored
across sites) and SFTT=1/FTM Mirroring (Local Protection) configured.

The administrator has been alerted that there is a problem with the cluster. The following has been

The vSAN Witness Host is offline.
Two disk failures on two hosts have occurred in the preferred site.
This has resulted in a critical production virtual machine\\’s vodka becoming inaccessible.

Which step needs to be performed by the administrator to resolve the issue?

A. Replace all failed disks on the preferred site.
B. Replace the vSAN Witness Host
C. Replace access to the existing vSAN Witness Host
D. Replace only one failed disk on the preferred site.

Correct Answer: C


Which statement accurately describes the result when proper VM Storage Policy Affinity Rules on a stretched vSAN
cluster is set?

A. When a site is disconnected, the VM will lose access to its VMDK.
B. When a site is disconnected, the VM will continue to have access to its VMDK.
C. Bandwidth is unnecessarily sent across the inter-site link.
D. Proper policies result in higher inter-site bandwidth utilization.

Correct Answer: A


A company hosts a vSAN 7 stretched cluster for all development workloads. The original sizing of a maximum of 250
concurrent workloads in the vSAN cluster are no longer sufficient and need to increase to at least 500 concurrent
workloads within the next six months.

To meet this demand, the original 8-node (4-4-1) cluster has recently been expanded to 16 nodes (8-8-1).
Which three additional steps should the administrator take to support the current growth plans while minimizing the
number of resources required at the witness site? (Choose three.)

A. Add the new vSAN witness appliance to the vCenter Server.
B. Deploy a new large vSAN witness appliance at the witness site.
C. Configure the vSAN stretched cluster to use the new vSAN witness.
D. Deploy a new extra-large vSAN witness appliance at the witness site.
E. Upgrade the vSAN stretched cluster to vSAN 7.0 U1.
F. Configure the new vSAN witness as a shared witness appliance.

Correct Answer: BCF


A 30-minute power maintenance window has been approved on Sunday. Due to a delay, the maintenance took 20
minutes longer to finish.

During this time, the vSAN administrator noticed that one of the nodes of the cluster was affected by a power shortage, as it was connected to an affected power source. The default vSAN storage policy has been applied.
What will be the status of the vSAN objects on the affected host immediately after it is recovered?

A. The cluster will be partitioned and the vSAN host will need to be rejoined.
B. A rebuild of the affected objects will occur.
C. All objects will remain accessible.
D. All objects on the affected host will be lost.

Correct Answer: B


During a planning session for new vSAN clusters in multiple data centers, the customer relayed the following

Highest possible mitigation during a host failure in terms of capacity. A constraint in this year\’s IT budget.
What should the architect recommend?

A. Enable operations reserve. A minimum cluster of 3 vSAN nodes.
B. Enable host build reserve. A minimum cluster of 4 vSAN nodes.
C. Enable performance services. A minimum cluster of 6 vSAN nodes.
D. Enable IOInsight Metrics. A minimum cluster of 2 vSAN ROBO nodes.

Correct Answer: B


An administrator is tasked with preparing for a Cross vCenter migration in a stretched vSAN cluster where the virtual
machines migration will be orchestrated via VMware Site Recovery Manager.

Which action should the administrator take so the migration is successful?

A. Disable vSAN Deduplication and Compression
B. Reconfigure vCenter HA Admission control
C. Enable vCenter Single Sign-On Enhanced Linked Mode
D. Make sure that Witness traffic is on the management NIC.

Correct Answer: C

Reference: https://docs.vmware.com/en/Site-Recovery-Manager/8.4/com.vmware.srm.admin.doc/GUIDB64096E8-F49A-4BF6-92CE-05FBA972F3C0.html


An administrator is tasked with setting up Kerberos authentication only for the vSAN File services.
Which version of Kerberos must be selected if the NFS version is v4.1?

A. krb5i
B. krb4
C. krb5
D. krb5p

Correct Answer: A

Reference: https://core.vmware.com/resource/best-practices-running-nfs-vmware-vsphere


An administrator is planning to change a vSAN Storage Policy to apply a Failures To Tolerate (FTT) of 2, using RAID-6.
What is the minimum number of vSAN nodes required?

A. 6
B. 4
C. 5
D. 8

Correct Answer: A

Reference: https://docs.vmware.com/en/VMware-Cloud-on-AWS/services/com.vmware.vsphere.vmc-aws-manage-datacenter-vms.doc/GUID-EDBB551B-51B0-421B-9C44-6ECB66ED660B.html


An architect needs to automate an infrastructure that supports VMware Horizon as well as VMware Tanzu. Which
solution mandates the use of VMware vSAN?

A. VMware Cloud Foundation
B. VMware Horizon
C. VMware Tanzu
D. VMware vRealize Automation

Correct Answer: D

Reference: https://www.vmware.com/products/vrealize-automation.html


An architect collected the below technical requirements from the customer during a vSAN cluster design

Maximize the vSAN datastore usable capacity.
Deduplication and compression are required to help utilize available capacity efficiency.
Ensure the highest level of resiliency wherever possible.

Which disk group configuration should the architect include in the design?

A. One disk group per host, with one cache tier flash disk and four capacity tier, flash disks.
B. Two disk groups per host, each with one cache tier flash disk and four capacity tier flash disks.
C. Two disk groups per host, each with one cache tier flash disk and six capacity tier flash disks.
D. Two disk groups per host, each with one cache tier flash disk and six capacity tier magnetic disks.

Correct Answer: D


A company has engaged a consultant to upgrade an existing vSAN cluster to vSAN 7.0 U1.
During the discovery phase, the consultant found the following information about the existing environment:

The VMware vCenter Server has recently been upgraded from VMware vSphere 6.7 U3 to version 7.0 U1.
The vSAN Cluster was recently expanded with identical hardware specifications but from a different hardware vendor.
The hardware for each vSAN node is listed on the vSAN Compatibility Guide (VCG) for vSAN 7.

The vSAN Cluster has the following configuration:

-vSAN version: 6.6.1
-Number of vSAN nodes: 10
-Encryption: enabled
-Deduplication and Compression: enabled
-vSAN Capacity Utilization: 60%

Each vSAN node has the following configuration:

-VMware vSphere ESXi version: 6.5 Update 3
-CPU: 2 processors, 20 cores
-RAM: 768GB RAM.
-Disk: 2 Cache SSDs and 6 Capacity SSDs
-Network: 4 x 10GbE

Which three recommendations should the consultant make to ensure all data remains protected in the event of a vSAN
failure? (Choose three.)

A. The Full data migration maintenance mode option must be chosen to protect the data during the upgrade.
B. The Ensure accessibility, migration maintenance mode option must be chosen to protect the data during the
C. The upgrade process should be completed using host upgrade baselines in VMware vSphere Lifecycle Manager
D. The vSAN nodes should be upgraded to vSphere ESXi 7.0 U1.
E. The upgrade process should be completed using images in VMware vSphere Lifecycle Manager (vLCM).
F. The vSAN nodes should be upgraded to vSphere ESXi 6.7 U3.

Correct Answer: BDE


An administrator managing a vSAN cluster of six nodes with policy FTT-2/RAID-6 decided to put one of the nodes in
maintenance mode using the “Full-data migration” option.

What will happen after this action is taken?

A. The host will enter in maintenance mode and the data will remain accessible until the host exits maintenance mode.
B. The system will prompt to add an additional host to the cluster in order to preserve the policy compliance.
C. The host will enter in maintenance mode and only data with no redundancy will remain accessible.
D. The host will enter into maintenance mode if both components of a certain object are residing on that host, then one of the components will be moved to another available host.

Correct Answer: A

Reference: https://blogs.vmware.com/virtualblocks/2020/02/06/what-happens-vsan-host-in-maintenancemode/

An architect is designing a new vSphere environment with the following resources:

  • 600 vCPU
  • 5,760 GB RAM
  • Average resource usage is:
  • 60 vCPU
  • 1,152 GB RAM

The design must meet the following requirements:

  • The environment has the ability to burst by 25%.
  • Each host can schedule 36 vCPUs and has 512 GB RAM.
  • Management overhead is 20%.

What is the minimum number of hosts required to meet the design requirements?

A. Three
B. Five
C. Four
D. Two

Correct Answer: D


The Chief Operating Officer (COO) at an organization raises concerns that their virtual infrastructure environment is
vulnerable. Recently, a security-related issue with a virtual machine caused all management services to become
unavailable. No budget is available in the short term for additional platform investment. An architect is asked to review
the current environment and make recommendations to mitigate concerns.

A virtualization administrator has provided the following details: There is a single four-node cluster of ESXi servers
There are two, Layer 2, physical network switches connecting resources The data center network is presented as a
single /16 subnet Given the information provided, which functional requirement should the architect include in the design to mitigate the Coo’s concerns?

A. The virtual infrastructure environment must connect application virtual machines and management services to new
physical network switches
B. The virtual infrastructure environment must connect application virtual machines and management services to
separate distributed virtual switches (DVS)
C. The virtual infrastructure environment must connect application virtual machines and management services to
separate VLANs
D. The virtual infrastructure environment must connect management services to a vSphere standard switch (VSS)

Correct Answer: D


An architect is tasked with designing a new VMware software-defined data center (SDDC) solution for an
an online retail customer who has a primary and secondary data center as well as 10 distribution hubs.
The customer has provided the following business requirements to help inform the design:

The solution must support the running of up to 1,000 concurrent virtual machines across the primary and
secondary data center.

The solution must support the running of up to 20 concurrent virtual machines in each distribution hub.
The solution must support the separation of management and lines-of-business application virtual

All management components (including directory services, backup, automation, operations, and logging)
must be deployed to the primary data center.

All virtual infrastructure components must have redundancy of N+1.
All sites are connected to each other using a wide area network that has multiple diversely routed links.

The solution should support a monthly uptime target of 99.9%.
The recovery time objective (RTO) for the solution must be four hours.
The recovery point objective (RPO) for the solution must be 24 hours.

Given the information from the customer, which assumption should the architect include in the design?

A. All business application virtual machines can be deployed into a single cluster within the primary data center.
B. Each distribution hub should be configured with a backup device.
C. The wide area network has sufficient bandwidth to support centralized management.
D. Each cluster will have a minimum of four hosts.

Correct Answer: B


A new real-time financial service application is being developed by the engineering team at a financial firm and will be
released as a public Software-as-a-Service (SaaS) offering. The solutions architect has designed and deployed a new
vSphere environment and the supporting network infrastructure for hosting all public services.

ESXi hosts are configured to use Precision Time Protocol (PTP) and a local stratum-1 network time server. Application provisioning and scaling will be managed by VMware vRealize Automation and can be run on Microsoft Windows or multiple distributions of Linux.

Which three recommendations should the architect include in the design to ensure that the service maintains timekeeping within an accuracy of one second? (Choose three.)

A. Use Microsoft Windows Server as the guest operating system.
B. Configure the chrony time-sync agent on each virtual machine guest operating system.
C. Set the virtual hardware device to use Host System Time (NTP) for each virtual machine running the application.
D. Add a precision clock virtual device to each virtual machine running the application.
E. Use a Linux distribution as the guest operating system.
F. Add a virtual watchdog timer (VWDT) device to each virtual machine running the application.

Correct Answer: ABC


During a requirements gathering workshop, the customer provides the following information:
Each host has 2 × 10 GbE NIC EtherChannel is not currently configured No changes can be made to the physical
network Network throughput must be prioritized for defined critical services
Which two recommendations should the architect make with regard to virtual networking? (Choose two.)

A. Use Route Based on Physical NIC Load.
B. Use Network I/O Control with Shares.
C. Use Network I/O Control with Reservation.
D. Use Link Aggregation Control Protocol (LACP).
E. Use Network I/O Control with Limits.

Correct Answer: AD

Reference: https://docs.vmware.com/en/VMware-vSphere/6.5/vsphere-esxi-vcenter-server-65-networkingguide.pdf


An architect is designing a VMware software-defined data center (SDDC) solution based on the following customer
requirements: The solution must initially support 1,000 virtual machines The solution must scale to support the
concurrent running of up to 5,000 virtual machines The production environment should be delivered across two data
centers The solution should have a maximum tolerable downtime (MTD) of four hours The solution should have a
monthly service availability target of 99.8%

Which two assumptions could the architect make based on the information from the customer to help size the solution? (Choose two.)

A. The number of vSphere hosts in a cluster
B. The average resource utilization of a virtual machine
C. The size (CPU/RAM/storage) of the average virtual machine
D. The guest operating system for each virtual machine
E. The size (CPU/RAM/storage) of the vSphere hosts

Correct Answer: AE


A VMware Service Provider is tasked with delivering a solution for continuous availability for a subset of Tier 1 virtual
machines (VMs) and vApps running in their vSAN environment. The VMs make up a mission-critical application and
there can be no data loss in the event of an outage at their primary data center.

In the event of a regional outage, they have established a 10-minute recovery point objective (RPO). Failover/ failback to the third side must be automated.

They have the following in place:
Two local data centers (primary and secondary) connected with 100 Gb dedicated fiber

-2ms round-trip time (RTT) latency between the sites A third data center located on another power grid
-70ms latency between the primary and secondary data centers Matching storage arrays at all locations

Which two solutions could be used to meet the requirements? (Choose two.)

A. Site Recovery Manager
B. Snapshots
C. vSAN Metro Cluster
D. vSphere Data Protection
E. vStorage APIs for Array Integration (VAAI)

Correct Answer: BC


During a requirements gathering workshop, the customer provides the following requirement that is
pertinent to the design of a new vSphere environment:

The Maximum Tolerable Downtime (MTD) for all Tier 1 applications is one hour.
Which requirement classification is being gathered for the design documentation?

A. Manageability
B. Performance
C. Availability
D. Recoverability

Correct Answer: C


Following a recent acquisition, an architect needs to merge IT assets into its current data center. The
combined vSphere environment will need to run the newly acquired company\’s virtual machines.

Network integration work has already been completed and the current environment has the capacity to host all
virtual machines. The Operations team needs to identify which virtual machines belong to the acquired
company and report on their usage.

How should the architect merge the company\’s assets and virtual machines?

A. Leave the newly acquired company\’s assets in their current place
B. Lift and shift the acquired assets into the data center
C. Migrate the acquired company\’s virtual machines into the existing vSphere environment
D. Migrate and apply vSphere tags to the acquired company\’s virtual machines

Correct Answer: D


An architect is tasked with expanding an existing VMware software-defined data center (SDDC) solution so that it can
be used to deliver a virtual desktop infrastructure (VDI) service off-shore development activities.

The production environment is currently delivered across two geographically dispersed data centers. The two data
centers are currently connected to each other through multiple diversely routed, high bandwidth, and low latency links.
The current operations management components are deployed to a dedicated management cluster that is configured
with N+1 redundancy.

The current VMware software-defined data center (SDDC) has a monthly availability target of
99.5%, which includes all management components.

The customer requires that the new solution scale support the concurrent running of 500 persistent virtual desktops.
The virtual desktops must not share the same virtual infrastructure as existing virtual machines, but can be managed
using the same VMware operations management components.

Any new VDI service management components must be installed into the management cluster. There is no requirement to back up the virtual desktops because all relevant user data is stored centrally. The VDI service is providing business-critical services and must have an availability target of 99.9%. Given the information from the customer, which two assumptions would the architect include in the design? (Choose two.)

A. The existing virtual infrastructure has sufficient capacity to host the new VDI workloads
B. The existing operations monitoring tools have sufficient capacity to monitor the new VDI services
C. The existing management cluster has enough available capacity to host any VDI service management component
D. The management cluster has N+1 redundancy
E. The VDI service has a higher service-level agreement (SLA) than the operations management SLA

Correct Answer: AB


An architect has 50 ESXi hosts to deploy and DHCP servers are not allowed on any network. Which automated host
deployment method should the architect use?

A. Stateless vSphere Auto Deploy
B. Stateful vSphere Auto Deploy
C. Scripted installation
D. Interactive installation

Correct Answer: C


During a requirements gathering workshop to design a physical to virtual migration, the customer provides
the following information:

There is no physical firewall in the data center with no anticipated plans for a future network refresh.
Leveraging the virtual infrastructure to mitigate the lack of network security must be addressed in the

All physical servers to be migrated exist on the same VLAN.
Which recommendation should the architect make to address the customer requirement with regard to
virtual networking?

A. Split the virtual machines into several VLANs Use tag actions
B. Create port groups with different names and the same VLAN IDs Enable traffic shaping for ingress and egress traffic
C. Enable traffic filtering and marking Use allow or drop actions
D. Disable traffic filtering and marking Use tag actions

Correct Answer: A


An architect is tasked with planning the design of a new vSphere environment. When commissioned, this environment
will be used to migrate an existing set of virtual machines.

An inventory of the existing infrastructure, including configured vCPU, RAM, and storage sizes has been provided.
In order for each virtual machine to be migrated, which two data sources with peak and average utilization data are
required for sizing? (Choose two.)

A. %Ready
B. Disk Write latency
D. Ballooned memory

Correct Answer: BE

Here are good free VMware 1V0-81.20 exam dumps practices:

Practice, practice, practice, VMware 1V0-81.20 practice test

Take the mock exam and review the answers to the questions you missed. Practice the questions to identify your weaknesses so you can focus on your learning.


When using VMware Carbon Black Live Response, what command will show all active processes?

A. dir
B. list
C. ls
D. ps


Which two are true about a VMware Service-defined Firewall? (Choose two.)

A. A firewall that allows you to use 3rd party features like IDS/IPS, threat protection, anti-bot, and anti-virus solutions
B. A firewall that blocks external access into your internal network based on IP services
C. A firewall that enforces policy for North-South traffic
D. A firewall that is auto-scalable as new workloads are deployed
E. A firewall that provides East-West protection between internal applications


Which VMware Carbon Black Cloud function allows an administrator to remotely run commands on protected

A. Live Query
B. Alert Triage
C. Investigate
D. Live Response


What is the term used to describe a type of social engineering attack aimed at a specific person or specific type of

A. Phishing
B. Whaling
C. Tailgating
D. Spear Phishing


Which option would be considered an example of a Hardware-Based Exploit?

A. SQL Injection
B. Social Engineering
C. Jail Breaking
D. Denial of Service


If the Compromised Protection switch is enabled in Workspace ONE UEM, what is the expected behavior on
compromised devices in the environment?

A. A tag is assigned to the compromised devices and the admin gets a notification
B. Compromised devices are automatically Enterprise Wiped
C. A block is set for all network connections except to the VMware servers
D. Devices are marked as non-compliant and the admin gets a notification


Which Workspace ONE feature incorporates network range, device platform, and authentication method into the decision-making when evaluating an access request from a user?

A. Sensors
B. Compliance Policies
C. Access Policies
D. Restriction Profiles


When filtering firewall rules after selecting an object to filter by, which four columns do the filter search? (Choose

A. Services
B. Action
C. Protocol
D. Log
E. Applied To
F. Source
G. Destinations


Drag and drop the Cyber Kill events on the left into their proper sequential order on the right.
Select and Place:

Correct Answer:


Refer to the exhibit.
When attempting to run the recommended query for all Authorized SSH Keys in an organization, you see this view in
the console.

Why are you not able to run the query?

A. You must schedule the query first before you can run the query
B. The policy Windows Endpoints have no devices
C. You need the ‘Use Recommended Query’ permission set in your role
D. There are no Mac or Linux sensors in the selected policy


Which three common mitigations for social engineering attacks? (Choose three.)

A. user training
B. filtering Email attachments
C. update Antivirus software
D. remove applications
E. blocking the execution of suspicious files


Which is a common solution to implement for inbound network attacks?

A. Load Balancer
B. Firewall
C. Proxy
D. Reverse Proxy


Which parameter ensures an endpoint will stay connected with the designated VMware Carbon Black Cloud tenant?

A. Company Code
B. Organization Group ID
C. Device Serial Number
D. User ID

You need to start preparing for the VMware 2V0-62.21 exam by obtaining the 2V0-62.21 dumps pdf of Pass4itSure. The famous 2V0-62.21 exam dumps provided by Pass4itSure is one of the top VMware 2V0-62.21 exam questions, confirmed by the VMware expert team. Full 2V0-62.21 exam questions answers https://www.pass4itsure.com/2v0-62-21.html (2V0-62.21 PDF and 2V0-62.21 VCE) Make sure you can successfully pass the 2V0-62.21 exam.

Free VMware 2V0-62.21 PDF from Drive

VMware 2V0-62.21 PDF from Drive
Free downloadhttps://drive.google.com/file/d/1Q4OxrLLuw5UbLDFev-XTCHydxKxzEqy2/view?usp=sharing

Start! VMware 2V0-62.21 exam questions answers free

An administrator would like to customize their admin consoles default branding to include the company logo and reflect
the company\\’s text color and background.
How would the administrator accomplish this task?
A. Navigate to UEM Console, All Settings, System, Branding. Click Branding and edit the settings in the Branding page
as appropriate.
B. Navigate to the Configurations tab on the console. Click Branding. Edit the settings in the Branding page as
C. Navigate to the Hub Service console Home page. Click Branding. Edit the settings in the Branding page as
D. Navigate to UEM Console, All Settings, Hub Services. Click Branding and edit the settings in the Branding page as
Correct Answer: A

An administrator is tasked with determining the root cause for a recent outage where devices were not able to
authenticate. An investigation revealed a single AirWatch Cloud Connector (ACC) server that had a disk error which
caused it to be completely unresponsive.
Which VMware resiliency recommendation would have prevented this outage?
A. High Availability
B. Disaster Recovery
C. Cloud Hosted ACC
D. Restart ACC
Correct Answer: A

Which three Workspace ONE Edge Services are included in Unified Access Gateway? (Choose three.)
A. AirWatch Cloud Connector
B. Content Gateway
C. Secure Email Gateway
D. Workspace ONE Intelligence Connector
E. VMware Tunnel
Correct Answer: BCE

A customer has decided to use VMware Workspace ONE as their primary SAAS solution for endpoint management.
The customer\\’s security team requires all infrastructure to support High Availability (HA).
Which two components of Workspace ONE will need to be maintained by the customer? (Choose two.)
A. AirWatch Cloud Connector
B. Workspace ONE Database
C. Console Services Servers
D. Unified Access Gateway
E. Device Services Server
Correct Answer: AD

Which is required during installation of the Workspace ONE Intelligence Connector service?
A. Workspace ONE Intelligence Connector service must be installed on the AWCM Server.
B. Workspace ONE Intelligence Connector must be installed on the Console Server.
C. Workspace ONE Intelligence Connector service must be installed on the Device Services Server.
D. Workspace ONE Intelligence Connector must be installed on its own server.
Correct Answer: D
Reference: https://docs.vmware.com/en/VMware-Workspace-ONE/services/intelligencedocumentation/GUID-04_intel_reqs.html

As a Workspace ONE administrator, you have been tasked with creating a custom visualization for management that
shows device statistics, trust network threats, and application adoption metrics in a single view.
Which feature of Workspace ONE can be used?
A. Workspace ONE Intelligence Dashboards
B. Workspace ONE Access Application View
C. Workspace ONE Intelligence Automations
D. Workspace ONE UEM Device List View
Correct Answer: A
Reference: https://techzone.vmware.com/resource/workspace-one-intelligence-architecture#workspace-one-uem

Which feature of Workspace ONE UEM can be configured to allow reports to run on a schedule and have them
delivered to a subset of administrators?
A. Windows Scheduled Tasks
B. Report Subscriptions
C. Timed Report Execution
D. SQL Server Reporting Services
Correct Answer: B

Which of the following is a prerequisite to deploy VMware Unified Access Gateway OVF?
A. VMware vSphere
B. VMware Workstation
C. VMware Fusion
D. VMware Horizon
Correct Answer: A
Reference: https://docs.vmware.com/en/Unified-Access-Gateway/3.5/com.vmware.uag-35-deployconfig.doc/GUID-13DCCA35-8620-4F4C-8FBC-6916396221AD.html

An administrator would like to import Public Applications acquired from the Microsoft Store for Business. Which
configuration is required?
A. LDAP Active Directory Integration
B. SAML Authentication
C. Two Factor Authentication
D. Azure Active Directory Integration
Correct Answer: D
Reference: https://docs.vmware.com/en/VMware-Workspace-ONEUEM/2008/Application_Management_Windows/GUID-AWT-WIN-BSP-IMPORT.html

Which type of design is a diagram that includes network zones, network components, server locations, and hardware
A. Physical
B. Logical
C. Theoretical
D. Conceptual
Correct Answer: A

You are an administrator configuring custom reports in Workspace ONE Intelligence.
What is the maximum number of custom reports you can create per Organization Group (OG)?
A. 10
B. 50
C. 99
D. 500
Correct Answer: B

Which two statements are true about Content Gateway and Tunnel on Unified Access Gateway? (Choose two.)
A. Both can be configured with the same hostname on port 8443.
B. Both can be configured with the same hostname on different ports.
C. Both can be configured on port 8443 with different hostnames.
D. Both can be configured with the same hostname on port 443.
E. Both can be configured on port 443 with different hostnames.
Correct Answer: BE

A customer intends to implement Android device management in their environment.
Which three enrollment options would result in an end-user experience in which a dedicated container is created on the
device for only business applications and contents? (Choose three.)
A. Knox Container
B. Device Enrollment Program (DEP)
C. Work Managed Device
D. Legacy enrolled
E. Corporate Owned Personally Enabled (COPE)
F. Work Profile
Correct Answer: CEF

In short, the VMware 2V0-62.21 dumps provided by Pass4itSure are perfect for the 2V0-62.21 exam. Come and start 2V0-62.21 exam questions answers https://www.pass4itsure.com/2v0-62-21.html (Q&As: 60). Pass4itSure 2V0-62.21 dumps are the true VMware certification exam for every IT professional.

Which three solutions does the software-defined data center (SDDC) help build? (Choose three.)
A. Native cloud
B. Secure cloud
C. Hyperscale
D. Hybrid cloud
E. On premises
F. Public cloud
Correct Answer: DEF
Reference: https://www.vmware.com/solutions/software-defined-datacenter/in-depth.html#delivery-options

Which plane is responsible for creating and deleting network objects in the NSX-T Data Center Architecture?
A. Control Plane
B. Data Plane
C. Life Cycle Plane
D. Management Plane
Correct Answer: D

A customer needs to manage and extend their data center network into VMware Cloud on AWS and Microsoft Azure
Which VMware product should the customer use?
A. NSX Cloud
B. NSX Intelligence
C. vCloud Director Extender
D. vRealize Network Insight Cloud
Correct Answer: A
Reference: https://www.vmware.com/products/nsx-cloud.html

How can NSX-T Distributed Firewall help customers achieve security for newly migrated containerized applications?
A. Quality of service
B. Micro-segmentation
C. Dynamic routing
D. Network I/O control
Correct Answer: B
Reference: https://blogs.vmware.com/networkvirtualization/2020/04/nsx-t-3-0.html/

A customer is implementing a proof of concept for vSphere and wants to enable features such as HA, vMotion and
Which component is required to enable these features?
A. vCenter Server
B. vSphere Client
C. SAN Storage
D. Distributed Switch
Correct Answer: A
Reference: https://docs.vmware.com/en/VMware-vSphere/6.0/vsphere-esxi-vcenter-server-601-resourcemanagementguide.pdf

Which product in the virtual infrastructure layer of the SDDC provides network virtualization capabilities?
A. VMware NSX
B. VMware vSphere
C. VMware vRealize Network Insight
D. VMware vSAN
Correct Answer: A
Reference: https://docs.vmware.com/en/VMware-Validated-Design/5.0/com.vmware.vvd.sddc-design.doc/GUID-2E9FE367-8295-49CB-9C21-B615B543D705.html

Which component is required to use VMware Distributed vSwitches (vDS)?
A. VMware NSX-T
B. VMware SD-WAN
C. VMware Identity Manager
D. VMware vCenter Server
Correct Answer: A
Reference: https://www.altaro.com/vmware/vsphere-distributed-switch-guide/

A customer needs multi-cloud load balancing, web application firewall, and container ingress services across onpremises data centers and any cloud.
Which product meets this customer\\’s needs?
A. VMware HCX
B. NSX Advanced Load Balancer
C. NSX Cloud
D. NSX Distributed IDS
Correct Answer: B
Reference: https://www.vmware.com/products/nsx-advanced-load-balancer.html

What is the benefit of connecting segments to Tier-1 Gateways?
A. Enhanced cloud consumption model
B. Enhanced micro-segmentation model
C. Enhanced East/West communication
D. Enhanced North/South communication
Correct Answer: C
Reference: https://www.vgarethlewis.com/2019/12/17/vmware-nsx-t-logical-routing-part-1-tier-1-gateway/

Given this exhibit:

1V0-41.20 exam questions-q10

Which statement is true about the firewall rule?
A. It is a distributed firewall applied to App-Servers, DB-Servers and Web-Servers that rejects traffic on port 22.
B. It is a gateway firewall applied to a Tier-1 gateway that rejects traffic on port 22.
C. It is a distributed firewall applied to App-Servers, DB-Servers and Web-Servers that drops traffic on port 22.
D. It is a gateway firewall applied to a Tier-0 gateway that drops traffic on port 22.
Correct Answer: C

Which security services are natively provided by NSX-T Data Center?
A. Network introspection
B. Endpoint protection
C. Distributed IDS
D. Anti-virus protection
Correct Answer: B

How does virtual networking enable business to reduce time-to-market?
A. By performing automatic hardware upgrades
B. By increasing traffic bandwidth
C. By removing physical network devices
D. By providing network services on demand
Correct Answer: D
Reference: https://www.vmware.com/radius/virtual-cloud-networking-10-things/

A customer has experienced a disaster.
Which statement describes a recovery benefit of a vSphere Environment with NSX Data Center?
A. NSX Datacenter enables replication between sites.
B. Workload mobility is tied to vCenter server.
C. It simplifies the DR by not requiring the change of the IP addresses of workloads.
D. It is a requirement to stretch cluster to have a DR scenario.
Correct Answer: D
Reference: https://docs.vmware.com/en/VMware-NSX-T-DataCenter/3.1/administration/GUID-5D7E3D436497-4273-99C1-77613C36AD75.html

