1V0-71-21 Certified Technical Associate - Application Modernization (VCTA-AM) Practice Questions
Prepare for 1V0-71-21 with more than an answer.
- Exam fee
- $125 USD
- Level
- Associate
- Valid for
- 3 years
Domains covered on the exam 6
- Architecture and Technologies20%
- Products and Solutions25%
- Planning and Designing15%
- Installing, Configuring, and Setup15%
- Performance-tuning, Optimization, and Upgrades10%
- Troubleshooting and Repairing15%
- 1
What are three key benefits of adopting a microservices architecture compared to a traditional monolithic architecture? (Select THREE)
Show answer details
Correct answer: B, C, E
Microservices offer several advantages over monoliths: 1) Improved fault isolation, as services are independent processes. 2) Technology heterogeneity, as each service can choose the best tech stack for its job. 3) Independent scalability, allowing cost-effective scaling of only the services that need it. In contrast, monoliths have a single deployment unit (which can be simpler initially but harder to manage at scale) and often have more complex, distributed communication and data consistency challenges.
- 2
The command
docker build -t my-app:1.0 .is used to build a container image from a Dockerfile. What does the.at the end of the command signify?Show answer details
Correct answer: C
The final argument in the
docker buildcommand specifies the build context. The build context is the set of files at the specified location (URL or path) that are sent to the Docker daemon. The.signifies that the build context is the current working directory. This allows instructions in the Dockerfile, likeCOPY ./app /app, to refer to files within that directory. - 3
True or False: A Kubernetes Service of type
ClusterIPis accessible from outside the cluster by default, provided the correct firewall rules are in place on the nodes.Show answer details
Correct answer: B
This statement is false. The
ClusterIPservice type, which is the default, exposes the service on an internal IP within the cluster. This IP is only reachable from within the cluster. To expose a service to the outside world, one must use aNodePort,LoadBalancer, or anIngressresource. - 4
A platform team is using Tanzu Service Mesh to manage microservices across two different Kubernetes clusters, one in AWS and one in Azure. They need to ensure that if the 'user-profile' service in AWS fails, traffic is automatically and seamlessly redirected to the 'user-profile' service running in the Azure cluster. Which Tanzu Service Mesh feature is specifically designed to enable this type of cross-cluster, high-availability use case?
Show answer details
Correct answer: A
Tanzu Service Mesh's Global Namespace (GNS) feature allows services with the same name, deployed across different clusters and clouds, to be treated as a single, logical service. GNS provides capabilities like global service discovery and load balancing (GSLB) with automated failover. By defining a GNS for the 'user-profile' service, TSM can monitor the health of instances in both AWS and Azure and automatically route traffic to the healthy instance, enabling seamless cross-cluster failover.
- 5
A developer needs to store a database password securely and make it available to a container within a Pod. Storing the password in the container image or in a plain-text ConfigMap is against security policy. What is the appropriate Kubernetes object for this purpose?
Show answer details
Correct answer: C
Kubernetes Secrets are specifically designed to hold small amounts of sensitive data such as passwords, tokens, or keys. They are stored in the cluster (by default, base64 encoded in etcd, with options for encryption at rest) and can be mounted into pods as files or exposed as environment variables, but separately from the pod definition. This decouples sensitive information from the application code and configuration, aligning with security best practices.
- 6
A platform engineering team is deploying a new version of a critical microservice using a blue-green strategy on Tanzu Kubernetes Grid. The current 'blue' version is serving 100% of production traffic via a Kubernetes Service named
payment-svc. The new 'green' deployment is running and has been tested internally. Which action is the most effective and standard way to switch production traffic to the 'green' version with zero downtime?Show answer details
Correct answer: B
The most efficient and standard Kubernetes-native way to switch traffic in a blue-green deployment is to update the selector of the existing Service. A
kubectl patchorkubectl applyon the service manifest achieves this atomically, redirecting all traffic from the old pods to the new ones without any downtime or DNS changes. Deleting and recreating the service would cause a service outage. Usingport-forwardis for debugging, not production traffic. Modifying the deployment's labels would not change where the existing service is pointing. - 7
A developer is troubleshooting a pod that is stuck in the
ImagePullBackOffstate. The pod manifest specifies the imageprivate-repo.corp.local/app:v2.1. The worker node has network connectivity to the private repository. What are the two most likely causes for this error? (Select TWO)Show answer details
Correct answer: A, B
The
ImagePullBackOffstatus indicates that the kubelet on the worker node failed to pull the container image. The two most common reasons for this when pulling from a private repository are authentication failure or the specified image/tag not existing. Authentication is handled via animagePullSecretassociated with the pod's ServiceAccount. If the secret is missing, incorrect, or expired, the pull will fail. Similarly, a simple typo in the image tag will also result in a pull failure. Insufficient CPU/memory or a missing Ingress controller are unrelated to the image pull process. - 8
True or False: In Tanzu Kubernetes Grid, the Cluster API (CAPI) is used exclusively for managing the lifecycle of workload clusters, while the management cluster must always be deployed and managed manually.
Show answer details
Correct answer: B
This statement is false. While the Cluster API's primary role within a TKG management cluster is to manage the lifecycle of workload clusters, the management cluster itself is typically deployed using tools like the Tanzu CLI, which bootstraps a temporary
kindcluster to then provision the full management cluster using Cluster API controllers. Therefore, CAPI is integral to the creation of the management cluster itself, not just the workload clusters it subsequently manages. - 9
An architect is designing a multi-cloud Kubernetes strategy for a global enterprise using Tanzu Mission Control (TMC). The primary requirements are to enforce consistent security policies across all clusters (AKS, EKS, and TKG on-premises) and to restrict developers in the 'junior-dev' group from creating
ClusterRoleBindingresources. Which TMC policy type should the architect create to meet these requirements?Show answer details
Correct answer: D
Tanzu Mission Control's Custom Policies leverage the Open Policy Agent (OPA) Gatekeeper framework. This allows administrators to write fine-grained rules using the Rego language to enforce custom constraints on any Kubernetes resource. The requirement to block the creation of
ClusterRoleBindingresources by a specific user group is a classic use case for a custom admission control policy, which is implemented in TMC as a Custom Policy. Other policy types like Network, Quota, or Image Registry are for more specific, pre-defined use cases. - 10
A DevOps team is migrating a stateful application, a distributed database, to Kubernetes. The application requires a stable, unique network identifier for each of its replicas and persistent storage that survives pod restarts. Which Kubernetes workload resource is specifically designed to manage this type of application?
Show answer details
Correct answer: C
A StatefulSet is the ideal Kubernetes workload API object for managing stateful applications. It provides guarantees about the ordering and uniqueness of its pods. This includes stable, unique network identifiers (e.g., pod-0, pod-1), stable persistent storage linked to each pod's identity, and ordered, graceful deployment and scaling. Deployments are designed for stateless applications where pods are interchangeable.
