1V0-4120 Sample Questions

1V0-4120 Sample Questions & Answers

vSphere networking concepts and SDDC product components dominate the weighting, with the remainder split between software-defined data center and networking fundamentals, and finding your way around the NSX interface.

Launch the full 1V0-4120 simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    VMware Products and Solutions · Identify the roles of each of the high-level components of the NSX architecture.

    An administrator successfully deployed the three-node NSX Manager cluster. What is the primary role of this cluster in the NSX-T architecture?

    Show answer & explanation

    Correct answer: C

    The NSX Manager cluster forms the Management Plane. Its primary role is to provide a graphical user interface (GUI) and REST API endpoint for all configuration and operational tasks. It is responsible for storing the desired state of the system and pushing the configuration to the Control Plane and Data Plane components. It does not forward workload traffic (Data Plane) nor does it host the centralized Control Plane (which is also distributed).

  2. Question 2Advanced

    VMware Products and Solutions · Identify the functionality of the NSX-T features.

    Case Study: InnovateCloud Solutions

    InnovateCloud Solutions is a managed service provider that offers isolated development environments for its clients. They are designing a new multi-tenant offering using VMware NSX-T. Each client (tenant) requires its own logical routing domain for their application tiers (e.g., web, app, db). These tenant networks must be completely isolated from each other. However, all tenants need to access a shared set of services, such as DNS and NTP servers, which are located on a dedicated network segment.

    To provide North-South connectivity to the internet and the corporate network, a central routing instance has been configured to peer with the physical network fabric using BGP. The design must be scalable to support hundreds of tenants, and the provisioning of a new tenant's network stack should be simple and repeatable.

    Which NSX-T logical routing design best meets these requirements?

    Show answer & explanation

    Correct answer: C

    This is the classic multi-tiered routing architecture for multi-tenancy. The single Tier-0 gateway handles all North-South routing and peering with the physical network. Each tenant receives a dedicated Tier-1 gateway, which provides logical routing isolation. The Tier-1 gateways connect upstream to the Tier-0. Connecting the shared services segment to the Tier-0 allows all tenants to access it via their connection to the Tier-0, while maintaining tenant-to-tenant isolation at the Tier-1 level.

  3. Question 3Intermediate

    VMware Products and Solutions · Identify the functionality of the NSX-T features.

    An administrator needs to create a security policy that prevents all workloads tagged with 'PCI-Environment' from initiating any communication to workloads tagged as 'Development'. Which NSX-T component is the most appropriate and efficient place to configure this policy?

    Show answer & explanation

    Correct answer: B

    The Distributed Firewall (DFW) is the ideal component for this use case. The DFW operates at the virtual NIC of every workload, providing stateful firewalling for all East-West traffic. Because it's distributed, it can enforce policies based on dynamic criteria like tags, regardless of the workload's network location or IP address. A Gateway Firewall would only see traffic that crosses the gateway, making it ineffective for controlling traffic between workloads on the same logical segment.

  4. Question 4Intermediate

    VMware Products and Solutions · Identify the functionality of the NSX-T features.

    An administrator has configured a Tier-0 Gateway in an Active-Standby high availability mode. What happens to the North-South traffic flow if the active Edge Node fails?

    Show answer & explanation

    Correct answer: B

    In Active-Standby HA mode, one Edge Node is actively forwarding traffic while the other is in a standby state, ready to take over. If the active node fails, a failover event is triggered. The standby Edge Node assumes the active role, takes over the necessary IP and MAC addresses, and begins forwarding traffic with minimal disruption.

  5. Question 5Intermediate

    Administrative and Operational Tasks · Given a scenario including a goal, identify how to use the NSX graphical user interface to achieve that goal.

    An administrator needs to quickly isolate a compromised virtual machine from the network to prevent a security threat from spreading. The goal is to block all inbound and outbound traffic for that specific VM. From the NSX Manager UI, where would the administrator navigate to accomplish this task most effectively?

    Show answer & explanation

    Correct answer: C

    The Distributed Firewall (DFW) is the correct tool for isolating a specific VM. The standard workflow is to navigate to the Security section, select the Distributed Firewall, create a new high-priority policy (e.g., 'Quarantine'), and add a rule that applies directly to the compromised VM. Setting the rule's action to 'Drop' for all traffic effectively isolates it from the network.

  6. Question 6Intermediate

    VMware Products and Solutions · Identify the functionality of the NSX-T features.

    An administrator is creating a new logical segment for a web server farm. They need to ensure this segment is available to all ESXi hosts within a specific vSphere cluster designated for production workloads. Which NSX-T object defines the scope or boundary for this logical segment?

    Show answer & explanation

    Correct answer: B

    A Transport Zone defines the collection of hosts (Transport Nodes) that can participate in a particular logical network. When a logical segment is created, it is associated with a Transport Zone. Only the hosts that are members of that Transport Zone will be able to connect VMs to that segment. This is how NSX-T controls the span of a logical network.

  7. Question 7Advanced

    Administrative and Operational Tasks · Given a scenario including a goal, identify how to use the NSX graphical user interface to achieve that goal.

    A junior administrator reports that two VMs on the same logical segment can ping each other, but neither can reach the external network. A senior administrator confirms that the segment is connected to a Tier-1 Gateway, and the Tier-1 is connected to a Tier-0 Gateway. What is a likely misconfiguration that needs to be performed on the Tier-1 Gateway via the NSX Manager UI?

    Show answer & explanation

    Correct answer: B

    The symptoms describe successful East-West traffic (VM to VM) but failed North-South traffic (VM to external). A common cause is that the Tier-1 Gateway is not advertising its connected routes (the segment's subnet) to the Tier-0 Gateway. Without this advertisement, the Tier-0 doesn't know how to route traffic back to the segment. This is configured under the Tier-1 Gateway's Route Advertisement settings in the UI.

  8. Question 8Intermediate

    Architecture and Technologies · Identify the Software Defined Networking (SDN) building blocks.

    True or False: The NSX-T Data Plane is responsible for maintaining the runtime state of the virtual network based on configurations received from the Management Plane.

    Show answer & explanation

    Correct answer: B

    This statement is false. The Control Plane, not the Data Plane, is responsible for maintaining the runtime state. The Management Plane pushes the desired configuration to the Control Plane. The Control Plane then computes and maintains the runtime state (like forwarding tables) and programs the Data Plane. The Data Plane's only job is to forward packets based on the tables it receives from the Control Plane.

  9. Question 9Intermediate

    VMware Products and Solutions · Identify the key features of vSphere.

    A vSphere cluster is configured with Distributed Resource Scheduler (DRS) in fully automated mode. During a period of high CPU utilization on one ESXi host, DRS initiates a vMotion of several VMs to other hosts in the cluster. How does NSX-T ensure that the distributed firewall policies associated with these VMs are maintained after migration?

    Show answer & explanation

    Correct answer: C

    NSX-T Distributed Firewall policies are realized as rules within the hypervisor kernel (VIBs installed on ESXi hosts). The NSX Control Plane ensures that all hosts in a transport zone have the correct set of policies. When a VM moves via vMotion, it lands on a destination host that already has the required policies programmed in its kernel. The enforcement is tied to the VM's virtual NIC, not the host's physical location, so security is maintained seamlessly.

  10. Question 10Intermediate

    VMware Products and Solutions · Given a use case, identify the product that supports the use case.

    An organization has two data centers in different cities. They need to extend several L2 networks between the sites to facilitate a seamless migration of stateful applications without re-IPing them. Which VMware solution is specifically designed for this application mobility and hybrid connectivity use case?

    Show answer & explanation

    Correct answer: C

    VMware HCX (Hybrid Cloud Extension) is an application mobility platform designed to simplify workload migration, rebalancing, and business continuity across data centers and clouds. Its key feature is the ability to create a secure, high-performance L2 network extension, allowing VMs to be migrated (cold, warm, or live) between sites while retaining their IP addresses.

Ready for the real thing?

The full 1V0-4120 simulator has every exam-style question, timed mode, and instant scoring.