Cloud, Associate (JNCIA-CLOUD) Free Sample Questions

20 free sample questions243 in the full practice test

Try simulator

JN0-214 Sample Questions

  1. Question 1

    A financial services company is deploying a private cloud using OpenStack Zed. The security policy mandates that all administrative actions performed via the OpenStack APIs must be auditable and tied to a specific user identity. Which OpenStack component is primarily responsible for enforcing this policy by managing user authentication and service catalogs?

    Answer and explanation

    Correct answer: C

    Keystone is the identity service for OpenStack. It provides API client authentication, service discovery, and distributed multi-tenant authorization by implementing OpenStack's Identity API. All other OpenStack services use Keystone to validate user requests and locate other services, making it central to security and auditability. Nova is the compute service, Neutron is the networking service, and Cinder is the block storage service.

  2. Question 2

    A cloud administrator is configuring an overlay network for a multi-tenant environment and requires the ability to carry both Layer 2 MAC and Layer 3 IP information within the control plane. The solution must be highly scalable and use a standards-based protocol for advertising network reachability. Which technology combination best fulfills these requirements?

    Answer and explanation

    Correct answer: C

    EVPN (Ethernet VPN) uses BGP as a control plane to distribute Layer 2 MAC address and Layer 3 IP reachability information, which is ideal for large-scale overlay networks. When used with a VXLAN data plane, it provides a highly scalable and standards-based solution that avoids the need for flood-and-learn mechanisms. VLANs with STP are not an overlay technology and have scaling limitations. VXLAN with multicast relies on flooding, which is less scalable than a BGP control plane. GENEVE is a flexible encapsulation but does not define its own control plane.

  3. Question 3

    Multiple answers

    A DevOps team is using an OpenShift 4.10 cluster for their CI/CD pipeline. They need to run specialized build tools that have high resource requirements and should not compete for resources with regular application workloads. Additionally, these build pods need to be scheduled on specific nodes that have been provisioned with extra CPU and memory. Which two OpenShift node types should be used to achieve this separation? (Select TWO).

    Answer and explanation

    Correct answers: B, D

    Worker nodes (or compute nodes) are where standard application workloads run. The specially provisioned nodes for the builds would be a subset of worker nodes, often with specific labels.

    Infrastructure nodes are designated to run parts of the OpenShift platform stack, like the registry, router, and monitoring components. By moving these services to dedicated infrastructure nodes, and scheduling heavy build pods there as well (via taints and tolerations), you can effectively isolate them from the general application workloads running on standard worker nodes.

  4. Question 4

    True or False: In a Software-Defined Networking (SDN) architecture, the control plane is distributed across all networking devices, and each device makes independent forwarding decisions based on its local configuration.

    Answer and explanation

    Correct answer: B

    The statement describes a traditional networking architecture. The fundamental principle of SDN is the separation of the control plane from the data plane. In SDN, the control plane is centralized in an SDN controller, which makes intelligent forwarding decisions for the entire network. The networking devices (data plane) simply execute the forwarding instructions received from the controller.

  5. Question 5

    A developer is writing a YAML manifest for an application deployment on a Kubernetes 1.24 cluster. The application needs a persistent storage volume that survives pod restarts. The cluster administrator has already provisioned several backend storage options via the StorageClass API. Which Kubernetes API object must the developer define in their manifest to request storage from a pre-defined StorageClass?

    Answer and explanation

    Correct answer: C

    A PersistentVolumeClaim (PVC) is a request for storage by a user. The developer's pod manifest will reference a PVC. The PVC, in turn, specifies requirements like size and access mode, and can name a StorageClass to dynamically provision a PersistentVolume (PV) that satisfies the claim. The PV is the actual storage resource, typically managed by the administrator, while the PVC is the developer's request for that resource.

  6. Question 6

    A startup is launching a new web application and wants to minimize initial capital expenditure on hardware and reduce the burden of infrastructure management. Their development team is small and prefers to focus solely on writing and deploying application code, without managing the underlying operating systems, patches, or server scaling. Which cloud service model is the most appropriate choice for this startup?

    Answer and explanation

    Correct answer: B

    Platform as a Service (PaaS) is the ideal model because it abstracts away the underlying infrastructure, including servers, operating systems, and patching. The cloud provider manages the platform, allowing the development team to focus exclusively on their application code and data. IaaS would still require them to manage the OS and scaling, while SaaS involves consuming a finished software product, not deploying their own code.

  7. Question 7

    During the deployment of a Virtual Network Function (VNF) such as a virtual firewall, an administrator observes high latency and packet loss. The VNF is running on a KVM hypervisor. The administrator suspects that the performance issue is related to how the VNF interacts with the physical network interface card (NIC). Which technology would provide the most significant performance improvement by allowing the VNF to bypass the hypervisor's virtual switch and interact directly with the physical NIC?

    Answer and explanation

    Correct answer: B

    Single Root I/O Virtualization (SR-IOV) is a specification that allows a single physical PCIe device, like a NIC, to appear as multiple separate physical devices. It enables the VNF's virtual function (VF) to be directly mapped to the physical function (PF) of the NIC, bypassing the hypervisor's networking stack (like vSwitch). This direct hardware access dramatically reduces latency and increases throughput, which is critical for performance-sensitive VNFs. VXLAN offloading helps with encapsulation but doesn't solve the hypervisor bypass issue. OVS and Linux bridge are virtual switches that the VNF would be bypassing.

  8. Question 8

    A cloud architect is designing a solution that requires flexible metadata to be carried within network overlay packets to signal information to different network functions and endpoints. The existing overlay solution, VXLAN, is too rigid as its header is fixed. The architect needs an encapsulation protocol designed for extensibility. Which network virtualization encapsulation technology should be selected?

    Answer and explanation

    Correct answer: D

    GENEVE (Generic Network Virtualization Encapsulation) was specifically designed to be more flexible and extensible than VXLAN. Its key feature is a variable-length header that can carry flexible metadata using Type-Length-Value (TLV) options. This allows different vendors and applications to insert custom information into the overlay packet without requiring a new encapsulation protocol, making it ideal for the architect's requirements.

  9. Question 9

    A systems administrator is tasked with deploying a containerized application on a Linux host using Docker. The application inside the container needs to bind to port 80, but the host's port 80 is already in use by another service. The administrator wants to map port 8080 on the host to port 80 in the container. Which Docker networking mode and command flag should be used to achieve this?

    Answer and explanation

    Correct answer: B

    Bridge mode is the default networking mode in Docker, creating a private network for containers. The --publish (or -p) flag is used for port mapping in the format HOST_PORT:CONTAINER_PORT. To map port 8080 on the host to port 80 in the container, the correct flag is --publish 8080:80. Host mode would share the host's network namespace, causing a port conflict with the existing service on port 80.

  10. Question 10

    An organization uses OpenStack Heat templates written in YAML to automate the deployment of multi-tier applications. A junior administrator is reviewing a template and needs to understand how one resource, like a virtual machine instance, can be configured to use a network port that is defined elsewhere in the same template. Which section of the Heat template is used to establish this kind of relationship and dependency?

    Answer and explanation

    Correct answer: C

    Within the resources section of a Heat template, the get_resource intrinsic function is used to reference another resource defined within the same template. For example, the properties of an OS::Nova::Server resource would use { get_resource: my_network_port } to associate itself with an OS::Neutron::Port resource named my_network_port. This creates an implicit dependency, ensuring the port is created before the server instance.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 243 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon