Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

VMware 3V0-25.25 - Advanced VMware Cloud Foundation 9.0 Networking

Page: 2 / 2
Total 60 questions

How should the Global Managers (GMs) and Local Managers (LMs) be distributed to ensure high availability and optimal performance in a multi-site NSX Federation deployment comprised of three sites? (Choose two.)

A.

Each NSX site must have its own LM cluster that reports to the GM.

B.

LMs are only needed on the primary site. Secondary sites can manage their local data plane directly via the GM.

C.

LMs should only be deployed as single nodes to reduce overhead.

D.

The GM cluster should be deployed across three sites.

E.

The GM should be a single appliance placed in a central cloud environment to simplify connectivity, relying on vSphere HA for availability.

An NSX Manager cluster has failed. The administrator deployed a new NSX Manager using the latest version and attempted to restore from a backup, but the restore operation failed. What would an administrator do to recover the cluster?

A.

Edit the backup passphrase to match the new build.

B.

Use SDDC Manager to replace NSX Manager.

C.

Use the NSX restore API instead of the UI.

D.

Deploy an NSX Manager that matches the backup's build.

An administrator is troubleshooting why workloads in NSX cannot reach the external network 10.100.0.0/16. The Tier-0 Gateway is in Active/Active mode and has the following configuration:

• Uplink-1 (VLAN 100): 192.168.100.0/24 -> router R1 at 192.168.100.1

• Uplink-2 (VLAN 101): 192.168.101.0/24 -> router R2 at 192.168.101.1

• A static route for 10.100.0.0/16 was added with both next-hops (192.168.100.1 and 192.168.101.1).

• The Scope of this route is set to Uplink-1.

Symptoms:

• Virtual Machines (VMs) cannot reach 10.100.0.0/16

• Traceroute from the VM stops at the Tier-0 gateway with "Destination Net Unreachable"

• Pings from the Edge nodes to both 192.168.100.1 and 192.168.101.1 are success

What explains why workloads in NSX cannot reach the external network?

A.

Static routes do not support Equal Cost Multi-Pathing (ECMP) in NSX.

B.

The static route Scope is set to only one uplink interface, but the next-hops are on two different VLANs.

C.

The next-hops should have been configured as the Tier-0's own uplink IPs instead of the routers IPs.

D.

The physical routers are missing return routes.

An administrator is responsible for managing a VMware Cloud Foundation (VCF) Private Cloud consisting of a single VCF Fleet with a single Workload Domain.

The administrator has been tasked with configuring NSX to support the new Virtual Desktop Infrastructure (VDI) solution that allows users to securely access a mainframe-

based application located on the physical network. The VDI solution will use a dedicate DHCP solution for each of the the desktop pool segments and static addresses for all

VDI management components.

The administrator completes the following steps towards configuring DHCP:

1. Creates a new tier-1 gateway (vdi-tier-1) and links it to the tier-0 gateway (gw-tier-0).

2. Creates one new segment for vdi management (vdi-seg-01) and connects it to vdi-tier-1.

3. Creates two new segments for virtual desktops (vdi-seg-02 and vdi-seg-03) and connects them to vdi-tier-1.

Drag and drop the six steps from the list of Possible Steps on the left and place them in order in to the Solution Steps. (Choose six.)

An administrator is attempting to confirm the successful transmission between an internal VM to an external destination.

An ICMP request packet is being sent from Sa-transit-web-01 to the Student Desktop in the diagram.

Drag and Drop the commands output into their appropriate originating NSX object.

An administrator is preparing to deploy a new workload domain that will host vSphere Kubernetes Service (VKS) clusters. Before configuring the network for the Kubernetes clusters, the administrator needs to create a Tier-0 Gateway to handle North/South connectivity. What is the requirement for creating a Tier-0 Gateway for use with a workload domain that is running the vSphere Kubernetes service (VKS) with VPC?

A.

The Tier-0 Gateway route map must contain an IP prefix with only a deny rule.

B.

The Tier-0 Gateway must be configured in Non-Preemptive failover mode.

C.

The Tier-0 Gateway must be configured in Active/Standby mode.

D.

The Tier-0 Gateway must have IPv6 enabled.

A cloud service provider runs VPCs with differing traffic patterns:

• Some VPCs are generating high, large North/South flows.

• Most of the VPCs generate very little traffic.

The architect needs to optimize Edge dataplane resource consumption while ensuring that noisyVPCs do not impact others.

Which optimization satisfies the requirement?

A.

Assign one dedicated Edge node per high-traffic VPC.

B.

Reduce the number of VPCs by consolidating VPCs into shared namespaces.

C.

Convert high-traffic VPCs into VLAN-backed segments attached directly to Tier-0 gateways.

D.

Use multiple Edge clusters and distribute VRF-backed VPCs based on traffic profiles.

An administrator has a VMware Cloud Foundation (VCF) instance. A critical NSX security update has been released by Broadcom. How can the administrator install the NSX update?

A.

Download the NSX patch to the NSX Manager. Apply it using VCF Operations Fleet Management.

B.

Download the NSX patch to VCF Operations. Apply it using NSX Manager.

C.

Download the NSX patch to VCF Operations. Apply it using VCF Operations Fleet Management.

D.

Download the NSX patch to the NSX Manager. Apply it using NSX Manager.