2V0-21.23 Sample Questions

2V0-21.23 Sample Questions & Answers

Infrastructure components and VM management tie with troubleshooting and recovery for the top share, next to integrating Tanzu and Kubernetes, design principles, network and storage setup, upgrade procedures, and security and operational management.

Launch the full 2V0-21.23 simulator →

Showing 10 of 20 free samples.

  1. Question 1IntermediateSelect 2

    Administrative and Operational Tasks · VM Encryption

    An administrator needs to encrypt a virtual machine's disks and its vMotion traffic. The environment uses a third-party Key Management Server (KMS). Which two components must be configured in vCenter Server to enable this functionality? (Select TWO)

    Show answer & explanation

    Correct answers: A, B

  2. Question 2Advanced

    Products and Solutions · NSX Integration

    A financial company is implementing a new three-tier application in their vSphere 8 environment. The security policy requires strict network isolation between the Web, App, and DB tiers. The administrator has been asked to implement this using a solution that provides centralized management and distributed firewalling capabilities without requiring significant physical network changes.

    The current environment consists of a single vCenter Server managing one cluster of ESXi hosts. All hosts are connected to a vSphere Distributed Switch (VDS). The physical network team has provided a single VLAN for all VM traffic. The company has licenses for vSphere Enterprise Plus and VMware NSX.

    To meet the security requirements, the administrator plans to use NSX to create logical segments for each application tier and apply distributed firewall rules to control traffic flow between them. This approach will provide micro-segmentation within the existing VLAN.

    Which configuration step is a prerequisite for creating NSX logical segments and applying distributed firewall rules to the VMs in this cluster?

    Show answer & explanation

    Correct answer: C

    Before any NSX networking and security features like logical segments (overlay networks) or the distributed firewall can be utilized, the ESXi hosts in the cluster must be 'prepared' for NSX. This process, managed from the NSX Manager, involves installing NSX kernel modules (VIBs) on each host. These modules enable the hypervisor to participate in the NSX data plane, allowing it to enforce firewall rules and handle overlay network traffic directly at the vNIC level.

  3. Question 3Advanced

    Performance-tuning, Optimization, and Upgrades · Storage Performance Troubleshooting

    An administrator is troubleshooting poor storage performance for a VM running a database application. The administrator uses esxtop and navigates to the disk device view. Which counter should be monitored to get the most accurate measure of the latency being experienced by the guest OS for I/O operations?

    Show answer & explanation

    Correct answer: C

    In esxtop, GAVG/cmd (Guest Average Latency) represents the total latency for an I/O operation as seen from the perspective of the virtual machine's guest OS. It is the sum of kernel latency (KAVG) and device latency (DAVG). Therefore, GAVG is the most comprehensive and accurate metric for understanding the actual storage latency the application is experiencing.

  4. Question 4AdvancedSelect 2

    Administrative and Operational Tasks · vSphere Security

    To enhance security, a vSphere administrator wants to ensure that ESXi hosts only boot with authentically signed VMware software and that the host's configuration is measured and attested by vCenter. Which two features must be enabled on the ESXi host hardware and configured in vSphere to achieve this? (Select TWO)

    Show answer & explanation

    Correct answers: A, B

  5. Question 5Beginner

    Installing, Configuring, and Setup · vSphere Distributed Switch Policies

    An administrator is configuring a new vSphere Distributed Switch (VDS) and wants to ensure that if an uplink adapter fails, the traffic is rerouted to another available uplink with minimal packet loss. The physical switches are not configured for Link Aggregation (LACP). Which NIC teaming policy should be selected for the distributed port group?

    Show answer & explanation

    Correct answer: D

    The default and most common policy, 'Route based on originating virtual port,' provides reliable failover without requiring special physical switch configurations like LACP. When an uplink fails, the VDS automatically reroutes the traffic associated with the virtual ports on that uplink to the remaining active uplinks in the team. 'Route based on IP hash' requires LACP, and 'Route based on physical NIC load' is more for load balancing than simple failover.

  6. Question 6Intermediate

    Installing, Configuring, and Setup · vSphere Lifecycle Manager (vLCM) Updates

    A vSphere administrator is using vSphere Lifecycle Manager (vLCM) to manage a cluster with an image. The security team has released a critical patch that needs to be applied to the ESXi hosts immediately. Which is the correct procedure to update the cluster image with the new patch?

    Show answer & explanation

    Correct answer: B

    When managing a cluster with a vLCM image, the 'desired state' model is used. To apply a patch, the administrator must edit the cluster's image definition. Within the image editor, they can select new components, such as patches, from the vLCM depot. After saving the updated image, vLCM will show the hosts as non-compliant, and the administrator can then run the remediation workflow to apply the change.

  7. Question 7Beginner

    Performance-tuning, Optimization, and Upgrades · CPU Performance Metrics

    A virtual machine is experiencing high CPU ready time (%RDY). What does this metric indicate?

    Show answer & explanation

    Correct answer: C

    CPU ready time (%RDY) is the percentage of time a virtual machine was ready to run but could not get scheduled on a physical CPU because all available CPU cores on the host were busy. High CPU ready time is a key indicator of CPU contention and often means the ESXi host is oversubscribed for CPU resources.

  8. Question 8Intermediate

    Installing, Configuring, and Setup · vCenter High Availability (VCHA)

    An administrator needs to deploy a new vCenter Server 8 instance with an embedded Platform Services Controller. The deployment must be configured for high availability from the start. Which option in the vCenter Server Appliance installer GUI should be selected?

    Show answer & explanation

    Correct answer: A

    Deploying a vCenter Server with VCHA from the start is not a direct one-click option in the installer. The correct procedure is to first deploy a standalone vCenter Server by selecting the 'Install' option. After this initial deployment is complete and the vCenter is operational, the administrator then configures vCenter HA (VCHA) from within the vSphere Client, which will deploy the Passive and Witness nodes.

  9. Question 9Beginner

    Architecture and Technologies · vMotion and EVC

    A vSphere administrator needs to perform a live migration of a virtual machine from a host with an AMD processor to a host with an Intel processor. What must be configured to allow this migration to succeed?

    Show answer & explanation

    Correct answer: C

    vMotion requires that the source and destination hosts have compatible CPUs. Migrations between different CPU vendor families (e.g., AMD and Intel) are not supported, even with Enhanced vMotion Compatibility (EVC) enabled. EVC can only mask CPU features within the same vendor family to allow migrations between different generations of processors (e.g., an older Intel CPU to a newer Intel CPU).

  10. Question 10Advanced

    Troubleshooting and Repairing · vSphere HA Network Partitions

    A company's vSphere 8 infrastructure is spread across two geographically separate datacenters, DC1 and DC2. A single vCenter Server in DC1 manages hosts in both locations. The network link between the datacenters has an RTT latency of 10ms. During a network outage that isolates DC2, the ESXi hosts in DC2 lose connectivity to vCenter. The administrator observes that vSphere HA does not initiate VM failovers for the hosts in DC2, even though they are part of the same HA cluster.

    Key configuration details:

    • vSphere HA is enabled.
    • Host isolation response is set to 'Power off and restart VMs'.
    • The default gateway is in DC1 and is used as an isolation address.
    • Datastore heartbeating is enabled on shared storage within DC2.

    Why did HA fail to restart the virtual machines in this scenario?

    Show answer & explanation

    Correct answer: A

    In a network partition scenario, vSphere HA elects a master host. If hosts in a partition cannot communicate with the master and also cannot ping the isolation address, they consider themselves isolated. However, before taking action, the hosts in the partition communicate with each other. If they determine they are in a 'minority' partition (i.e., fewer hosts than the partition containing the master), they will not initiate failovers to prevent a split-brain scenario where VMs could be running in both partitions simultaneously. Since the vCenter and likely the HA master are in DC1, the hosts in DC2 formed a minority partition and correctly chose not to take action.

Ready for the real thing?

The full 2V0-21.23 simulator has every exam-style question, timed mode, and instant scoring.