The Best 5V0-23.20 Exam Study Material Premium Files and Preparation Tool (Jan-2024) [Q57-Q82]

Share

The Best 5V0-23.20 Exam Study Material Premium Files and Preparation Tool (Jan-2024)

Get Instant Access to 5V0-23.20 Practice Exam Questions

NEW QUESTION # 57
A developer is connecting to a Tanzu Kubernetes Cluster using the kubectl vsphere login command Which information must be specified, in addition to both the name of the cluster and the Supervisor Cluster Control Wane IP?

  • A. The path to the existing kubeconfig file and the Token D for the SSO credentials
  • B. The name of the Supervisor Namespace and the SSO Username
  • C. The name of the Supervisor Namespace and the Token ID for the SSO credentials
  • D. The path to the existing kubeconfig file and the SSO Username

Answer: A


NEW QUESTION # 58
To which set of networks are the Supervisor Cluster nodes attached when deploying with an NSX-T network topology?

  • A. Frontend and Workload
  • B. Workload and NSX Overlay
  • C. Frontend and Management
  • D. Management and NSX Overlay

Answer: A


NEW QUESTION # 59
How does Kubernetes implement the vSphere storage policy in vSphere with Tanzu?

  • A. Persistent Volume
  • B. Storage class
  • C. Static Persistent Volume
  • D. Paravirtual CSl

Answer: B

Explanation:
Explanation
When vSphere with Tanzu converts storage policies that you assign to namespaces into Kubernetes storage classes, it changes all upper case letters into lower case and replaces spaces with dashes (-). To avoid confusion, use lower case and no spaces in the VM storage policy names.
Storage Policy Based Management is a vCenter Server service that supports provisioning of persistent volumes and their backing virtual disks according to storage requirements described in a storage policy.


NEW QUESTION # 60
Which corresponding object is automatically created in the embedded Registry Service when a new Namespace is created in the Supervisor Cluster?

  • A. Image
  • B. Pod
  • C. Project
  • D. Container

Answer: C


NEW QUESTION # 61
Why would an organization set up private image registries?

  • A. Role-based access control can be assigned by integrating the image registry with user identity management.
  • B. Public image registries lack enterprise support.
  • C. Open source registry server projects enable organizations to modify them as necessary.
  • D. DevOps engineers are able to store virtual machine images in a central location.

Answer: A

Explanation:
Explanation

VMware created Harbor in 2014. Harbor was shared with the community through an open-source license in 2016 and donated to the Cloud Native Computing Foundation (CNCF) in 2018.
Harbor is integrated into VMware products: vSphere Integrated Containers, Tanzu Kubernetes Grid Integrated Edition, and vSphere with Tanzu. The embedded Harbor for vSphere with Tanzu includes the following features: * Identity integration and role-based access control
* Graphical user interface
* Auditing of operations
* Management with labels


NEW QUESTION # 62
What is required to enable Workload Management?

  • A. Windows Network Load Balancer
  • B. vSphere Distributed Switch
  • C. NSX-V
  • D. Github repository

Answer: B

Explanation:
Explanation
https://docs.vmware.com/en/VMware-vSphere/7.0/vsphere-esxi-vcenter-server-702-vsphere-with-tanzu-guide.pd Configuring Workload Networks You configure one or more workload networks and their respective IP address ranges.
Each workload network is assigned a vSphere Distributed Switch port group and uses a defined IP range to allocate IP addresses to workloads (VMware Tanzu Kubernetes clusters).


NEW QUESTION # 63
Which kubectl command is used to deploy the application when using a Kubernetes deployment specification file, my-app.yaml?

  • A. kubectl apply spec my-app.yaml
  • B. kubectl apply -f my-app.yaml
  • C. kubectl run my-app.yaml
  • D. kubectl create my-app.yaml

Answer: B


NEW QUESTION # 64
A developer is trying to deploy a Kubernetes Application into a namespace within a Supervisor Cluster The deployment must utilize the latest assets that have been pushed into the Registry Service.
What should the developer add to the YAML file to ensure that the deployment is successful?

  • A. image: /<namespace>/<image name>:latest
  • B. template: /<namespace name>/<image name>:latest
  • C. template: <image registry url>/<namespace name>/<image name> : latest
  • D. image: <image registry url>/<namespace name>/<image name>:latest

Answer: D

Explanation:
Create an example pod spec with the details about the private registry.
apiVersion: v1
kind: Pod
metadata:
name: <workload-name>
namespace: <kubernetes-namespace>
spec:
containers:
- name: private-reg-container
image: <Registry-IP-Address>/<vsphere-namespace>/<image-name>:<version> imagePullSecrets:
- name: <registry-secret-name>
Replace <workload-name> with the name of the pod workload.
Replace <kubernetes-namespace> with the Kubernetes namespace in the cluster where the pod will be created. This must be the same Kubernetes namespace where the Registry Service image pull secret is stored in the Tanzu Kubernetes cluster (such as the default namespace).
Replace <Registry-IP-Address> with the IP address for the embedded Harbor Registry instance running on the Supervisor Cluster.
Replace <vsphere-namespace> with the vSphere Namespace where the target Tanzu Kubernetes is provisioned.
Replace <image-name> with an image name of your choice.
Replace <version> with an appropriate version of the image, such as "latest".
Replace <registry-secret-name> with the name of the Registry Service image pull secret that you created previously.


NEW QUESTION # 65

Which capability do persistent volumes provide to containerized applications?

  • A. Support for in-memory databases
  • B. Automated disk archival
  • C. Retention of application state and data
  • D. Support for ephemeral workloads

Answer: C

Explanation:
Explanation
Certain Kubernetes workloads require persistent storage to store data permanently. To provision persistent storage for Kubernetes workloads, vSphere with Tanzu integrates with Cloud Native Storage (CNS), a vCenter Server component that manages persistent volumes.
Persistent storage is used by vSphere Pods, Tanzu Kubernetes clusters, and VMs. The following example illustrates how persistent storage is used by a vSphere Pod.
vSphere Pods use different types of storage depending on the objects that are stored. The types of storage are ephemeral virtual machine disks (VMDKs), persistent volume VMDKs, and containers image VMDKs:
* Storage policies for container image and ephemeral disks are defined at the cluster level.
* Storage policies for persistent volumes are defined at the namespace level.
* Networking for vSphere Pods uses the topology provided by NSX.


NEW QUESTION # 66
Which two functions are provided by the NSX Container Rug-in (NCP)? (Choose two.)

  • A. Creates an NSX-T logical topology for a Kubernetes cluster and a separate logical network for each Kubernetes namespace
  • B. Implements Kubernetes Ingress with an NSX-T layer 7 load balancer
  • C. Integrates with container-based PaaS such as Docker
  • D. Configures Overlay Transport Zones
  • E. Implements Kubernetes Ingress with an NSX-T layer 4 load balancer

Answer: A,B

Explanation:
Explanation
NCP provides the following functionalities:
* Automatically creates an NSX-T Data Center logical topology for a Kubernetes cluster, and creates a separate logical network for each Kubernetes namespace.
* Implements Kubernetes Ingress with NSX-T layer 7 load balancer
* Connects Kubernetes pods to the logical network, and allocates IP and MAC addresses.
* Supports network address translation (NAT) and allocates a separate SNAT IP for each Kubernetes namespace.Note:When configuring NAT, the total number of translated IPs cannot exceed 1000.
* Implements Kubernetes network policies with NSX-T Data Center distributed firewall.
* Implements Kubernetes service of type ClusterIP and service of type LoadBalancer.


NEW QUESTION # 67
An organization is preparing to deploy vSphere with Tanzu and will be using the vSphere Networking stack.
How should the administrator allocate management network IP addresses for the Kubernetes Control Plane within the Supervisor Cluster?

  • A. Four IP addresses are required, one for each of the Control Plane VMs and one spare for performing rolling cluster upgrades
  • B. Six IP addresses are required, one for each of the Control Plane VMs, one for the floating IP address of the Control Plane VM. one for performing rolling cluster upgrades and one for the image Registry VM.
  • C. Five IP addresses are required, one for each of the Control Plane VMs. one for the floating IP address of the Control Plane VM, and one spare for performing rolling cluster upgrades
  • D. Three IP addresses are required, one for each of the Control Plane VMs

Answer: C

Explanation:
Static IPs for Kubernetes control plane VMs
Block of 5A block of 5 consecutive static IP addresses to be assigned to the Kubernetes control plane VMs in the Supervisor Cluster.


NEW QUESTION # 68
How can a vSphere administrator replace the Supervisor Cluster API endpoint certificate?

  • A. Use the vSphere Client to replace the Workload platform MTG certificate.
  • B. Use kubectl to replace the Supervisor Cluster API endpoint certificate.
  • C. Use the vSphere Client to replace the NSX Load Balancer certificate.
  • D. Use the certificate-manager CLI utility to replace the Supervisor Cluster API endpoint certificate.

Answer: A

Explanation:

As a vSphere administrator, you can replace the certificate for the virtual IP address (VIP) to securely connect to the Supervisor Cluster API endpoint with a certificate signed by a CA that your hosts already trust. The certificate authenticates the Kubernetes control plane to DevOps engineers, both during login and subsequent interactions with the Supervisor Cluster.
Prerequisites
Verify that you have access to a CA that can sign CSRs. For DevOps engineers, the CA must be installed on their system as a trusted root.
Procedure
In the vSphere Client, navigate to the Supervisor Cluster.
Click Configure then under Namespaces select Certificates.
In the Workload platform MTG pane, select Actions > Generate CSR.
Provide the details for the certificate.
Once the CSR is generated, click Copy.
Sign the certificate with a CA.
From the Workload platform MTG pane, select Actions > Replace Certificate.
Upload the signed certificate file and click Replace Certificate.
Validate the certificate on the IP address of the Kubernetes control plane.


NEW QUESTION # 69
The application development team is pushing a Kubernetes application into production. I consists of an application server and a database. The team wants to ensure that only the production application server can access the production database.
Can the development team meet this requirement using Kubernetes Network Policy?

  • A. Yes. by logging in to NSX Manager and creating a firewall rules to only allow the production application server pod to talk to the database
  • B. No, Kubernetes Network Policy does not support this action.
  • C. Yes, by using kubect1 to create a Network Policy that only allows pods on the same network segment to talk to each other.
  • D. Yes, by using kubect1 to create a policy that disables pod to pod communication in the Namespace

Answer: C

Explanation:
If you want to control traffic flow at the IP address or port level (OSI layer 3 or 4), then you might consider using Kubernetes NetworkPolicies for particular applications in your cluster. NetworkPolicies are an application-centric construct which allow you to specify how a pod is allowed to communicate with various network "entities" (we use the word "entity" here to avoid overloading the more common terms such as "endpoints" and "services", which have specific Kubernetes connotations) over the network. NetworkPolicies apply to a connection with a pod on one or both ends, and are not relevant to other connections.


NEW QUESTION # 70
Which two functions are provided by the NSX Container Rug-in (NCP)? (Choose two.)

  • A. Creates an NSX-T logical topology for a Kubernetes cluster and a separate logical network for each Kubernetes namespace
  • B. Implements Kubernetes Ingress with an NSX-T layer 7 load balancer
  • C. Integrates with container-based PaaS such as Docker
  • D. Configures Overlay Transport Zones
  • E. Implements Kubernetes Ingress with an NSX-T layer 4 load balancer

Answer: A,B


NEW QUESTION # 71
Where are the virtual machine images stored that are used to deploy Tanzu Kubernetes clusters?

  • A. Harbor Image Registry
  • B. Namespace
  • C. Content Library
  • D. Supervisor Cluster

Answer: C

Explanation:
Explanation
The vSphere administrator configures a Subscribed Content Library on the Supervisor Cluster. The virtual machine image that is used for the Tanzu Kubernetes cluster nodes is pulled from this library. A Subscribed Content Library originates from a Published Content Library. After the subscription is created, the system synchronizes it with the published library. To create the Tanzu Kubernetes cluster nodes, VMware publishes a Photon OS OVA library to which you subscribe. After the subscriber is synchronized with the publisher, you associate the content library with the Supervisor Cluster.


NEW QUESTION # 72
An administrator is tasked with increasing the amount of CPU and memory in an existing Tanzu Kubernetes cluster.
Which change must the administrator complete to ensure the cluster scales successfully when updating the YAML definition?

  • A. Increase the number of control plane nodes
  • B. Update the Virtual Machine Class Type
  • C. Increase the number of worker nodes
  • D. Manually update the CPU and memory of the nodes

Answer: B

Explanation:
Explanation
Virtual Machine Class Types for Tanzu Kubernetes Clusters
A virtual machine class defines the resource sizing for Tanzu Kubernetes cluster VMs: * CPU * Memory * Storage Virtual machine class types range from extra small (xsmall) to extra large (xlarge). Class types are categorized as guaranteed or best effort:
* Guaranteed: Reserve all CPU and memory allocations. * Best effort: Allocate the same CPU and memory but do not reserve the resources.
The class type guaranteed-small allocates 2 CPU, 4 GB of memory, and 16 GB of storage and reserves CPU and memory allocations. Custom virtual machine class types cannot be defined.


NEW QUESTION # 73
A development team has deployed a Tanzu Kubernetes cluster and would like to verify the version of Kubernetes that is running. Which command will show this information?

  • A. kubect1 get vm dev-cluster
  • B. kubect1 describe tkc dev-cluster
  • C. kubect1 explain tkg dev-cluster
  • D. kubect1 get version

Answer: A


NEW QUESTION # 74
An administrator needs to configure a Supervisor Cluster with the vSphere networking stack (vSphere Distributed Switch) and HAProxy appliance using default configuration. The administrator has already connected all hosts in the cluster to a vSphere Distributed Switch and created distributed portgroups.
Which designation must be mapped to a distributed portgroup?

  • A. Primary Workload Network
  • B. Supervisor Cluster Network
  • C. Frontend Network
  • D. Load Balancer Network

Answer: B


NEW QUESTION # 75
Which open-source project extends the Docker registry source code to provide an enterprise-class registry server?

  • A. Harbor
  • B. Namespace
  • C. Github
  • D. Manifest

Answer: A


NEW QUESTION # 76
How is information found about all Kubernetes Persistent Volumes in a vSphere environment?

  • A. Using: kubectl get persistentvolumes
  • B. Navigating to the Cloud Native Storage view in vCenter Server
  • C. Using: esxcli storage cloud native get
  • D. Accessing the FCD folder on a Datastore

Answer: B


NEW QUESTION # 77
An administrator is configuring a vSphere with Tanzu Supervisor Cluster with the vSphere networking stack.
Which two minimum requirements must be met for the compute and networking components? (Choose two.)

  • A. The cluster configured with vSphere High Availability enabled
  • B. A minimum of three distinct subnets
  • C. The cluster configured with vSphere DRS enabled and automation level set to Fully Automated
  • D. A DHCP IP address range for the HA Proxy virtual IPs
  • E. A DHCP IP address range for the Kubernetes control plane VMs

Answer: B,C


NEW QUESTION # 78
How do Tanzu Kubemetes clusters communicate with Storage Policy Based Management to request PersistentVolumes?

  • A. Through a proxy VM
  • B. Through the Supervisor Cluster
  • C. Directly with the vCenter Server
  • D. Directly with vCenter Server and the underlying ESXi hosts

Answer: C

Explanation:
Explanation
The Cloud Native Storage for vSphere with Tanzu workflow is as follows:
1. A developer deploys a pod using the kubectl CLI.
2. The vSphere with Tanzu Cloud Native Storage-Container Storage Interface (CNS-CSI) reads this request from the control plane API server.
3. CNS-CSI informs the vCenter Server CNS of the need for a disk with storage class Gold.
4. CNS interfaces with SPBM for a suitable datastore that satisfies the Gold storage class (storage policy).
5. SPBM decides on a suitable datastore and interfaces with DRS for a suitable ESXi host.
6. Hostd on the ESXi host creates a First Class Disk (VMDK) on the datastore.
7. Spherelet on the ESXi host takes the created VMDK.
8. Spherelet mounts the VMDK to the vSphere Pod.
9. Spherelet reports the mount as a successful event to the control plane API server.


NEW QUESTION # 79
An administrator working in a vSphere with Tanzu environment wants to ensure that all persistent volumes configured by developers within a namespace are placed on a defined subset of datastores The administrator has applied tags to the required datastores in the vSphere Client Which action should the administrator take next to meet the requirement?

  • A. Create a storage Policy containing the tagged datastores. and apply it to the Supervisor Cluster.
  • B. Create a persistent volume claim containing the tagged datastores, and apply it to the vSphere Namespace.
  • C. Create a storage policy containing the tagged datastores. and apply it to the vSphere Namespace.
  • D. Create a storage class containing the tagged datastores. and apply it to the Supervisor Cluster

Answer: C

Explanation:

The vSphere administrator defines and assigns VM storage policies to a namespace:
* VM storage policies are translated into Kubernetes storage classes.
* Developers can access all assigned VM storage policies in the form of storage classes.
* Developers cannot manage storage classes.
Storage class names are created in the following way:
* Spaces in VM Storage Policy names are replaced with hyphens (-).
* Special characters are replaced with a digit. A VM Storage Policy called My Gold Policy $ is called my-gold-policy-0 as a storage class.


NEW QUESTION # 80
How does Kubernetes implement the vSphere storage policy in vSphere with Tanzu?

  • A. Persistent Volume
  • B. Storage class
  • C. Static Persistent Volume
  • D. Paravirtual CSl

Answer: B

Explanation:
When vSphere with Tanzu converts storage policies that you assign to namespaces into Kubernetes storage classes, it changes all upper case letters into lower case and replaces spaces with dashes (-). To avoid confusion, use lower case and no spaces in the VM storage policy names.
Storage Policy Based Management is a vCenter Server service that supports provisioning of persistent volumes and their backing virtual disks according to storage requirements described in a storage policy.


NEW QUESTION # 81
An administrator is tasked with increasing the amount of CPU and memory in an existing Tanzu Kubernetes cluster.
Which change must the administrator complete to ensure the cluster scales successfully when updating the YAML definition?

  • A. Increase the number of control plane nodes
  • B. Update the Virtual Machine Class Type
  • C. Increase the number of worker nodes
  • D. Manually update the CPU and memory of the nodes

Answer: B


NEW QUESTION # 82
......

Validate your Skills with Updated 5V0-23.20 Exam Questions & Answers and Test Engine: https://www.testvalid.com/5V0-23.20-exam-collection.html

Reliable Study Materials & Testing Engine for 5V0-23.20 Exam Success!: https://drive.google.com/open?id=1C2bVbySJ0hyBhmtJ0LOvkExtW3ReXCXN