VMware 3V0-25.25 - Advanced VMware Cloud Foundation 9.0 Networking Exam
Page: 2 / 12
Total 58 questions
Question #6 (Topic: Exam A)
An administrator is troubleshooting why workloads in NSX cannot reach the external network 10.100.0.0/16.
The Tier-0 Gateway is in Active/Active mode and has the following configuration:
Uplink-1 (VLAN 100): 192.168.100.0/24 → router R1 at 192.168.100.1
Uplink-2 (VLAN 101): 192.168.101.0/24 → router R2 at 192.168.101.1
A static route for 10.100.0.0/16 was added with both next-hops (192.168.100.1 and 192.168.101.1)
The Scope of this route is set to Uplink-1
Symptoms:
Virtual Machines (VMs) cannot reach 10.100.0.0/16
Traceroute from the VM stops at the Tier-0 gateway with "Destination Net Unreachable"
Pings from the Edge nodes to both 192.168.100.1 and 192.168.101.1 are success
What explains why workloads in NSX cannot reach the external network?
The Tier-0 Gateway is in Active/Active mode and has the following configuration:
Uplink-1 (VLAN 100): 192.168.100.0/24 → router R1 at 192.168.100.1
Uplink-2 (VLAN 101): 192.168.101.0/24 → router R2 at 192.168.101.1
A static route for 10.100.0.0/16 was added with both next-hops (192.168.100.1 and 192.168.101.1)
The Scope of this route is set to Uplink-1
Symptoms:
Virtual Machines (VMs) cannot reach 10.100.0.0/16
Traceroute from the VM stops at the Tier-0 gateway with "Destination Net Unreachable"
Pings from the Edge nodes to both 192.168.100.1 and 192.168.101.1 are success
What explains why workloads in NSX cannot reach the external network?
A. The physical routers are missing return routes.
B. The next-hops should have been configured as the Tier-0's own uplink IPs instead of the routers IPs.
C. Static routes do not support Equal Cost Multi-Pathing (ECMP) in NSX.
D. The static route Scope is set to only one uplink interface, but the next-hops are on two different VLANs.
Answer: D
Question #7 (Topic: Exam A)
The NSX Manager is reporting the following open alarm:
Remote Logging Not Configured
The administrator has verified that remote logging is enabled for the NSX Manager and NSX Edge nodes. However, the alarm is still open in NSX Manager.
Which statement explains why the Remote Logging Not Configured alarm is still open?
Remote Logging Not Configured
The administrator has verified that remote logging is enabled for the NSX Manager and NSX Edge nodes. However, the alarm is still open in NSX Manager.
Which statement explains why the Remote Logging Not Configured alarm is still open?
A. The Remote Logging Not Configured alert has been suppressed in the NSX Manager.
B. Operations for Logs has not been enabled in VCF Operations Fleet Management.
C. One or more ESX nodes are not currently configured to forward log messages to a remote logging server.
D. The administrator needs to log out and log back in to the NSX Manager UI to refresh the alert status.
Answer: C
Question #8 (Topic: Exam A)
How should the Global Managers (GMs) and Local Manager (LM)s be distributed to ensure high availability and optimal performance in a multisite NSX Federation deployment comprised of three sites? (Choose two.)
A. The GM should be a single appliance placed in a central cloud environment to simplify connectivity, relying on vSphere HA for availability.
B. The GM cluster should be deployed across three sites.
C. LMs are only needed on the primary site. Secondary sites can manage their local data plane directly via the GM.
D. Each NSX site must have its own LM cluster that reports to the GM.
E. LMs should only be deployed as single nodes to reduce overhead.
Answer: BD
Question #9 (Topic: Exam A)
An architect needs to allow users to deploy multiple copies of a test lab with public access to the internet.
The design requires the same machine IPs be used for each deployment.
What configuration will allow each lab to connect to the public internet?
The design requires the same machine IPs be used for each deployment.
What configuration will allow each lab to connect to the public internet?
A. Configure firewall rules to isolate the traffic going to the public internet.
B. Configure DNAT rules on the Tier-1 gateway.
C. Configure SNAT rules on the Tier-0 gateway.
D. Configure isolation on the NSX segment.
Answer: C
Question #10 (Topic: Exam A)
An administrator created a new Tier-1 Gateway and is attempting to change the connected gateway for a deployed segment to use the new gateway.
In the UI, when the administrator clicks the Connected Gateway dropdown, the new Tier-1 gateway is not shown as an available gateway.
What would prevent the new Tier-1 gateway from showing in the list of available gateways?
In the UI, when the administrator clicks the Connected Gateway dropdown, the new Tier-1 gateway is not shown as an available gateway.
What would prevent the new Tier-1 gateway from showing in the list of available gateways?
A. The Tier-1 Gateway is not connected to an NSX Edge Cluster.
B. The Tier-1 Gateway and NSX Segment are connected to different Tier-0 Gateways.
C. The Tier-1 Gateway and NSX Segment are in different transport zones.
D. The Tier-1 Gateway connectivity policy is set to "None".
Answer: C