Spring Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

An administrator has a vSphere 8 Update 1a with NSX 4.1.0.2 environment. What option can the administrator use to converge this vSphere with NSX environment into a VMware Cloud Foundation (VCF) Workload Domain?

A.

Use the VCF installer to automatically converge the vSphere with NSX environment into a new VCF Workload Domain.

B.

Upgrade NSX to version 9 into the vSphere 8 environment and use the VCF installer to converge the vSphere 8 with NSX environment into a new VCF Workload Domain.

C.

Upgrade the environment version and use the VCF installer to converge the vSphere environment into a new VCF Workload Domain.

D.

Upgrade the environment and use VCF Operations to converge the vSphere environment into a new VCF Workload Domain.

An administrator is tasked to enable users to configure an individual VPC, but not create subnets. What three NSX roles would the administrator assign to allow access without the ability to create subnets? (Choose three.)

A.

Security Admin

B.

Network Admin

C.

VPC Admin

D.

Security Operator

E.

Network Operator

Which two requirements are part of the registration process for Local Manager (LM) to a Global Manager (GM) in NSX for centralized management of network and security services across different workload domains deployed in separate locations? (Choose two.)

A.

The LM will validate the GM license to perform the GM registration.

B.

The external load balancer VIP is used for NSX Managers without requiring node API certificate updates.

C.

The LM Cluster VIP / FQDN is provided for GM-LM communication.

D.

The IP / FQDN of any of the 3 LM must be used for registration.

E.

The GM-Active requests the LM IP / FQDN and admin credentials for registration.

An administrator needs to prevent the datacenter from advertising any internal prefixes toward a new VPC, while still ensuring the VPC receives a default route learned from the datacenter's upstream network. Where should the routing policy be applied?

A.

On each segment default gateway.

B.

On the Tier-1 gateway.

C.

On the VPC transit gateway.

D.

On the provider Tier-0 neighbor.

The administrator is working to ascertain the encapsulation of GENEVE by reviewing the capture on Wireshark.

The administrator instructed VM-1 to send a continuous ICMP request directed at VM-2.

Click to highlight where the administrator should observe the GENEVE encapsulated packet.

The administrator is implementing a multi-location VMware Cloud Foundation (VCF) environment. The design requires centralized security and networking policies across multiple VCF instances. What action must the administrator take to satisfy the requirements?

A.

Deploy a Global Manager cluster manually.

B.

Deploy a Local Manager (LM) cluster using VCF Operations.

C.

Use SDDC Manager to deploy a Global Manager cluster.

D.

Use VCF Installer to deploy a Local Manager (LM) cluster.

An administrator is enabling IPv6-to-IPv4 communication for workloads hosted in an NSX environment. The workloads use IPv6-only addressing, but the external systems they must reach are IPv4-only. To provide this translation service, the administrator decides to configure NAT64. Which two following characteristics about NAT64 are true? (Choose two.)

A.

NAT64 is stateless and requires gateways to be deployed in active-standby mode.

B.

NAT64 requires the Tier-1 gateway to be configured in active-standby mode.

C.

NAT64 is supported on Tier-1 gateways only.

D.

NAT64 is supported on Tier-0 and Tier-1 gateways.

E.

NAT64 requires the Tier-1 gateway to be configured in active-active mode.

An administrator is troubleshooting an issue where workloads connected to a Tier-1 Gateway named T1-App can no longer reach external North/South destinations.

• The Tier-1 is connected to an Active/Standby Tier-0 Gateway named T0-Prod.

Symptoms observed:

• VMs on segments attached to T1-App can ping each other.

• VMs on T1-App cannot reach any external IP outside T0-Prod.

• From a VM on the segment, ping to the T1-App Distributed Router (DR) IP succeeds.

• Ping from the VM to the T1-App Service Router (SR) fails.

• The Edge cluster hosting the T1-App SR shows both Edge nodes Up and Healthy.

• No failover has occurred — the same Edge node is still shown as Active for T1-App.

What is the most likely cause of this issue?

A.

The overlay network between DR and SR has an MTU mismatch.

B.

Route advertisement from T1-App to T0-Prod for 100.64.x.x/31 is disabled.

C.

Static default route is missing on the Tier-1 DR component.

D.

Localized control plane is enabled on the Tier-1 causing the SR to remain admin-down.