Spring Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

VMware 3V0-25.25 Advanced VMware Cloud Foundation 9.0 Networking Exam Practice Test

Page: 1 / 6
Total 60 questions

Advanced VMware Cloud Foundation 9.0 Networking Questions and Answers

Question 1

An administrator has noticed that both the active and standby Global Managers have gone offline.

What is the correct sequence of events to restore the Global Managers?

Question # 1

Options:

Question 2

The administrator must configure Border Gateway Protocol (BGP) on the Tier-0 Gateway to establish neighbor relationships with upstream routers. Which two statements describe the Border Gateway Routing Protocol (BGP) configuration on a Tier-0 Gateway? (Choose two.)

Options:

A.

EIGRP is configured by default.

B.

Can be used as an Exterior Gateway Protocol.

C.

The network is divided into areas that are logical groups.

D.

It supports a 4-byte autonomous system number.

Question 3

The administrator is working to ascertain the encapsulation of GENEVE by reviewing the capture on Wireshark.

The administrator instructed VM-1 to send a continuous ICMP request directed at VM-2.

Click to highlight where the administrator should observe the GENEVE encapsulated packet.

Question # 3

Options:

Question 4

An administrator is configuring an NSX segment used by a nested hypervisor deployment where an ESXi VM runs on an ESXi host and multiple VMs run inside the ESXi VM. Which segment profile must be created to satisfy the request?

Options:

A.

IP Discovery

B.

Security

C.

MAC Discovery

D.

Spoof Guard

Question 5

An administrator has deployed a workload domain in VMware Cloud Foundation (VCF). The workload domain was deployed with NSX managers using the XL form factor. After deployment, the administrator realizes the NSX manager is oversized and needs to change to a smaller form factor. What should the administrator do to accomplish this task?

Options:

A.

Each NSX Manager must be redeployed.

B.

Each NSX manager must be resized using the API.

C.

Each NSX manager must be resized through vCenter.

D.

Each NSX manager must be rightsized using VCF Operations.

Question 6

An NSX Manager cluster has failed. The administrator deployed a new NSX Manager using the latest version and attempted to restore from a backup, but the restore operation failed. What would an administrator do to recover the cluster?

Options:

A.

Edit the backup passphrase to match the new build.

B.

Use SDDC Manager to replace NSX Manager.

C.

Use the NSX restore API instead of the UI.

D.

Deploy an NSX Manager that matches the backup's build.

Question 7

An administrator has a vSphere 8 Update 1a with NSX 4.1.0.2 environment. What option can the administrator use to converge this vSphere with NSX environment into a VMware Cloud Foundation (VCF) Workload Domain?

Options:

A.

Use the VCF installer to automatically converge the vSphere with NSX environment into a new VCF Workload Domain.

B.

Upgrade NSX to version 9 into the vSphere 8 environment and use the VCF installer to converge the vSphere 8 with NSX environment into a new VCF Workload Domain.

C.

Upgrade the environment version and use the VCF installer to converge the vSphere environment into a new VCF Workload Domain.

D.

Upgrade the environment and use VCF Operations to converge the vSphere environment into a new VCF Workload Domain.

Question 8

An administrator is tasked to create a development environment with a Tier-1 gateway to host overlay segments for only East/West workload communication. North/South communication is also required. The solution will not include the following services: NAT, DHCP, VPN. Which step must the administrator take when creating the Tier-1 gateway?

Options:

A.

Configure a Service Interface on the Tier-1 gateway to connect each overlay segment to provide the East/West communication.

B.

Enable route advertisement and connect the Tier-1 gateway to the Tier-0 gateway.

C.

Assign the Tier-1 gateway to an Edge Cluster before any segments are created.

D.

Keep route advertisement disabled and leave the Tier-1 gateway disconnected from any Tier-0 gateway.

Question 9

When using a DHCP Relay on a segment, which design restriction must be considered?

Options:

A.

DHCP settings, DHCP options, and static bindings cannot be configured on the segment.

B.

DHCP client requests cannot be relayed to the external DHCP servers.

C.

DHCP settings, DHCP options, and static bindings can be configured on the segment.

D.

DHCP Relay service is available to all the other segments in the network.

Question 10

An administrator has been tasked with providing a networking solution including a Source and Destination NAT for a single Tenant. The tenant is using Centralized Connectivity with a Tier-0 Gateway named Ten-A-Tier-0 supported by an Edge cluster in Active-Active mode. The NAT solution must be available for multiple subnets within the Tenant space. The administrator chooses to deploy a Tier-1 Gateway to implement the NAT solution. How would the administrator complete the task?

Options:

A.

Change Ten-A-Tier-0 to Active-Standby to support the stateful NAT.

B.

Create a new Tier-0 Gateway in Active-Standby mode and attach another Tier-1 Gateway.

C.

Create a Tier-1 Gateway in Distributed Routing mode only and do not attach it to Ten-A-Tier-0.

D.

Create a new Tier-1 Gateway in Active-Standby mode and attach it to Ten-A-Tier-0.

Question 11

Which two requirements are part of the registration process for Local Manager (LM) to a Global Manager (GM) in NSX for centralized management of network and security services across different workload domains deployed in separate locations? (Choose two.)

Options:

A.

The LM will validate the GM license to perform the GM registration.

B.

The external load balancer VIP is used for NSX Managers without requiring node API certificate updates.

C.

The LM Cluster VIP / FQDN is provided for GM-LM communication.

D.

The IP / FQDN of any of the 3 LM must be used for registration.

E.

The GM-Active requests the LM IP / FQDN and admin credentials for registration.

Question 12

An administrator has been tasked with enabling OSPF as the routing protocol for a Tier-0 Gateway. Which two items must be configured to enable OSPF for a Tier-0 Gateway?

Mark two answers by clicking the two correct locations on the image. (Choose two.)

Question # 12

Options:

Question 13

An administrator has deployed a new VMware Cloud Foundation (VCF) management domain. To be compliant with company policy, backups must be configured to occur anytime a change is made to the NSX configuration. How can the administrator ensure that complete configuration backups are captured every time a change occurs?

Options:

A.

Configure an alarm to detect configuration changes and automatically trigger a complete configuration backup.

B.

No action is required as by default NSX will automatically perform a complete backup every time a change is made to the configuration.

C.

Configure a cron job on the NSX Manager to automatically perform an incremental backup of the NSX configuration every hour.

D.

Create a recurring backup schedule and explicitly indicate that backups should be captured anytime the configuration changes.

Question 14

An administrator is troubleshooting BGP flapping in a VMware Cloud Foundation (VCF) 9 environment. A Tier-0 Gateway is running in Active/Active mode with two Edge nodes. BFD is enabled on the eBGP sessions to the upstream routers. Each Edge node uses its own uplink IP for BGP. After some network maintenance, one BGP session starts flapping every few minutes. The other BGP sessions stay stable. On the affected Edge node, the command get bfd-sessions shows:

• State: Down

• Diag: Detect Time Expired

Symptoms:

• The upstream router also shows the BFD session as Down with control Detection Time Expired.

• There are no interface errors, no packet loss for normal traffic, and clearing the BFD session temporarily brings it back up - but it flaps again after few minutes.

What is the root cause?

Options:

A.

BFD timers are mismatched between Tier-0 Gateway and the upstream routers.

B.

The MTU does not match on the end-to-end between Tier-0 Gateway and upstream routers.

C.

BFD is configured in echo mode on the upstream routers.

D.

The Edge nodes are undersized and are experiencing high contention on CPU and drops BFD packets.

Question 15

An administrator has noticed an issue in a freshly deployed VMware Cloud Foundation (VCF) environment where the BGP neighborship between the Tier-0 gateway and a physical router remains in the Idle state. Pings between the uplink IPs are successful. What is the issue?

Options:

A.

Autonomous System number mismatch.

B.

Distributed Firewall blocking traffic.

C.

Geneve tunnel down.

D.

Overlay MTU too low.

Question 16

How should the Global Managers (GMs) and Local Managers (LMs) be distributed to ensure high availability and optimal performance in a multi-site NSX Federation deployment comprised of three sites? (Choose two.)

Options:

A.

Each NSX site must have its own LM cluster that reports to the GM.

B.

LMs are only needed on the primary site. Secondary sites can manage their local data plane directly via the GM.

C.

LMs should only be deployed as single nodes to reduce overhead.

D.

The GM cluster should be deployed across three sites.

E.

The GM should be a single appliance placed in a central cloud environment to simplify connectivity, relying on vSphere HA for availability.

Question 17

An architect needs to allow users to deploy multiple copies of a test lab with public access to the internet. The design requires the same machine IPs be used for each deployment. What configuration will allow each lab to connect to the public internet?

Options:

A.

Configure DNAT rules on the Tier-1 gateway.

B.

Configure isolation on the NSX segment.

C.

Configure firewall rules to isolate the traffic going to the public internet.

D.

Configure SNAT rules on the Tier-0 gateway.

Question 18

An administrator is troubleshooting an issue where workloads connected to a Tier-1 Gateway named T1-App can no longer reach external North/South destinations.

• The Tier-1 is connected to an Active/Standby Tier-0 Gateway named T0-Prod.

Symptoms observed:

• VMs on segments attached to T1-App can ping each other.

• VMs on T1-App cannot reach any external IP outside T0-Prod.

• From a VM on the segment, ping to the T1-App Distributed Router (DR) IP succeeds.

• Ping from the VM to the T1-App Service Router (SR) fails.

• The Edge cluster hosting the T1-App SR shows both Edge nodes Up and Healthy.

• No failover has occurred — the same Edge node is still shown as Active for T1-App.

What is the most likely cause of this issue?

Options:

A.

The overlay network between DR and SR has an MTU mismatch.

B.

Route advertisement from T1-App to T0-Prod for 100.64.x.x/31 is disabled.

C.

Static default route is missing on the Tier-1 DR component.

D.

Localized control plane is enabled on the Tier-1 causing the SR to remain admin-down.

Page: 1 / 6
Total 60 questions