2V0-621 Flashcards
An administrator wants to provide users restricted access. The users should only be able to perform the following tasks:
- Create and consolidate virtual machine snapshots
- Add/Remove virtual disks
- Snapshot Management
Which default role in vCenter Server would meet the administrator’s requirements for the users?
A. Virtual machine power user
Which two roles can be modified? (Choose two.)
B. Network Administrator
C. Datastore Consumer
An administrator with global administrator privileges creates a custom role but fails to assign any privileges to it.
Which two privileges would the custom role have? (Choose two.)
A. System.View
B. System.Anonymous
An administrator wishes to give a user the ability to manage snapshots for virtual machines.
Which privilege does the administrator need to assign to the user?
A. Datastore.Allocate Space
An object has inherited permissions from two parent objects.
What is true about the permissions on the object?
B. The permissions are combined from both parent objects.
What is the highest object level from which a virtual machine can inherit privileges?
C. Data Center Folder
Which three Authorization types are valid in vSphere? (Choose three.)
A. Group Membership in vsphere.local
B. Global
D. vCenter Server
Which three components should an administrator select when configuring vSphere permissions? (Choose three.)
A. Inventory Object
B. Role
C. User/Group
In which two vsphere.local groups should an administrator avoid adding members? (Choose two.)
A. SolutionUsers
B. Administrators
An administrator has configured three vCenter Servers and vRealize Orchestrator within a Platform Services Controller domain, and needs to grant a user privileges that span all environments.
Which statement best describes how the administrator would accomplish this?
A. Assign a Global Permission to the user.
Which two methods are recommended for managing the VMware Directory Service? (Choose two).
A. Utilize the vmdir command.
B. Manage through the vSphere Web Client.
What are two sample roles that are provided with vCenter Server by default? (Choose two.)
A. Virtual machine User
B. Network Administrator
An administrator would like to use the VMware Certificate Authority (VMCA) as an Intermediate Certificate Authority (CA). The first two steps performed are:
- Replace the Root Certificate
- Replace Machine Certificates (Intermediate CA)
Which two steps would need to be performed next? (Choose two.)
A. Replace Solution User Certificates (Intermediate CA)
C. Replace the VMware Directory Service Certificate
Which three options are available for ESXi Certificate Replacement? (Choose three.)
A. VMware Certificate Authority mode
B. Custom Certificate Authority mode
C. Thumbprint mode
Lockdown Mode has been enabled on an ESXi 6.x host and users are restricted from logging into the Direct Console User Interface (DCUI).
Which two statements are true given this configuration? (Choose two.)
A. A user granted administrative privileges in the Exception User list can login.
B. A user defined in the DCUI.Access without administrative privileges can login.
Strict Lockdown Mode has been enabled on an ESXi host.
Which action should an administrator perform to allow ESXi Shell or SSH access for users with administrator privileges?
B. Add the users to Exception Users and enable the service.
An administrator wants to configure an ESXi 6.x host to use Active Directory (AD) to manage users and groups. The AD domain group ESX Admins is planned for administrative access to the host.
Which two conditions should be considered when planning this configuration? (Choose two.)
A. If administrative access for ESX Admins is not required, this setting can be altered.
C. An ESXi host provisioned with Auto Deploy cannot store AD credentials.
Which password meets ESXi 6.x host password requirements?
A. 8kMVnn2x!
An administrator would like to use a passphrase for their ESXi 6.x hosts which has these characteristics:
- Minimum of 21 characters
- Minimum of 2 words
Which advanced options must be set to allow this passphrase configuration to be used?
B. retry=3 min=disabled, disabled, 21, 7, 7 passphrase=2
Which Advanced Setting should be created for the vCenter Server to change the expiration policy of the vpxuser password?
A. VimPasswordExpirationInDays
An administrator has been instructed to secure existing virtual machines in vCenter Server.
Which two actions should the administrator take to secure these virtual machines? (Choose two.)
B. Restrict Remote Console access
D. Prevent use of Independent Non-Persistent virtual disks
An administrator has recently audited the environment and found numerous virtual machines with sensitive data written to the configuration files.
To prevent this in the future, which advanced parameter should be applied to the virtual machines?
A. isolation.tools.setinfo.disable = true
Which two statements are correct regarding vSphere certificates? (Choose two.)
B. ESXi host upgrades preserve the existing SSL certificate.
C. ESXi hosts have assigned SSL certificates from the VMware Certificate Authority (VMCA)
Which three options are available for replacing vCenter Server Security Certificates? (Choose three.)
A. Replace with Certificates signed by the VMware Certificate Authority.
B. Make VMware Certificate Authority an Intermediate Certificate Authority.
C. Do not use VMware Certificate Authority, provision your own Certificates.
When attempting to log in with the vSphere Web Client, users have reported the error:
Incorrect Username/Password
The administrator has configured the Platform Services Controller Identity Source as:
- Type. Active Directory as an LDAP Server
- Domain: vmware.com
- Alias: VMWARE
- Default Domain: Yes
Which two statements would explain why users cannot login to the vSphere Web Client? (Choose two.)
A. Users are typing the password incorrectly.
B. Users are in a forest that has 1-way trust.
Which group in the vsphere.local domain will have administrator privileges for the VMware Certificate Authority (VMCA)?
B. CAAdmins
Which Platform Service Controller Password Policy determines the number of days a password can exist before the user must change it?
A. Maximum Lifetime
An administrator is configuring the clock tolerance for the Single Sign-On token configuration policy and wants to define the time skew tolerance between a client and the domain controller clock.
Which time measurement is used for the value?
A. Milliseconds
Which VMware Single Sign-On component issues Security Assertion Markup Language (SAML) tokens?
A. VMware Security Token Service
Which two are valid Identity Sources when configuring vCenter Single Sign-On? (Choose two.)
C. OpenLDAP
D. LocalOS
An administrator needs to create an Integrated Windows Authentication (IWA) Identity Source on a newly deployed vCenter Server Appliance (VCSA).
Which two actions will accomplish this? (Choose two.)
A. Use a Service Principal Name (SPN) to configure the Identity Source.
C. Join the VCSA to Active Directory and configure the Identity Source with a Machine Account.
An administrator is creating a new Content Library. It will subscribe to another remote Content Library without authentication enabled.
What information from the published library will they need in order to complete the subscription?
A. Subscription URL
An administrator is assigning a user the Content Library administrator role. The user will only be creating the library for a single vCenter Server.
What is the lowest level of the permission heirarchy that this role can be granted to the user and still allow them to create a Content Library?
A. Global
Which three connection types are supported between a remote site and vCloud Air? (Choose three.)
A. Secure Internet Connectivity
B. Private Connect
E. Secure VPN
An administrator is adding an Active Directory over LDAP Identity Source for vCenter Single Sign- On, as indicated in the Exhibit.
What is the correct value to configure for the Domain alias?
A. The domain’s NetBIOS name.
An administrator decides to change the root password for an ESXi 6.x host to comply with the company’s security policies.
What are two ways that this can be accomplished? (Choose two.)
A. Use the Direct Console User Interface to change the password.
B. Use the passwd command in the ESXi Shell.
An administrator connects to an ESXi 6.x host console in order to shutdown the host.
Which option in the Direct Console User Interface would perform this task?
A. Press the F12 key
An administrator is able to manage an ESXi 6.x host connected to vCenter Server using the vSphere Web Client but is unable to connect to the host directly.
Which action should the administrator take to correct this behavior?
B. Disable Lockdown Mode on the ESXi host through vCenter Server.
An administrator needs two vCenter Servers to be visible within a single vSphere Web Client session.
Which two vCenter Server and Platform Services Controller (PSC) configurations would accomplish this? (Choose two.)
A. Install a single PSC with two vCenter Servers registered to it.
B. Install two PSCs in the same Single Sign-On domain with one vCenter Server registered to each PSC.
An administrator wants to clone a virtual machine using the vSphere Client.
Which explains why the Clone option is missing?
A. The vSphere Client is directly connected to the ESXi host.
An administrator creates a custom ESXi firewall rule using an XML file, however the rules do not appear in the vSphere Web Client.
Which action should the administrator take to correct the problem?
B. Load the new rules using esxcli network firewall refresh.
A common root user account has been configured for a group of ESXi 6.x hosts.
Which two steps should be taken to mitigate security risks associated with this configuration? (Choose two.)
B. Set a complex password for the root account and limit its use.
C. Use ESXi Active Directory capabilities to assign users the administrator role.
Which two advanced features should be disabled for virtual machines that are only hosted on a vSphere system? (Choose two.)
A. isolation.tools.unity.push.update.disable
B. isolation.tools.ghi.launchmenu.change
To reduce the attack vectors for a virtual machine, which two settings should an administrator set to false? (Choose two.)
A. ideX:Y.present
B. serial.present
Which two groups of settings should be reviewed when attempting to increase the security of virtual machines (VMs)? (Choose two.)
A. Disable hardware devices
B. Disable unexposed features
THIS HOST HAS NO MANAGEMENT NETWORK REDUNDANCY
An administrator is changing the settings on a vSphere Distributed Switch (vDS). During this process, the ESXi Management IP address is set to an address which can no longer communicate with the vCenter Server.
What is the most likely outcome of this action?
B. The host will automatically detect the communication issue and revert the change.
Which secondary Private VLAN (PVLAN) type can communicate and send packets to an Isolated PVLAN?
C. Promiscuous
Which three traffic types can be configured for dedicated Vmkernel adapters? (Choose three.)
B. vMotion traffic
C. vSphere Replication NFC traffic
D. Provisioning traffic
What are two limitations of Link Aggregation Control Protocol (LACP) on a vSphere Distributed Switch? (Choose two.)
B. Software iSCSI multipathing is not compatible.
D. It does not support configuration through Host Profiles.
Which two features are deprecated in Network I/O Control 3 (NIOC3)? (Choose two.)
A. Class Of Service (COS) Tagging
C. User-defined network resource pools
An administrator runs the command esxcli storage core device list and sees the following output:
mpx.vmhba1:C0:T0:L0 Display Name: RAID 5 (mpx.vmhba1:C0:T0:L0) Has Settable Display Name: false SizE. 40960 Device Type: Direct-Access Multipath Plugin: NMP Devfs Path: /vmfs/devices/disks/mpx.vmhba1:C0:T0:L0 Status: off Is Local: true
What can be determined by this output?
B. The device is in a Permanent Device Loss (PDL) state.
An administrator notices that there is an all paths down (APD) event occurring for the software FcoE storage.
What is a likely cause?
A. Spanning Tree Protocol is enabled on the network ports.
Which two statements are true regarding iSCSI adapters? (Choose two.)
A. Software iSCSI adapters require vmkernel networking.
B. Independent Hardware iSCSI adapters offload processing from the ESXi host.
Which command shows the Physical Uplink status for a vmnic?
B. esxcli network nic list
An administrator creates a Private VLAN with a Primary VLAN ID of 2. The administrator then creates three Private VLANs as follows:
- Marketing
- PVLAN ID. 4
- PVLAN Type. Isolated
- Accounting
- PVLAN ID. 5
- PVLAN Type. Community - Secretary
- PVLAN ID. 17
- PVLAN Type. Isolated
Users in the Accounting PVLAN are reporting problems communicating with servers in the Marketing PVLAN.
Which two actions could the administrator take to resolve this problem? (Choose two.)
A. Change the PVLAN type for the Accounting network to Promiscuous.
B. Change the PVLAN ID for the Accounting network to 2.
What are two use cases for Fibre Channel Zoning in a vSphere environment? (Choose two.)
B. Controls and isolates paths in a fabric.
D. Can be used to separate different environments.
Which two considerations should an administrator keep in mind when booting from Software Fiber Channel over Ethernet (FCoE)? (Choose two.)
C. Multipathing is not supported at pre-boot.
D. Boot LUN cannot be shared with other hosts even on shared storage.
An administrator is configuring virtual machines to use Worldwide Port Names (WWPNs) to access the storage.
Which two conditions are required? (Choose two.)
A. The switches in the fabric must be N-Port ID Virtualization aware.
B. The virtual machines must be using passthrough Raw Disk Mapping (RDMp).
Which two statements are true regarding VMFS3 volumes in ESXi 6.x? (Choose two.)
A. Creation of VMFS3 volumes is unsupported.
B. Upgrading VMFS3 volumes to VMFS5 is supported.
Which three statements are correct regarding Fibre Channel over Ethernet (FCOE)? (Choose three.)
A. The network switch must have Priority-based Flow Control (PFC) set to AUTO.
D. Each port on the FCoE card must reside on a separate vSwitch.
E. The ESXi host will require a reboot after moving an FCoE card to a different vSwitch.
Which two statements are true regarding Virtual SAN Fault Domains? (Choose two.)
A. They enable Virtual SAN to tolerate the failure of an entire physical rack.
B. Virtual SAN ensures that no two replicas are provisioned on the same domain.
An administrator created a six node Virtual SAN cluster, created a fault domain, and moved three of the six nodes into that domain.
A node that is a member of the fault domain fails.
What is the expected result?
A. The remaining two fault domain members are treated as failed.
Where is a Virtual SAN Fault Domain configured?
A. VMware Virtual SAN Cluster configuration
Which statement is true for the Path Selection Plug-In VMW_PSP_MRU?
D. VMW_PSP_MRU will have no preferred path setting for the Plug-In.
Which two tasks does the Pluggable Storage Architecture (PSA) perform? (Choose two.)
A. Handles I/O queueing to the logical devices.
C. Handles physical path discovery and removal.
Which two statements are true regarding Storage Multipathing Plug-Ins? (Choose two.)
B. The default Path Selection Policy is VMW_PSP_FIXED for iSCSI or FC devices.
C. VMW_PSP_MRU is typically selected for ALUA arrays by default.
What is the command to list multipathing modules on an ESXi 6.x host?
C. esxcli storage core plugin list –plugin-class=MP
Which two solutions require Physical Mode Raw Device Mapping (RDM)? (Choose two.)
A. Direct access to the storage array device
D. Guest Clustering across ESXi hosts
A device’s vStorage API for Array Integration (VAAI) support status command line output shows:
naa.500253825002a865 VAAI Plugin Name: ATS Status: unsupported Clone Status: unsupported Zero Status: supported Delete Status: unsupported
What is the corresponding VAAI support status in the vSphere Web Client?
A. Unknown
What will be the result of selecting the highlighted device?
A. Datastore will grow up to 200.01GB using the remaining free space on the device.
An administrator observes that virtual machine storage activity on an ESXi 6.x host is negatively affecting virtual machine storage activity on another host that is accessing the same VMFS Datastore.
Which action would mitigate the issue?
A. Enable Storage IO Control.
An administrator is having a problem configuring Storage I/O Control on a Datastore.
Which two conditions could explain the issue? (Choose two.)
A. A host is running ESXi 4.0.
B. An ESXi host does not have appropriate licensing.
Which three are requirements for configuring Storage I/O Control (SIOC)? (Choose three.)
A. The datastore must consist of only one extent.
B. The datastore is managed by a single vCenter Server.
C. Auto-tiered storage must be compatable with SIOC.
An administrator wishes to provide Load Balanced I/O for the device shown in the Exhibit.
To meet this requirement, which setting should be changed?
B. Path Selection Policy = Round Robin (VMware)
An administrator is configuring a storage device as shown in the Exhibit.
What is the expected effect on the stated device after running the command?
B. I/O will rotate on all storage targets that are Active Optimized state only.
A vSphere 6.x environment is configured with VMware Virtual Volumes (VVOLs). An administrator accesses the cluster Actions menu, as shown in the Exhibit.
Which option is used to create a VVOL on an existing VVOL container?
A. Storage
What will be created upon completion of the steps in this wizard?
A. 100GB VMFS5 datastore with free space available for expansion
An administrator is attempting to enable Enhanced vMotion Compatibility (EVC), but receives the error shown in the Exhibit.
Which condition would explain the error?
C. The ESXi host CPU has the Intel No-Execute feature disabled.
The list of devices attached to vmhba1 will be the basis for configuring a VMware Virtual SAN using Manual Mode.
Based on the exhibit, which two combinations of devices should be used to create Disk Group(s)? (Choose two.)
A. One Disk Group with one Flash Drive and three HDDs
B. Two Disk Groups with one Flash Drive and two HDDs each
An administrator is using the esxtop command to troubleshoot storage performance issues on a virtual machine. The esxtop capture is shown in the Exhibit.
Based on the exhibit, which two statements are true? (Choose two.)
A. The iSCSI device is experiencing high latency.
C. The Guest OS is experiencing high latency and response time.
An administrator needs to recover disk space on a previously-used thin provisioned virtual disk. The volumes where the administrator needs to recover the disk blocks are on VAAI-compliant storage arrays.
Which two actions should the administrator take accomplish this task? (Choose two.)
B. Use VMware Converter to migrate the virtual machine to a new datastore. This will recreate the volumes and recover all unused space.
D. Execute the esxcli storage vmfs unmap command.
An administrator recently created a Virtual SAN but no Storage Policies were defined. A few virtual machines were deployed to this cluster. The administrator analyzes the default Virtual SAN policy as shown in the Exhibit.
Based on the exhibit, which two statements are true? (Choose two.)
A. Losing one cluster node will not affect data availability.
B. Losing one Hard Disk in a cluster node will not affect data availability.
A Storage Policy for a Virtual SAN is set to the default policy, as shown in the Exhibit.
Which change would reduce the storage consumption by one third?
A. Number of failures to tolerate = 1
An administrator would like to add Challenge Handshake Authentication Protocol (CHAP) to an iSCSI adapter. The administrator accesses the Storage Adapters menu as shown in the Exhibit.
In which tab can the task be accomplished?
A. Properties
An administrator is writing a kickstart script to upgrade an ESXi 6.x host.
In which three locations can the script reside? (Choose three.)
A. NFS
B. USB
C. HTTP
Which file determines the location of the installation script during a scripted upgrade?
A. boot.cfg
What three supported methods can be used to upgrade a host from ESXi 5.x to ESXi 6.x? (Choose three.)
A. vSphere Update Manager
C. esxcli
D. vSphere Auto Deploy
Which two supported tools can be used to upgrade virtual machine hardware? (Choose two.)
A. vSphere Web Client
B. vSphere Update Manager
What are three recommended prerequisites before upgrading virtual machine hardware? (Choose three.)
A. Create a backup or snapshot of the virtual machine.
B. Upgrade VMware Tools to the latest version.
C. Verify that the virtual machine is stored on VMFS3, VMFS5, or NFS datastores.
An administrator wants to upgrade to vCenter Server 6.x.
The vCenter Server:
- Is hosted on a virtual machine server running Microsoft Windows Server 2008 R2, with 8 vCPUs and 16GB RAM.
- Will have an embedded Platform Services Controller.
- Hosts a Large Environment with 1,000 ESXi hosts and 10,000 Virtual Machines.
Why does the vCenter Server not meet the minimum requirements?
B. The virtual machine has insufficient resources for the environment size.
An administrator has upgraded a Distributed vCenter Server environment from 5.5 to 6.0.
What is the next step that should be taken?
A. vCenter Inventory Service must be manually stopped and removed.
When upgrading vCenter Server, an administrator notices that the upgrade fails at the vCenter Single Sign-On installation.
What must be done to allow the upgrade to complete?
A. Verify that the VMware Directory service can stop by manually restarting it.
During a vCenter Server upgrade, an ESXi 6.x host in a High Availability (HA) cluster fails.
Which statement is true?
A. HA will fail the virtual machines over to an available host during the vCenter Server upgrade process.
An administrator is upgrading a vCenter Server Appliance and wants to ensure that all the prerequisites are met.
What action must be taken before upgrading the vCenter Server Appliance?
A. Install the Client Integration Plug-in.
An administrator is upgrading vCenter Server and sees this error:
The DB User entered does not have the required permissions needed to install and configure vCenter Server with the selected DB. Please correct the following error(s): %s
Which two statements explain this error? (Choose two.)
A. The database is set to an unsupported compatibility mode.
B. The permissions for the database are incorrect.
Which two vCenter Server services are migrated automatically as part of an upgrade from a Distributed vCenter Server running 5.x? (Choose two.)
B. vSphere Web Client
C. vSphere Inventory Service