VMware Certified Technical Associate - Application Modernization (VCTA-AM) Free Sample Questions

20 free sample questions236 in the full practice test

Try simulator

1V0-71-21 Sample Questions

  1. Question 1

    A platform engineering team is deploying a new version of a critical microservice using a blue-green strategy on Tanzu Kubernetes Grid. The current 'blue' version is serving 100% of production traffic via a Kubernetes Service named payment-svc. The new 'green' deployment is running and has been tested internally. Which action is the most effective and standard way to switch production traffic to the 'green' version with zero downtime?

    Answer and explanation

    Correct answer: B

    The most efficient and standard Kubernetes-native way to switch traffic in a blue-green deployment is to update the selector of the existing Service. A kubectl patch or kubectl apply on the service manifest achieves this atomically, redirecting all traffic from the old pods to the new ones without any downtime or DNS changes. Deleting and recreating the service would cause a service outage. Using port-forward is for debugging, not production traffic. Modifying the deployment's labels would not change where the existing service is pointing.

  2. Question 2

    Multiple answers

    A developer is troubleshooting a pod that is stuck in the ImagePullBackOff state. The pod manifest specifies the image private-repo.corp.local/app:v2.1. The worker node has network connectivity to the private repository. What are the two most likely causes for this error? (Select TWO)

    Answer and explanation

    Correct answers: A, B

    The ImagePullBackOff status indicates that the kubelet on the worker node failed to pull the container image. The two most common reasons for this when pulling from a private repository are authentication failure or the specified image/tag not existing. Authentication is handled via an imagePullSecret associated with the pod's ServiceAccount. If the secret is missing, incorrect, or expired, the pull will fail. Similarly, a simple typo in the image tag will also result in a pull failure. Insufficient CPU/memory or a missing Ingress controller are unrelated to the image pull process.

  3. Question 3

    True or False: In Tanzu Kubernetes Grid, the Cluster API (CAPI) is used exclusively for managing the lifecycle of workload clusters, while the management cluster must always be deployed and managed manually.

    Answer and explanation

    Correct answer: B

    This statement is false. While the Cluster API's primary role within a TKG management cluster is to manage the lifecycle of workload clusters, the management cluster itself is typically deployed using tools like the Tanzu CLI, which bootstraps a temporary kind cluster to then provision the full management cluster using Cluster API controllers. Therefore, CAPI is integral to the creation of the management cluster itself, not just the workload clusters it subsequently manages.

  4. Question 4

    An architect is designing a multi-cloud Kubernetes strategy for a global enterprise using Tanzu Mission Control (TMC). The primary requirements are to enforce consistent security policies across all clusters (AKS, EKS, and TKG on-premises) and to restrict developers in the 'junior-dev' group from creating ClusterRoleBinding resources. Which TMC policy type should the architect create to meet these requirements?

    Answer and explanation

    Correct answer: D

    Tanzu Mission Control's Custom Policies leverage the Open Policy Agent (OPA) Gatekeeper framework. This allows administrators to write fine-grained rules using the Rego language to enforce custom constraints on any Kubernetes resource. The requirement to block the creation of ClusterRoleBinding resources by a specific user group is a classic use case for a custom admission control policy, which is implemented in TMC as a Custom Policy. Other policy types like Network, Quota, or Image Registry are for more specific, pre-defined use cases.

  5. Question 5

    A DevOps team is migrating a stateful application, a distributed database, to Kubernetes. The application requires a stable, unique network identifier for each of its replicas and persistent storage that survives pod restarts. Which Kubernetes workload resource is specifically designed to manage this type of application?

    Answer and explanation

    Correct answer: C

    A StatefulSet is the ideal Kubernetes workload API object for managing stateful applications. It provides guarantees about the ordering and uniqueness of its pods. This includes stable, unique network identifiers (e.g., pod-0, pod-1), stable persistent storage linked to each pod's identity, and ordered, graceful deployment and scaling. Deployments are designed for stateless applications where pods are interchangeable.

  6. Question 6

    A financial services company is using Tanzu Application Catalog (TAC) to provide a curated list of open-source software for their development teams. To comply with internal security standards, all container images must be scanned for critical vulnerabilities and come from a trusted source. Which core feature of Tanzu Application Catalog directly addresses this requirement?

    Answer and explanation

    Correct answer: C

    The primary value proposition of Tanzu Application Catalog is providing a curated catalog of software from a trusted source (Bitnami) that is continuously maintained. This process includes regular security scanning, testing for compatibility, and validation. This ensures that developers are using applications that are not only easy to deploy but also meet enterprise security and compliance standards out-of-the-box, directly addressing the company's requirement.

  7. Question 7

    During a review of a Kubernetes cluster's architecture, an administrator needs to explain the function of etcd. Which statement accurately describes the role of etcd in the Kubernetes control plane?

    graph TD subgraph Control Plane API[API Server] SCHED[Scheduler] CTRL[Controller Mgr] ETCD[(etcd)] end API ETCD SCHED --> API CTRL --> API subgraph Worker Nodes Kubelet1[Kubelet] Kubelet2[Kubelet] end Kubelet1 --> API Kubelet2 --> API
    Answer and explanation

    Correct answer: B

    etcd is a consistent and highly-available key-value store used as Kubernetes' backing store for all cluster data. It stores the configuration data, state, and metadata of the cluster, representing the 'desired state' of all objects. All other control plane components, like the API server, query and write to etcd to understand and change the state of the cluster. The scheduler places pods, the controller manager runs reconciliation loops, and the API server validates requests.

  8. Question 8

    A developer needs to expose a web application running in a set of pods to traffic from outside the Kubernetes cluster. The solution must provide Layer 7 routing capabilities, such as routing based on hostname or URL path, and handle SSL/TLS termination. Which combination of Kubernetes objects should be used?

    Answer and explanation

    Correct answer: B

    An Ingress resource is required to manage external access to services in a cluster, specifically for HTTP/HTTPS routing. It provides Layer 7 capabilities like host-based and path-based routing. However, the Ingress resource itself doesn't route traffic directly to pods; it routes traffic to a Kubernetes Service, which then load balances the traffic to the backend pods. Therefore, both an Ingress and a Service are needed to fulfill the requirements.

  9. Question 9

    An organization is adopting a GitOps methodology for managing their Kubernetes applications. They want to ensure that any configuration changes, such as updating a container image version in a Deployment manifest, are automatically synced from their Git repository to the live cluster. The command to apply the manifest is kubectl apply -f _____.yaml. Which VMware Tanzu toolset is specifically designed to enable this declarative, continuous delivery workflow?

    Answer and explanation

    Correct answer: C

    The Carvel tool suite, which is integrated with VMware Tanzu, provides a set of composable, single-purpose tools for application building, configuration, and deployment on Kubernetes. Tools like ytt (for templating), kapp (for deployment), and kapp-controller (a GitOps operator) are specifically designed to facilitate the GitOps workflow described, where declarative configurations in Git are automatically applied and managed on the cluster.

  10. Question 10

    A team is adopting an event-driven architecture to decouple their microservices. They need to select a component that receives events from producers and routes them to the appropriate consumers based on defined rules. What is the standard term for this component in an event-driven architecture?

    Answer and explanation

    Correct answer: B

    In an event-driven architecture, the Event Router (also known as a message broker or event bus) is the central component responsible for receiving events from producers and filtering, transforming, and routing them to interested consumers. This decouples the producers from the consumers, as they do not need to know about each other. The producer simply emits an event to the router.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 236 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon