5V0-11-21 Sample Questions & Answers
Preparing AWS infrastructure and standing up the SDDC ties with configuring networking, security and vSAN policies for the top share, next to migration tech, pairing cloud Log Insight, Horizon and the Automation add-on, needed accounts, and tuning Elastic DRS.
Launch the full 5V0-11-21 simulator →Showing 10 of 20 free samples.
- Question 1Advanced
Troubleshooting and Repairing · VPN Connectivity Troubleshooting
An administrator is troubleshooting a connectivity issue where on-premises VMs cannot communicate with VMs in a VMware Cloud on AWS SDDC over a newly configured route-based IPsec VPN. The VPN tunnel status is 'Up' in the NSX Manager. The administrator has verified that firewall rules on both the on-premises gateway and the SDDC Compute Gateway allow the traffic. What is the most likely remaining cause of the connectivity failure?
graph TD subgraph On-Premises Data Center OnPremVM[VM 10.10.10.5] OnPremGW[Firewall/Router] end subgraph VMC on AWS SDDC SDDC_VM[VM 192.168.1.5] CGW[Compute Gateway] end OnPremVM --> OnPremGW OnPremGW -- "IPsec VPN (Up)" --x CGW CGW --> SDDC_VMShow answer & explanation
Correct answer: A
For a route-based VPN in VMware Cloud on AWS, the IPsec tunnel provides the secure transport, but BGP (Border Gateway Protocol) is required to exchange routing information between the on-premises network and the SDDC. If the tunnel is up but no traffic flows, a common cause is a misconfigured or failed BGP session, meaning neither side knows how to route traffic to the other.
- Question 2Intermediate
Integrating Other VMware Products with the SDDC · vRealize Log Insight Cloud Configuration
A healthcare organization is deploying a new electronic health record (EHR) system on VMware Cloud on AWS. To meet HIPAA compliance requirements, all log data from the SDDC (including vCenter, ESXi, and NSX) must be forwarded to a centralized, compliant SIEM solution for long-term retention and analysis. The organization is already using vRealize Log Insight Cloud. What is the correct procedure to meet this requirement?
Show answer & explanation
Correct answer: C
The correct, supported method is to have the SDDC forward all logs to its integrated vRealize Log Insight Cloud instance. From there, the administrator can configure log forwarding within vRealize Log Insight Cloud to send all necessary logs to one or more external SIEM endpoints. This provides a centralized and manageable forwarding point.
- Question 3Intermediate
Performance-tuning and Optimization · vSphere Permissions
An administrator needs to provide a junior colleague with the ability to create, delete, and manage virtual machines within a specific resource pool in the SDDC, but prevent them from making any changes to cluster-level settings like DRS or HA. What is the most effective way to grant these specific permissions?
Show answer & explanation
Correct answer: B
The principle of least privilege dictates creating a custom role with only the required permissions (e.g., VM Power On/Off, Create, Delete) and assigning that role to the user specifically on the target resource pool. The CloudAdmin role has the privilege to create and manage these custom roles, enabling granular access control.
- Question 4Intermediate
Planning and Designing · Connectivity Options
A media company wants to extend their on-premises data center to VMware Cloud on AWS to handle burst rendering workloads. They need a high-bandwidth, low-latency, private connection. The on-premises data center is located in an AWS Direct Connect enabled facility. They have already provisioned a 10 Gbps Direct Connect connection. Which type of virtual interface (VIF) must be configured on the Direct Connect connection to establish private connectivity to the SDDC?
Show answer & explanation
Correct answer: B
A private VIF is the correct choice for establishing a private, dedicated connection from an on-premises network to an AWS Virtual Private Cloud (VPC). Since the VMware Cloud on AWS SDDC is connected to a customer's VPC, the private VIF is used to extend the on-premises network to that VPC, thereby enabling private access to the SDDC.
- Question 5Advanced
Planning and Designing · Sizing and Disaster Recovery
Case Study:
A global logistics company, 'ShipFast', is planning a full data center evacuation to VMware Cloud on AWS. Their on-premises environment consists of 500 VMs with a total of 2000 vCPU, 8TB RAM, and 150TB of utilized storage. The workloads include Oracle databases, web servers, and custom Java applications. An analysis with Live Optics shows an average of 80,000 IOPS with a 70/30 read/write ratio. The CIO has mandated that the new cloud environment must support disaster recovery to a different AWS region with an RPO of 15 minutes.
The project team must select the appropriate host type and size the initial SDDC. They also need to choose a DR solution. The primary goal is to balance performance for the database workloads with overall cost-effectiveness. The migration must be completed within three months with minimal downtime for critical applications.
Which combination of host type and disaster recovery solution best meets ShipFast's requirements?
Show answer & explanation
Correct answer: B
This is the optimal solution. The i3en.metal hosts are designed for storage-dense and I/O-intensive workloads like Oracle databases, making them a perfect fit for the 150TB storage and high IOPS requirement. VMware Site Recovery is the native, integrated DRaaS solution for VMware Cloud on AWS that can easily achieve an RPO of 15 minutes or less through vSphere Replication.
- Question 6Advanced
Troubleshooting and Repairing · VMware Cloud on AWS API Usage
A developer is using the VMware Cloud on AWS API to automate the creation of new network segments. They have successfully obtained an OAuth 2.0 access token from the Cloud Services Platform (CSP). Which API endpoint should the developer send the request to for creating a new segment within a specific SDDC?
Show answer & explanation
Correct answer: C
Network segments are NSX-T objects. To create, modify, or delete them, the request must be sent to the NSX Manager API endpoint specific to that deployed SDDC. The access token obtained from CSP is used to authenticate against this proxied API service.
- Question 7Beginner
Deploying and Configuring · SDDC Network Planning
When deploying a new VMware Cloud on AWS SDDC, an administrator must provide a CIDR block for the management network. Which statement correctly describes the constraints for this CIDR block?
Show answer & explanation
Correct answer: C
This is the correct constraint. The management CIDR block has a flexible size (/16, /20, /23 are common choices) and, crucially, it must be unique and not overlap with the CIDR of the AWS VPC it connects to, nor any on-premises networks that will be linked via VPN or Direct Connect to avoid routing conflicts.
- Question 8Beginner
Planning and Designing · Account Requirements
What is the primary role of the underlying AWS account that is linked to a VMware Cloud on AWS organization during the SDDC deployment process?
Show answer & explanation
Correct answer: B
The linked AWS account serves as the payment vehicle. VMware bills the usage of the SDDC hosts and software to this AWS account. Any native AWS services consumed (e.g., S3, EC2 instances in the same VPC) are also billed to this account, providing a single, consolidated bill from AWS.
- Question 9Intermediate
Performance-tuning and Optimization · vSphere Permissions
True or False: The CloudAdmin role in VMware Cloud on AWS has the privileges required to configure a connection to an external identity source, such as an on-premises Active Directory, for vCenter authentication.
Show answer & explanation
Correct answer: A
This statement is true. A key responsibility of the CloudAdmin role is to configure identity and access management. This includes configuring vCenter Single Sign-On to use an external identity source like Microsoft Active Directory over LDAP/S or OpenLDAP, allowing on-premises users and groups to be assigned permissions within the SDDC's vCenter.
- Question 10IntermediateSelect 3
Administrative and Operational Tasks · Hybrid Linked Mode
A consultant is helping a customer set up Hybrid Linked Mode between their on-premises vCenter Server and their new VMC on AWS SDDC. Which three of the following are prerequisites for a successful configuration? (Select THREE)
Show answer & explanation
Correct answers: A, B, C
Network connectivity is a fundamental requirement. The on-premises vCenter must be able to communicate with the cloud vCenter over a private network connection.
Hybrid Linked Mode has specific version compatibility requirements. The on-premises vCenter Server must meet the minimum version supported for linking with the cloud SDDC.
The on-premises systems must be able to resolve the private IP address of the cloud vCenter from its fully qualified domain name (FQDN). This typically requires setting up DNS conditional forwarders.
Ready for the real thing?
The full 5V0-11-21 simulator has every exam-style question, timed mode, and instant scoring.