VMware vSphere with Tanzu Specialist Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 208 questions. Use the simulator for timed and flashcard mode.

Try Simulator

5V0-23-20 Sample Questions

  1. Question 1

    Q1

    A DevOps engineer is attempting to deploy a new Tanzu Kubernetes Cluster (TKC) into a vSphere Namespace. The deployment fails with an error message indicating 'no suitable VM class found'. The engineer has confirmed that multiple VM classes are defined in the Supervisor Cluster. What is the most likely cause of this issue?

    Show answer & explanation

    Correct answer: A

    VM classes are defined at the Supervisor Cluster level but must be explicitly associated with a vSphere Namespace to be usable within it. If no VM classes are added to the namespace, the Tanzu Kubernetes Grid Service cannot find a suitable class to provision the control plane and worker nodes for a new TKC, leading to this specific error.

  2. Question 2

    Q2Multiple answers

    A platform operator needs to provide developers with different T-shirt sizes for Tanzu Kubernetes Cluster nodes (e.g., small, medium, large). Which two components must be configured to achieve this? (Select TWO)

    Show answer & explanation

    Correct answers: A, B

    VM Classes define the CPU, memory, and reservation settings for virtual machines, directly corresponding to the T-shirt sizes for TKC nodes. Multiple classes must be created to offer different sizes.

    After VM Classes are created at the Supervisor Cluster level, they must be assigned to the specific vSphere Namespace where developers will be deploying their TKCs. This makes the T-shirt sizes available within that namespace.

  3. Question 3

    Q3

    True or False: When using vSphere with Tanzu with the vSphere Distributed Switch (VDS) for networking, a third-party IPAM provider is required for managing IP addresses for vSphere Pods.

    Show answer & explanation

    Correct answer: B

    This statement is false. The Supervisor Cluster provides its own internal IPAM capabilities when configured with VDS networking, eliminating the need for an external or third-party IPAM solution for vSphere Pods.

  4. Question 4

    Q4

    Company Background:
    A financial technology company, FinCorp, is modernizing its monolithic trading application by breaking it down into containerized microservices. They have chosen vSphere with Tanzu to leverage their existing VMware expertise and infrastructure. The environment is configured with NSX-T for advanced networking and security.

    Current Situation:
    The security team has mandated strict network isolation between the different microservices. Specifically, the 'order-processing' service should only be able to communicate with the 'trade-execution' service on TCP port 8080, and the 'trade-execution' service should only be able to initiate communication with the 'market-data' service on TCP port 9000. All other pod-to-pod communication within the namespace must be denied by default.

    Requirement:
    As the vSphere administrator, you must implement a solution using native Kubernetes objects that enforces this traffic flow policy within the 'trading-app' vSphere Namespace.

    Which approach satisfies the security requirement?

    Show answer & explanation

    Correct answer: B

    This is the correct Kubernetes-native approach. A default-deny ingress policy establishes a zero-trust baseline. Then, specific 'allow' ingress policies are created for each service, using pod selectors to precisely define which source pods can connect to which destination pods on specific ports. The NSX Container Plugin (NCP) translates these Kubernetes objects into underlying NSX-T firewall rules automatically.

  5. Question 5

    Q5

    A vSphere administrator is enabling Workload Management and must choose a networking stack. The existing environment uses a vSphere Distributed Switch (VDS) and the primary requirement is to get the Supervisor Cluster operational with minimal changes to the existing network infrastructure. Which component provides load balancing for Kubernetes services in this configuration?

    Show answer & explanation

    Correct answer: C

    When vSphere with Tanzu is configured with VDS networking, a load balancer based on HAProxy is automatically deployed as a virtual machine. This appliance provides Layer 4 load balancing for the Supervisor Cluster's control plane and for Kubernetes services of type LoadBalancer created within the namespaces.

  6. Question 6

    Q6

    The command kubectl vsphere login --server= --tanzu-kubernetes-cluster-name --vsphere-username is used to authenticate to a Tanzu Kubernetes Cluster. Where does the resulting authentication context get stored?

    Show answer & explanation

    Correct answer: C

    The kubectl vsphere login command authenticates the user against vCenter SSO and retrieves a temporary token. It then adds a new context, cluster, and user entry to the user's local kubeconfig file (typically located at ~/.kube/config), allowing subsequent kubectl commands to be authenticated against the target cluster.

  7. Question 7

    Q7

    A developer needs to deploy a stateful application that requires 50 GiB of high-performance storage. The vSphere administrator has created a storage policy named 'fast-ssd' which is backed by an all-flash vSAN datastore. How can the developer request storage that adheres to this policy for their application?

    Show answer & explanation

    Correct answer: B

    The standard Kubernetes method for requesting storage is to create a PersistentVolumeClaim (PVC). In a vSphere with Tanzu environment, vSphere storage policies are automatically exposed as StorageClasses. The developer creates a PVC manifest that specifies the size requirement (50 GiB) and sets the storageClassName field to 'fast-ssd'. This tells vSphere to provision a persistent volume on a datastore that complies with the 'fast-ssd' policy.

  8. Question 8

    Q8

    What is the primary role of the Spherelet component running on each ESXi host in a Supervisor Cluster?

    Show answer & explanation

    Correct answer: B

    The Spherelet is a VMware-developed equivalent of a Kubelet that is integrated directly into the ESXi hypervisor. It allows the Supervisor Cluster's Kubernetes control plane to communicate with the ESXi host, register it as a node, and manage the lifecycle of vSphere Pods directly on the hypervisor, providing a secure and performant way to run containers.

  9. Question 9

    Q9

    An administrator needs to update the Kubernetes version of a running Tanzu Kubernetes Cluster (TKC). Which is the correct procedure to perform this upgrade in a supported manner?

    Show answer & explanation

    Correct answer: C

    Tanzu Kubernetes Clusters are managed declaratively via a Custom Resource Definition (CRD). The supported method to trigger a rolling upgrade is to edit the cluster's manifest, change the Kubernetes version specified in the distribution.version field to a supported, available version, and then re-apply the manifest. The TKG controllers will then orchestrate a rolling update of the control plane and worker nodes.

  10. Question 10

    Q10

    A vSphere administrator has enabled the Harbor Image Registry service on a Supervisor Cluster. A developer reports that they are unable to push container images to the registry, receiving an 'authentication required' error. The developer is a member of a group that has 'Edit' permissions on the vSphere Namespace. What is the most likely reason for this failure?

    Show answer & explanation

    Correct answer: A

    Permissions on the vSphere Namespace (like 'Edit' or 'View') do not automatically grant access to the integrated Harbor registry. Harbor maintains its own authentication. Users must perform a separate docker login command using their vCenter SSO username and password. This authenticates their client session specifically with the registry service.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the 5V0-23-20 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 208 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon