View Full VMware 2V0-21.23 Exam Dumps and Practice Test Dumps.
Question 121
What type of Content Library subscription downloads items only when needed?
- Push subscription
- Filtered or On-demand subscription
- Immediate full replication
- Scheduled manual mirroring
Correct Answer: 2
Explanation:
An on-demand subscription to a Content Library allows a subscriber library to sync only the metadata of templates and images initially, saving significant storage space. The actual underlying payload files—such as OVF templates or ISO images—are downloaded from the publisher library on-demand only when an administrator attempts to deploy or use that specific item. This efficient mechanism minimizes cross-site bandwidth consumption and reduces storage footprints across distributed branch office locations.
Question 122
Which feature ensures CPU compatibility across different generations of processors during vMotion?
- Fault Tolerance
- Distributed Resource Scheduler
- Enhanced vMotion Compatibility (EVC)
- Storage DRS
Correct Answer: 3
Explanation:
Enhanced vMotion Compatibility creates a baseline CPU feature mask at the cluster level, hiding advanced instruction sets from newer processors so that older CPUs can comprehend them. This allows virtual machines to migrate freely via vMotion between hosts with different CPU models and generations without requiring power-offs. EVC is essential for maintaining high flexibility during hardware lifecycle refreshes and optimizing compute utilization across mixed-generation enterprise clusters.
Question 123
What foundational structure combines local flash and capacity drives in a vSAN cluster?
- vSAN Disk Group
- Datastore Cluster
- Storage Pool LUN
- Software RAID Array
Correct Answer: 1
Explanation:
A vSAN disk group is a logical aggregation of physical storage devices on an ESXi host, consisting of one dedicated cache tier device and one or more capacity tier devices. The cache tier handles read caching and write buffering, while the capacity tier provides persistent long-term storage. Every host contributing storage to a vSAN cluster must have at least one valid disk group configured, balancing performance and resilience across the distributed storage fabric.
Question 124
What is the maximum number of virtual CPUs supported for a single Fault Tolerance protected VM in vSphere?
- 2 vCPUs
- 4 vCPUs
- 6 vCPUs
- 8 vCPUs
Correct Answer: 4
Explanation:
Modern vSphere Fault Tolerance supports protecting virtual machines configured with up to 8 virtual CPUs and specified memory limits, depending on the specific vSphere license edition. FT maintains a continuous, identical secondary instance running in lockstep with the primary virtual machine across a separate physical host. While it guarantees zero downtime and zero data loss upon hardware failure, resource constraints are imposed to manage the heavy network and CPU overhead associated with instantaneous instruction replication.
Question 125
Which service provides hardware-based security for cryptographic operations and key protection in vSphere?
- vCenter SSO
- vSphere Trust Authority
- Host Profiles
- Active Directory Federation
Correct Answer: 2
Explanation:
vSphere Trust Authority decouples key management and attestation from the main vCenter management cluster, establishing a secure, dedicated cluster to verify the integrity of ESXi hosts. By leveraging Trusted Platform Module chips and hardware root-of-trust, Trust Authority ensures that encrypted virtual machines and sensitive secrets are only released to verified, untampered hosts. This architecture enhances security compliance in highly regulated enterprise cloud environments.
Question 126
What type of file is used to deploy a pre-configured virtual appliance package?
- .vmdk file
- .iso image file
- .ovf or .ova template file
- .vmx configuration file
Correct Answer: 3
Explanation:
Open Virtualization Format (.ovf) and Open Virtualization Appliance (.ova) are standardized, platform-independent file formats used to package and distribute virtual machines or multi-tier virtual appliances. An OVF package consists of a descriptor file, manifest, and associated virtual disk files, while an OVA packages these components into a single tar-archive. They allow administrators to export and import standardized workloads seamlessly across different virtualization platforms.
Question 127
Which vSphere HA admission control policy reserves resources based on a percentage of total cluster compute capacity?
- Host Failures Cluster Tolerates (FCT)
- Percentage of Cluster Resources
- Dedicated Failover Hosts
- Resource Reservation Pool
Correct Answer: 2
Explanation:
The Percentage of Cluster Resources admission control policy in vSphere HA ensures that a specified fraction of the cluster’s total CPU and memory resources is held in reserve for failover purposes. If an ESXi host fails, the remaining unreserved capacity must be sufficient to restart all protected virtual machines. This flexible policy automatically adjusts failover reservations dynamically as new hosts are added to or removed from the cluster, simplifying capacity management.
Question 128
What Storage DRS recommendation mode automatically applies space-balancing migrations without administrator approval?
- Manual mode
- Semi-automated mode
- Rule-enforced mode
- Automated mode
Correct Answer: 4
Explanation:
Automated Storage DRS continuously monitors space utilization and I/O latency across datastore clusters, automatically generating and executing Storage vMotion recommendations to rebalance load and prevent out-of-space conditions. Unlike manual mode, which only suggests migrations for administrator review, fully automated mode handles rebalancing in real time without manual intervention. This maximizes datastore efficiency and prevents storage performance bottlenecks proactively.
Question 129
What are the three node roles deployed in a vCenter Server High Availability (VCHA) configuration?
- Primary, Backup, Standby
- Active, Passive, Witness
- Master, Replica, Observer
- Leader, Follower, Arbiter
Correct Answer: 2
Explanation:
vCenter Server High Availability protects the vCenter management appliance by deploying a three-node cluster consisting of an Active node, a Passive node, and a Witness node. The Active node runs the live management services and synchronizes database and file changes synchronously to the Passive node. The Witness node participates by breaking potential ties in network-partition scenarios, ensuring automatic failover without split-brain corruption of the vCenter database.
Question 130
What parameter does Network I/O Control use to allocate bandwidth among different traffic types on a physical adapter?
- Priority tags
- Rate-limiting bits
- Shares and Reservation limits
- Packet shaping windows
Correct Answer: 3
Explanation:
Network I/O Control uses shares, reservations, and limit configurations to manage bandwidth allocation for different traffic classes—such as vMotion, Fault Tolerance, storage, and virtual machine traffic—across physical uplink ports. Shares determine the relative priority of traffic during congestion, while reservations guarantee a minimum throughput threshold. This ensures that critical infrastructure traffic never gets starved by heavy virtual machine network activity.
Question 131
What vSphere feature enables running containerized workloads natively on ESXi hypervisors?
- vSphere with Kubernetes (Supervisor Cluster)
- Docker Swarm Integration Plugin
- Container Engine Daemon for ESXi
- Photon OS Native Service
Correct Answer: 1
Explanation:
vSphere with Kubernetes transforms standard vSphere clusters into a Supervisor Cluster, allowing administrators to deploy and manage Kubernetes namespaces and containerized applications alongside traditional virtual machines. It integrates vSphere networking, storage policies, and identity management directly with Kubernetes APIs. This empowers developers and administrators to manage modern cloud-native applications within a unified enterprise virtualization infrastructure.
Question 132
What ESXi security feature verifies the digital signature of software modules before loading them during boot?
- TPM Attestation
- Interlock Boot Verification
- Kernel Integrity Shield
- ESXi Secure Boot
Correct Answer: 4
Explanation:
ESXi Secure Boot is a UEFI firmware feature that ensures the hypervisor kernel, drivers, and VIB packages are cryptographically signed by VMware or trusted partners before they are allowed to execute. If any system file has been tampered with or unauthorized code is injected, Secure Boot halts the startup process. This prevents low-level rootkits and boot-sector malware from compromising the underlying hypervisor layer.
Question 133
What VMware tool provides centralized log collection, indexing, and analytics for vSphere environments?
- vRealize Orchestrator
- Aria Operations for Logs (formerly vRealize Log Insight)
- vSphere Health Inspector
- ESXi Log Collector Utility
Correct Answer: 2
Explanation:
Aria Operations for Logs delivers real-time log management, analytics, and deep search capabilities across ESXi hosts, vCenter Servers, and associated virtual infrastructure components. It aggregates syslog data, provides pre-configured dashboards, and generates alerts for known system errors or security anomalies. This centralized visibility greatly accelerates root-cause analysis during complex datacenter troubleshooting sessions.
Question 134
What defines the set of supported virtual hardware features and device models available to a virtual machine?
- Host Profile Template
- Virtual Machine Generation ID
- Virtual Machine Compatibility (Hardware Version)
- Guest Operating System Profile
Correct Answer: 3
Explanation:
Virtual Machine Compatibility, historically known as virtual hardware version, determines the maximum number of virtual CPUs, memory limits, and advanced device models that a virtual machine can utilize. Upgrading hardware compatibility unlocks newer hypervisor capabilities, though it may limit ability to migrate the VM back to older ESXi host versions. Administrators upgrade compatibility intentionally after verifying guest OS driver support.
Question 135
What action does Storage DRS take when a datastore exceeds its high-utilization threshold?
- Recommends or executes migrations to free space
- Automatically deletes old snapshots
- Compresses all virtual disks in place
- Converts thin disks to eager zeroed
Correct Answer: 1
Explanation:
When a datastore within a datastore cluster exceeds its configured space utilization threshold, Storage DRS triggers rebalancing logic. It identifies suitable virtual disks on the congested datastore and recommends or automatically executes Storage vMotion migrations to other datastores with abundant free space. This automated load balancing prevents unexpected out-of-space outages and maintains optimal storage performance.
Question 136
What physical network adapters are bound to a vSphere Distributed Switch to provide external connectivity?
- Bridge uplinks
- VMkernel adapters
- Port group gateways
- Distributed Switch Uplinks (Uplink Ports)
Correct Answer: 4
Explanation:
Distributed Switch Uplinks are specialized ports on a vSphere Distributed Switch where physical network interface cards from ESXi hosts are connected. These uplinks bridge virtual network traffic from distributed port groups out onto the physical enterprise network switches. Configurations applied to uplink ports, such as NIC teaming policies and VLAN trunking, govern how all host traffic exits the virtualized infrastructure.
Question 137
How does vCenter Single Sign-On integrate external identity providers like Microsoft Active Directory?
- By installing local LDAP daemons on ESXi
- By configuring Active Directory as an SSO Identity Source
- By synchronizing local shadow accounts via cron
- By tunneling through ESXi firewall rules
Correct Answer: 2
Explanation:
vCenter Single Sign-On allows administrators to add external directories—such as Active Directory, OpenLDAP, or LDAP-based identity providers—directly as trusted Identity Sources. Once configured, users and groups from those directories can be assigned granular Roles and Permissions within vCenter without requiring duplicate account creation. This centralizes identity governance and enforces corporate password policies across the entire vSphere environment.
Question 138
What encryption method protects virtual machine disk data while it is being migrated via vMotion?
- AES-NI hardware cipher
- IPsec tunnel encryption
- Encrypted vMotion
- SSL/TLS transport wrapper
Correct Answer: 3
Explanation:
Encrypted vMotion ensures that virtual machine memory, disk data, and device state information transiting between ESXi hosts during a live migration are cryptographically protected. Administrators can configure vMotion encryption as Required, Optional, or Disabled. Even if network traffic is intercepted over untrusted physical links, encrypted vMotion prevents unauthorized exposure of sensitive workload data.
Question 139
Which virtual disk mode allows a disk to remain unaffected by virtual machine snapshots?
- Independent – Persistent
- Independent – Non-persistent
- Dependent – Read-only
- Raw Device Mapping – Mode 2
Correct Answer: 1
Explanation:
Setting a virtual disk to Independent – Persistent mode means that changes written to that disk are written immediately and permanently, and importantly, the disk is excluded from standard virtual machine snapshot operations. When a snapshot is reverted, persistent independent disks retain their current state rather than rolling back. This mode is commonly used for virtual disks storing databases, mail spools, or data that must not revert during snapshot testing.
Question 140
Where are ESXi diagnostic information and core dumps redirected in the event of a critical system crash (Purple Screen of Death)?
- Local USB scratch partition
- vCenter Syslog collector daemon
- Network File System temp store
- Configured core dump partition or network dump collector
Correct Answer: 4
Explanation:
When an ESXi host experiences a critical kernel fault resulting in a Purple Screen of Death, it attempts to dump its memory contents to a pre-configured local diagnostic partition or a remote network dump collector. This core dump file is vital for VMware Global Support Services to analyze memory registers, trace stack dumps, and determine the exact root cause of the hypervisor crash. Proper core dump configuration is a best practice for enterprise troubleshooting.