A DevOps team is experiencing inconsistent application behavior in KVM guests running on a NUMA-based host. Performance analysis indicates that VMs are frequently accessing memory from remote NUMA nodes, causing high latency. Which virsh subcommand should be used to inspect the current NUMA configuration and CPU pinning for a running domain named app-vm1?
Answer and explanation
Correct answer: C
The virsh numatune command is specifically designed to display and modify NUMA parameters for a running virtual machine. This command provides details on memory node binding and vCPU to physical CPU pinning, which is essential for diagnosing and resolving NUMA-related performance issues. vcpuinfo shows vCPU state but not pinning, nodeinfo shows host NUMA details but not the VM's configuration, and memtune controls overall memory limits, not NUMA placement.
Question 2
Multiple answers
An administrator is building a minimal, secure Docker image for a Go application. To reduce the attack surface and image size, they are using a multi-stage build. Which of the following are key benefits of this approach? (Select TWO)
Answer and explanation
Correct answers: A, D
Multi-stage builds allow you to use one stage with a full SDK to build the application (e.g., golang:1.19) and a subsequent stage to copy only the compiled binary into a minimal base image (e.g., scratch or alpine). This ensures that build-time dependencies, compilers, and source code are not present in the final image, dramatically reducing its size and attack surface. It does not automatically handle image signing or affect the build cache in the described manner.
Question 3
A system administrator needs to convert a VMware VMDK disk image (source.vmdk) to a QCOW2 format for use with KVM, while also enabling compression and preallocating all metadata to improve performance. Which qemu-img convert command achieves this?
Answer and explanation
Correct answer: B
The correct command is qemu-img convert -f vmdk -O qcow2 -c -o preallocation=metadata source.vmdk target.qcow2. The -f flag specifies the source format, -O specifies the output format. The -c flag is the shorthand for enabling qcow2 compression. The -o flag is used for format-specific options, and preallocation=metadata tells qemu-img to create a non-sparse image where only the metadata is preallocated, which can improve performance by avoiding metadata fragmentation.
Question 4
You are tasked with setting up a highly available LXD cluster for running critical system containers. During the initialization of the second cluster node, you are prompted for the address of an existing cluster member. After providing the address and the trust password, the join process fails with a network timeout. The nodes are on the same subnet, and basic ping tests between them are successful. What is the most likely cause of this failure?
Answer and explanation
Correct answer: B
LXD clustering relies on communication over TCP port 8443 for its API and internal raft consensus protocol. While ICMP (ping) may be allowed, a common security practice is to block most incoming ports by default. A network timeout during the join process, despite successful ping tests, strongly indicates that a firewall is blocking the specific port LXD requires for cluster communication. Storage pool names being different or NTP issues would typically result in different error messages after the initial connection is established.
Question 5
True or False: When using the libvirt provider in Vagrant, the Vagrantfile must explicitly define a private network for the VM to be accessible from the host, as no default NAT network is created automatically.
Answer and explanation
Correct answer: B
False. By default, the vagrant-libvirt provider will attempt to connect the VM to libvirt's 'default' virtual network, which is typically a NAT-based network. This allows the VM to access the external network and provides a DHCP-assigned IP address. While defining a private network (config.vm.network "private_network") is a common practice for stable host-to-guest communication, it is not strictly required for the VM to get network connectivity upon creation.
Question 6
A financial services company is containerizing a legacy application. For compliance reasons, they must strictly control the system calls the container can make to the host kernel. The security team has provided a JSON file (profile.json) defining an allowed list of syscalls. Which Docker command correctly applies this seccomp profile to a container named legacy-app?
Answer and explanation
Correct answer: A
The correct way to apply a custom seccomp profile to a Docker container is by using the --security-opt flag. The syntax is seccomp= . This instructs the container runtime to load the specified profile and restrict the container's allowed system calls to only those defined in the file. The other options use incorrect flags (--seccomp-profile, --apparmor) or incorrect syntax for the security option.
Question 7
A systems engineer is managing a Xen hypervisor and needs to perform maintenance on the host. Before shutting down, they want to save the exact memory state of a critical Para-Virtualized (PV) domain named db-server-pv to disk so it can be resumed quickly later. Which xl command should be used to accomplish this?
Answer and explanation
Correct answer: C
The xl save command is used to stop a domain and save its current state, including its entire memory content, to a file on disk. The domain is terminated on the hypervisor after the save is complete. This state can then be restored later using xl restore. xl snapshot is for disk snapshots, xl suspend pauses the domain but keeps its state in the host's memory, and xl migrate moves a running domain to another host.
Question 8
You are designing a libvirt network architecture to isolate a group of development VMs from the main production network while still allowing them to access the internet. The requirements are: the VMs should be on their own private subnet (192.168.100.0/24), they should obtain IPs via DHCP, and their outbound traffic should be NAT-ed through the host's primary network interface. Which type of libvirt virtual network should you create?
Answer and explanation
Correct answer: C
A NAT-forwarded network is the standard libvirt configuration that meets these requirements. It creates a virtual bridge, runs a DHCP server to assign IPs to VMs on a private subnet, and uses iptables rules on the host to perform Network Address Translation (NAT) for outbound traffic. This isolates the VMs while providing them with internet access. A bridged network would place them on the same L2 network as the host, an isolated network would prevent internet access, and a routed network requires additional static routes on the external network.
Question 9
A team is using Packer to build golden images for both AWS (AMI) and local QEMU (QCOW2) environments from a single HCL template. They need to run a shell script (setup.sh) to configure the base OS, but this script requires environment-specific variables. For AWS, it needs the AWS_REGION, and for QEMU, it needs a BUILD_TYPE variable set to local. How can this be achieved within the Packer template?
Answer and explanation
Correct answer: A
The most effective way to handle builder-specific provisioning is to use a single provisioner block with different environment_vars for each builder, controlled by only or except clauses. However, since the variables are different, a cleaner approach is to use two distinct provisioner blocks. One block would have only = ["amazon-ebs"] and set AWS_REGION, while the other would have only = ["qemu"] and set BUILD_TYPE. This provides clear separation and ensures the correct environment variables are passed to the script depending on which builder is active.
Question 10
Case Study: A media company is migrating its video transcoding service to a containerized architecture. The service consists of a front-end web application that accepts uploads, a RabbitMQ message queue, and multiple back-end worker containers that perform the CPU-intensive transcoding tasks.
The lead architect has defined the following requirements:
The entire multi-container application must be definable in a single, portable configuration file for easy deployment in development and staging.
The worker containers must not expose any ports to the host or external network, but they must be able to connect to the RabbitMQ container.
The front-end container needs to be accessible from the host machine on port 8080.
A persistent volume is required for the RabbitMQ container to ensure message durability across restarts.
Which technology and configuration strategy best satisfies all of these requirements?
Answer and explanation
Correct answer: C
Docker Compose is the ideal tool for this scenario, as it allows defining a multi-container application in a single YAML file (Req 1). By default, Compose creates a custom bridge network for the application, allowing all services to communicate via their service names (e.g., rabbitmq) without exposing ports (Req 2). The ports mapping for the frontend service satisfies Req 3. Defining a named volume at the top level and mounting it into the RabbitMQ service provides persistent storage (Req 4). Kubernetes is a more complex solution than required, and the manual script approach lacks the declarative and portable nature of Compose.