2V0-71-23 Sample Questions & Answers
Kubernetes lifecycle concepts tie with the roles of cert-manager, Harbor and Fluent Bit for the heaviest weight, next to day-to-day admin for Tanzu Kubernetes Grid, the Tanzu side of vSphere, and Mission Control, plus registry scanning and image policies.
Launch the full 2V0-71-23 simulator →Showing 10 of 20 free samples.
- Question 1Advanced
VMware Products and Solutions · Understand and Explain Common Administration Requirements for Tanzu Kubernetes Grid
A platform operator is deploying a new Tanzu Kubernetes Grid (TKG) management cluster to a vSphere environment using the CLI. The deployment fails during the provider resource creation step. Upon reviewing the logs, the operator suspects an issue with the credentials used to connect to vCenter. Which command should the operator use to verify and, if necessary, regenerate the vSphere credentials stored in the local Tanzu configuration?
Show answer & explanation
Correct answer: A
- Question 2Advanced
VMware Products and Solutions · Describe the features and benefits of Tanzu Service Mesh
A financial services company has deployed Tanzu Service Mesh across their hybrid environment, which includes TKG clusters on-premises and in AWS. They have created a Global Namespace (GNS) for their 'trading-app' to facilitate secure, cross-cluster communication. A new regulation requires that all traffic between the 'market-data' service and the 'order-processing' service within this GNS must be mutually authenticated using mTLS. How should an administrator enforce this requirement?
Show answer & explanation
Correct answer: B
Tanzu Service Mesh manages cross-cluster security through policies applied at the Global Namespace level. To enforce mutual TLS (mTLS) for all services within a GNS, the administrator should configure an authentication policy for that GNS and set the mTLS mode to STRICT. This ensures that all service-to-service communication is encrypted and mutually authenticated, regardless of which cluster the services are running in.
- Question 3Intermediate
Architecture and Technologies · Describe the concept of Cluster API
During the deployment of a TKG cluster on vSphere, the process fails. An operator runs
tanzu cluster getand observes that the control plane nodes are stuck in the 'Provisioning' phase. Which underlying technology is responsible for the declarative reconciliation of the cluster's state against the vSphere infrastructure?Show answer & explanation
Correct answer: C
Cluster API (CAPI) is the core Kubernetes project that TKG uses for declarative, API-driven cluster lifecycle management. When a cluster is created, CAPI controllers in the management cluster constantly work to reconcile the desired state (e.g., '3 control plane nodes') with the actual state of the infrastructure provider (in this case, vSphere). A failure in this process, causing nodes to be stuck in 'Provisioning', points to an issue within the CAPI reconciliation loop.
- Question 4Advanced
VMware Tanzu for Kubernetes Operations · vSphere with Tanzu
Case Study:
A healthcare organization is modernizing its patient portal application using VMware Tanzu for Kubernetes Operations. They have a vSphere 7.0U3 environment with vSAN as the primary datastore. A Supervisor Cluster has been successfully deployed, and a vSphere Namespace called 'patient-portal-prod' has been created for the development team.
The application consists of several microservices, including a stateful database component that requires persistent storage with high availability. The security team mandates that all application traffic must be routed through a centralized ingress point with TLS termination, and developers must not have permissions to create their own ingress objects.
The operations team needs to ensure they can back up the entire 'patient-portal-prod' namespace, including persistent volumes, to an S3-compatible object store for disaster recovery. They also need to provide developers with a simple way to deploy the application stack without managing complex Kubernetes YAML manifests.
Which combination of Tanzu components and configurations best meets all the stated requirements?
Show answer & explanation
Correct answer: A
This solution correctly addresses all requirements. A vSphere Storage Policy for vSAN provides the highly available persistent storage. Contour serves as the centralized ingress controller. Velero, integrated with Tanzu Mission Control, handles the namespace and PV backups to S3. Packaging the application as a Carvel package and adding it to the TMC Catalog provides the simplified deployment method for developers.
- Question 5Intermediate
VMware Products and Solutions · Describe the features and benefits of Aria Operations for Applications
An SRE is troubleshooting application latency in a Kubernetes cluster that is monitored by Aria Operations for Applications (formerly Tanzu Observability). The SRE needs to identify which specific microservice call in a distributed transaction is causing the slowdown. Which capability of Aria Operations for Applications is essential for this type of analysis?
Show answer & explanation
Correct answer: C
Distributed tracing is the specific observability capability designed to track requests as they flow through multiple microservices in a distributed system. It allows an SRE to visualize the entire path of a transaction, see the duration of each service call (span), and pinpoint the exact location of latency bottlenecks.
- Question 6Intermediate
Architecture and Technologies · Describe Kubernetes networking and storage concepts
A platform administrator is configuring a new TKG cluster that will host applications requiring high-performance, low-latency storage. The underlying vSphere environment uses vSAN. To meet the application's performance requirements, the administrator needs to ensure that all PersistentVolumes created for this application use a specific vSAN policy that enables RAID-1 mirroring and a high number of IOPS reservations. What Kubernetes object must the administrator create and configure to make this vSAN policy available for developers to request via PersistentVolumeClaims?
Show answer & explanation
Correct answer: C
A StorageClass is a Kubernetes object that allows administrators to define different 'classes' of storage. When using the vSphere CSI driver, the StorageClass parameters can be used to reference a specific vSphere storage policy (like a vSAN policy). Developers can then request storage from this class in their PersistentVolumeClaims, and the CSI driver will automatically provision a PersistentVolume that complies with the underlying vSAN policy.
- Question 7Intermediate
VMware Tanzu for Kubernetes Operations · Explain how Tanzu Kubernetes Grid integrates with NSX Advanced Load Balancer
A company is using NSX Advanced Load Balancer (Avi) with Tanzu Kubernetes Grid. An administrator notices that when a new Service of type LoadBalancer is created, a new virtual service is not being created on the Avi Controller. The administrator has confirmed that the Avi Controller is reachable from the TKG cluster. Which component is responsible for watching the Kubernetes API for new Services and Ingresses and communicating with the Avi Controller to create the necessary virtual services?
graph TD subgraph TKG Cluster K8S_API[Kubernetes API Server] AKO[Avi Kubernetes Operator] end subgraph NSX ALB Controller[Avi Controller] SE[Service Engines] end K8S_API -- Watches for Services/Ingress --> AKO AKO -- Translates & sends API calls --> Controller Controller -- Instructs --> SEShow answer & explanation
Correct answer: B
The Avi Kubernetes Operator (AKO) is the integration component that runs within the TKG cluster. Its primary role is to watch the Kubernetes API for relevant objects (like Services of type LoadBalancer and Ingress objects) and translate them into the corresponding configuration objects (like Virtual Services and Pools) on the Avi Controller. If this communication fails, load balancing will not be provisioned.
- Question 8Beginner
VMware Tanzu for Kubernetes Operations · Describe Tanzu Kubernetes Grid Service
What is the primary function of the Tanzu Kubernetes Grid Service (TKGS) within a vSphere with Tanzu environment?
Show answer & explanation
Correct answer: C
The Tanzu Kubernetes Grid Service (TKGS) is a component of the Supervisor Cluster that allows developers and administrators to provision and manage what are known as TKG workload clusters or guest clusters. These are fully conformant, upstream Kubernetes clusters that run on VMs within a vSphere Namespace, providing a more isolated and traditional Kubernetes experience compared to running pods directly on the Supervisor.
- Question 9IntermediateSelect 2
VMware Tanzu for Kubernetes Operations · Describe vSphere with Tanzu shared datastores types
Which of the following are valid datastore types that can be used for shared storage by a vSphere with Tanzu Supervisor Cluster? (Select TWO)
Show answer & explanation
Correct answers: A, C
vSAN is a primary and fully supported shared storage solution for vSphere with Tanzu, providing hyper-converged, policy-driven storage.
NFS (v3 and v4.1) is a supported shared storage type for vSphere with Tanzu, allowing environments with existing NFS arrays to be used.
- Question 10Advanced
VMware Tanzu for Kubernetes Operations · Describe the role of Velero
An organization uses Velero to back up their TKG clusters. A junior administrator is tasked with restoring a specific namespace,
app--from a backup. After the restore, developers report that their application cannot connect to its database, which runs in the same namespace. The investigation reveals that the Kubernetes Secret containing the database password was not restored. What is the most likely reason for this failure?Show answer & explanation
Correct answer: D
By default, Velero backs up most standard Kubernetes objects. However, a backup can be customized using
--include-resourcesor--exclude-resourcesflags. If the original backup command either excluded secrets explicitly or included a specific list of resources that did not contain 'secrets', the Secret object would not have been part of the backup artifact and therefore could not be restored.
Ready for the real thing?
The full 2V0-71-23 simulator has every exam-style question, timed mode, and instant scoring.