Winter Sale Flat 65% Limited Time Discount offer - Ends in 0d 00h 00m 00s - Coupon code: netdisc

VMware 3V0-25.25 Advanced VMware Cloud Foundation 9.0 Networking Exam Practice Test

Page: 1 / 6
Total 60 questions

Advanced VMware Cloud Foundation 9.0 Networking Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$43.75  $124.99

PDF Study Guide

  • Product Type: PDF Study Guide
$38.5  $109.99
Question 1

An architect has just deployed a new NSX Edge cluster in a VMware Cloud Foundation (VCF) fleet. The BGP peer between the NSX Tier-0 gateway and the top-of-rack routers is successfully up and stable.

• BGP Connection is established, but the NSX Tier-0 is not receiving a default route from the top-of-rack routers.

• Workloads inside NSX have no Internet access.

What could be the solution?

Options:

A.

Tier-0 gateway community settings are missing on the top-of-rack router configuration.

B.

The top-of-rack router receives a default route from Tier-0 gateway.

C.

Tier-0 gateway has a limit set too low for how many routes it can accept.

D.

There is no default route configured on the top-of-rack router for the Tier-0 gateway.

Question 2

During a design review, the administrator is asked to explain which underlying technology enables the NSX Edge to perform fast packet processing and achieve near line-rate performance for Virtual Network Functions (VNFs). Which technology is leveraged in the NSX Edge for fast packet processing?

Options:

A.

Data Plane Development Kit (DPDK)

B.

AMD Power Now

C.

Non-Uniform Memory Access (NUMA)

D.

Intel Speed Step

Question 3

A sovereign cloud provider has a VMware Cloud Foundation (VCF) stretched Workload Domain across two data centers (AZ1 and AZ2), where site connectivity via Layer 3 is provided by the underlay. The following NSX details are included in the design:

• Each site must host its own local NSX Edge Cluster for availability zones.

• Tier-0 gateways must be configured in active/active mode with BGP ECMP to local top-of-rack switches.

• Inter-site Edge TEP traffic must not cross the inter-DC link.

• SDDC Manager is used to automate NSX deployment.

During deployment of the Edge Cluster for AZ2, the SDDC Manager workflow fails because the Edge transport nodes' TEP IPs are not reachable from the ESXi transport nodes. Which step ensures correct Edge Cluster deployment in multi-site stretched domains?

Options:

A.

Disable the liveness check during Edge deployment in SDDC Manager.

B.

Configure BGP neighbors before deploying the Edge Cluster.

C.

Reuse the TEP IP pool from AZ1.

D.

Create an AZ2-specific Edge TEP IP pool and map it to the AZ2 uplink profile before deploying the Edge Cluster.

Question 4

An administrator was asked to explain the characteristic and requirements of Centralized Connectivity Mode which is planned to be configured in one of the workload domains in

VMware Cloud Foundation (VCF) environment.

Drag and drop four options from the Options list on the left and place them into the Centralized Connectivity Mode on the right in any order. (Choose four.)

Options:

Question 5

An administrator is tasked to enable users to configure an individual VPC, but not create subnets. What three NSX roles would the administrator assign to allow access without the ability to create subnets? (Choose three.)

Options:

A.

Security Admin

B.

Network Admin

C.

VPC Admin

D.

Security Operator

E.

Network Operator

Question 6

An administrator changed the SFTP server used for scheduled NSX Manager backups. The backup jobs now fail with the error "Host KEY Verification Failed." The connectivity and credentials are correct. How would an administrator resolve the error?

Options:

A.

Turn Off Backup encryption.

B.

Update the SSH fingerprint.

C.

Trust the certificate on the SFTP server.

D.

Use the NSX cluster VIP as the SFTP endpoint.

Question 7

A cloud service provider runs VPCs with differing traffic patterns:

• Some VPCs are generating high, large North/South flows.

• Most of the VPCs generate very little traffic.

The architect needs to optimize Edge dataplane resource consumption while ensuring that noisyVPCs do not impact others.

Which optimization satisfies the requirement?

Options:

A.

Assign one dedicated Edge node per high-traffic VPC.

B.

Reduce the number of VPCs by consolidating VPCs into shared namespaces.

C.

Convert high-traffic VPCs into VLAN-backed segments attached directly to Tier-0 gateways.

D.

Use multiple Edge clusters and distribute VRF-backed VPCs based on traffic profiles.

Question 8

An administrator is enabling IPv6-to-IPv4 communication for workloads hosted in an NSX environment. The workloads use IPv6-only addressing, but the external systems they must reach are IPv4-only. To provide this translation service, the administrator decides to configure NAT64. Which two following characteristics about NAT64 are true? (Choose two.)

Options:

A.

NAT64 is stateless and requires gateways to be deployed in active-standby mode.

B.

NAT64 requires the Tier-1 gateway to be configured in active-standby mode.

C.

NAT64 is supported on Tier-1 gateways only.

D.

NAT64 is supported on Tier-0 and Tier-1 gateways.

E.

NAT64 requires the Tier-1 gateway to be configured in active-active mode.

Question 9

An administrator is responsible for a VMware Cloud Foundation (VCF) Private Cloud. The administrator has been tasked with identifying why there is no data ingress into a

workload domain.

The workload domain has been configured with:

. A dedicated NSX Edge Cluster.

. A Tier 0 gateway.

. A Tier-1 gateway that is configured for Distributed Routing only.

. An NSX segment where a test virtual machine is located.

As part of the exercise, the administrator must map the traffic flow for data ingress into the workload domain to identify the steps that external network traffic will take to

ingress into the workload domain and reach the virtual machine.

Drag and drop the six steps from the Steps list on the right and place them in order in the Solution Steps. (Choose six.)

Options:

Question 10

An administrator is configuring NSX resource sharing to allow shared access to multiple resources in the default space.

By default, which user role owns the shared resources for the default space?

Options:

A.

Network Admin

B.

Security Admin

C.

Project Admin

D.

Enterprise Admin

Question 11

How should the Global Managers (GMs) and Local Managers (LMs) be distributed to ensure high availability and optimal performance in a multi-site NSX Federation deployment comprised of three sites? (Choose two.)

Options:

A.

Each NSX site must have its own LM cluster that reports to the GM.

B.

LMs are only needed on the primary site. Secondary sites can manage their local data plane directly via the GM.

C.

LMs should only be deployed as single nodes to reduce overhead.

D.

The GM cluster should be deployed across three sites.

E.

The GM should be a single appliance placed in a central cloud environment to simplify connectivity, relying on vSphere HA for availability.

Question 12

An administrator is responsible for the management of a VMware Cloud Foundation (VCF) Fleet that consists of two VCF instances that are located in different physical locations. The administrator has been tasked with configuring a VPN between the two locations and has been tasked with identifying the two supported NSX Gateway configurations for an IPSec VPN. Drag and drop two items from the list of Possible Configurations into the list of Supported Configurations in any order.(Choose two.)

Options:

Question 13

An architect is designing a VMware Cloud Foundation (VCF) solution. The following information was gathered during the assessment phase:

• There is a critical application used by the Finance Team.

• The critical application has an availability and recoverability SLA of 99.999%.

• The critical application is sensitive to network changes.

Which two configurations should the architect include in their design? (Choose two.)

Options:

A.

Configure multiple static routes on Tier-1 gateway.

B.

Configure Tier-0 gateway for eBGP and ECMP.

C.

Enable BFD on the Tier-0 gateway.

D.

Configure Tier-1 gateway for eBGP and ECMP.

E.

Install and configure hosts with 100Gbps physical NICs.

Question 14

An administrator is tasked to configure NSX Federation between separate VMware Cloud Foundation (VCF) Fleets. Which requirement must all sites meet before being added to a Global Manager (GM) for NSX Federation?

Options:

A.

All Sites must use the same VTEP VLAN and IP pools.

B.

All sites must use identical Tier-0 gateway BGP autonomous system numbers.

C.

All sites must be managed by the same VCF instance.

D.

All sites must have the same NSX version and build.

Question 15

An administrator has deployed a workload domain in VMware Cloud Foundation (VCF). The workload domain was deployed with NSX managers using the XL form factor. After deployment, the administrator realizes the NSX manager is oversized and needs to change to a smaller form factor. What should the administrator do to accomplish this task?

Options:

A.

Each NSX Manager must be redeployed.

B.

Each NSX manager must be resized using the API.

C.

Each NSX manager must be resized through vCenter.

D.

Each NSX manager must be rightsized using VCF Operations.

Question 16

An administrator is responsible for managing a VMware Cloud Foundation (VCF) Private Cloud consisting of a single VCF Fleet with a single Workload Domain.

The administrator has been tasked with configuring NSX to support the new Virtual Desktop Infrastructure (VDI) solution that allows users to securely access a mainframe-

based application located on the physical network. The VDI solution will use a dedicate DHCP solution for each of the the desktop pool segments and static addresses for all

VDI management components.

The administrator completes the following steps towards configuring DHCP:

1. Creates a new tier-1 gateway (vdi-tier-1) and links it to the tier-0 gateway (gw-tier-0).

2. Creates one new segment for vdi management (vdi-seg-01) and connects it to vdi-tier-1.

3. Creates two new segments for virtual desktops (vdi-seg-02 and vdi-seg-03) and connects them to vdi-tier-1.

Drag and drop the six steps from the list of Possible Steps on the left and place them in order in to the Solution Steps. (Choose six.)

Options:

Question 17

An administrator must provide North/South connectivity for a VPC. The fabric exposes a distributed external VLAN across all ESX hosts. But, the only BGP peer to the core is on a VLAN only accessible on the Edge Cluster. Which design is required?

Options:

A.

Use a VPC Tier-0 Gateway in active/active mode with distributed eBGP peering.

B.

Distributed Transit Gateway with an EVPN route reflector on the transport nodes.

C.

Centralized Transit Gateway on the Edge Cluster.

D.

Deploy a Provider Tier-1 with BGP and connect the VPC Transit Gateway via route leaking.

Question 18

An architect needs to allow users to deploy multiple copies of a test lab with public access to the internet. The design requires the same machine IPs be used for each deployment. What configuration will allow each lab to connect to the public internet?

Options:

A.

Configure DNAT rules on the Tier-1 gateway.

B.

Configure isolation on the NSX segment.

C.

Configure firewall rules to isolate the traffic going to the public internet.

D.

Configure SNAT rules on the Tier-0 gateway.

Page: 1 / 6
Total 60 questions