VMware Certified Professional - Tanzu for Kubernetes Operations Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 228 questions. Use the simulator for timed and flashcard mode.

Try Simulator

2V0-71-23 Sample Questions

  1. Question 1

    Q1

    A platform engineering team is using Tanzu Mission Control (TMC) to manage a large fleet of Tanzu Kubernetes Grid (TKG) workload clusters. They need to ensure that all clusters within the 'pci-environment' cluster group use a specific, hardened OVA for their nodes and are restricted to a single vSphere resource pool. Which TMC policy type should be configured to enforce these infrastructure-level constraints?

    Show answer & explanation

    Correct answer: B

    A custom policy in Tanzu Mission Control allows administrators to enforce specific configurations defined in a template, which can include infrastructure-level settings like VM image (OVA) and resource pool placement. This provides the necessary flexibility to enforce hardware and image standards that are not covered by other predefined policy types.

  2. Question 2

    Q2

    A DevOps team is deploying a new TKG workload cluster on vSphere with Tanzu. The application requires access to two distinct networks: a corporate backend network for database access and a separate DMZ network for public-facing traffic. Which Tanzu package must be installed and configured on the cluster to enable pods to have multiple network interfaces?

    Show answer & explanation

    Correct answer: D

    Multus CNI is a container network interface (CNI) plugin for Kubernetes that enables attaching multiple network interfaces to pods. It acts as a 'meta-plugin' that can call other CNI plugins to configure the additional interfaces, which is exactly what is required for pods that need to connect to multiple distinct networks.

  3. Question 3

    Q3

    An administrator is configuring a Supervisor Cluster in a vSphere with Tanzu environment. They need to provide developers with three standardized T-shirt sizes for Kubernetes nodes: small, medium, and large. Which vSphere with Tanzu construct should the administrator create to define these standardized node sizes?

    Show answer & explanation

    Correct answer: A

    A VM Class in vSphere with Tanzu defines a template for the size and resources (CPU, memory, storage) of a virtual machine. Administrators create these classes to offer standardized 'T-shirt sizes' for nodes in Tanzu Kubernetes Grid workload clusters, which developers can then select when provisioning their clusters.

  4. Question 4

    Q4Multiple answers

    A security team wants to enforce a policy in Tanzu Mission Control that prevents any container image with a 'High' or 'Critical' CVE from being deployed to production clusters. They also want to ensure that only images from the company's approved Harbor registry can be used. Which TWO policy types in TMC should be configured to meet these requirements? (Select TWO)

    Show answer & explanation

    Correct answers: A, B

    The image registry policy is used to whitelist approved container registries, satisfying the requirement to only allow images from the company's Harbor instance.

    The security policy in TMC is used to enforce various security controls, including the ability to block deployments of images that have vulnerabilities exceeding a specified threshold (e.g., 'High' or 'Critical' CVEs).

  5. Question 5

    Q5

    True or False: When a vSphere with Tanzu Supervisor Cluster is enabled on a vSphere cluster, the ESXi hosts in that cluster become worker nodes that can run native Kubernetes pods scheduled directly by the Supervisor Cluster's control plane.

    Show answer & explanation

    Correct answer: A

    This is a fundamental concept of vSphere with Tanzu. Enabling the Supervisor Cluster transforms the vSphere cluster into a Kubernetes platform. The ESXi hosts are enhanced with a Spherelet (the vSphere equivalent of a Kubelet), allowing them to function as Kubernetes worker nodes and run pods directly on the hypervisor.

  6. Question 6

    Q6

    A platform operator is deploying a new Tanzu Kubernetes Grid (TKG) management cluster to a vSphere environment using the CLI. The deployment fails during the provider resource creation step. Upon reviewing the logs, the operator suspects an issue with the credentials used to connect to vCenter. Which command should the operator use to verify and, if necessary, regenerate the vSphere credentials stored in the local Tanzu configuration?

    Show answer & explanation

    Correct answer: A

  7. Question 7

    Q7

    A financial services company has deployed Tanzu Service Mesh across their hybrid environment, which includes TKG clusters on-premises and in AWS. They have created a Global Namespace (GNS) for their 'trading-app' to facilitate secure, cross-cluster communication. A new regulation requires that all traffic between the 'market-data' service and the 'order-processing' service within this GNS must be mutually authenticated using mTLS. How should an administrator enforce this requirement?

    Show answer & explanation

    Correct answer: B

    Tanzu Service Mesh manages cross-cluster security through policies applied at the Global Namespace level. To enforce mutual TLS (mTLS) for all services within a GNS, the administrator should configure an authentication policy for that GNS and set the mTLS mode to STRICT. This ensures that all service-to-service communication is encrypted and mutually authenticated, regardless of which cluster the services are running in.

  8. Question 8

    Q8

    During the deployment of a TKG cluster on vSphere, the process fails. An operator runs tanzu cluster get and observes that the control plane nodes are stuck in the 'Provisioning' phase. Which underlying technology is responsible for the declarative reconciliation of the cluster's state against the vSphere infrastructure?

    Show answer & explanation

    Correct answer: C

    Cluster API (CAPI) is the core Kubernetes project that TKG uses for declarative, API-driven cluster lifecycle management. When a cluster is created, CAPI controllers in the management cluster constantly work to reconcile the desired state (e.g., '3 control plane nodes') with the actual state of the infrastructure provider (in this case, vSphere). A failure in this process, causing nodes to be stuck in 'Provisioning', points to an issue within the CAPI reconciliation loop.

  9. Question 9

    Q9

    Case Study:

    A healthcare organization is modernizing its patient portal application using VMware Tanzu for Kubernetes Operations. They have a vSphere 7.0U3 environment with vSAN as the primary datastore. A Supervisor Cluster has been successfully deployed, and a vSphere Namespace called 'patient-portal-prod' has been created for the development team.

    The application consists of several microservices, including a stateful database component that requires persistent storage with high availability. The security team mandates that all application traffic must be routed through a centralized ingress point with TLS termination, and developers must not have permissions to create their own ingress objects.

    The operations team needs to ensure they can back up the entire 'patient-portal-prod' namespace, including persistent volumes, to an S3-compatible object store for disaster recovery. They also need to provide developers with a simple way to deploy the application stack without managing complex Kubernetes YAML manifests.

    Which combination of Tanzu components and configurations best meets all the stated requirements?

    Show answer & explanation

    Correct answer: A

    This solution correctly addresses all requirements. A vSphere Storage Policy for vSAN provides the highly available persistent storage. Contour serves as the centralized ingress controller. Velero, integrated with Tanzu Mission Control, handles the namespace and PV backups to S3. Packaging the application as a Carvel package and adding it to the TMC Catalog provides the simplified deployment method for developers.

  10. Question 10

    Q10

    An SRE is troubleshooting application latency in a Kubernetes cluster that is monitored by Aria Operations for Applications (formerly Tanzu Observability). The SRE needs to identify which specific microservice call in a distributed transaction is causing the slowdown. Which capability of Aria Operations for Applications is essential for this type of analysis?

    Show answer & explanation

    Correct answer: C

    Distributed tracing is the specific observability capability designed to track requests as they flow through multiple microservices in a distributed system. It allows an SRE to visualize the entire path of a transaction, see the duration of each service call (span), and pinpoint the exact location of latency bottlenecks.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the 2V0-71-23 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 228 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon