Skip to content

2V0-71-23 Certified Professional - Tanzu for Kubernetes Operations Practice Questions

Prepare for 2V0-71-23 with more than an answer.

228 questions in the full set20 sample questionsUpdated Mar 13, 2026
Exam fee
$250 USD
Level
Professional
Valid for
2 years
Domains covered on the exam 4
  1. Architecture and Technologies35%
  2. VMware Products and Solutions25%
  3. VMware Tanzu for Kubernetes Operations35%
  4. VMware Tanzu for Kubernetes Operations Security5%
  1. 1

    The command tanzu mission-control ____ create -f my-cluster.yaml is used to provision a new TKG workload cluster using a YAML manifest. What is the missing keyword in this command?

    Show answer details

    Correct answer: C

    The correct command structure for creating a cluster in TMC via the CLI is tanzu mission-control cluster create. The cluster keyword specifies the object type being managed.

  2. 2

    True or False: A Tanzu Mission Control 'Workspace' is a logical construct used to group multiple Cluster Groups together for simplified policy application.

    Show answer details

    Correct answer: B

    This statement is false. The relationship is reversed. A Workspace in TMC is used to group namespaces from multiple different clusters, allowing policies and access controls to be applied to a collection of namespaces that represent a logical application or team, regardless of which cluster they reside in. Cluster Groups are used to group entire clusters.

  3. 3

    What is the primary architectural difference between deploying a TKG Management Cluster on vSphere versus enabling a vSphere with Tanzu Supervisor Cluster?

    Show answer details

    Correct answer: B

    This is the core architectural distinction. A standalone TKG deployment on vSphere is a 'guest' implementation where the entire Kubernetes cluster (management and workload) runs inside virtual machines. In contrast, vSphere with Tanzu is a 'native' implementation where the Kubernetes control plane is deeply integrated with vCenter, and the ESXi hypervisors themselves are transformed into Kubernetes worker nodes via the Spherelet.

  4. 4

    An administrator needs to attach an existing, non-Tanzu Kubernetes cluster (such as EKS or GKE) to Tanzu Mission Control for centralized management. What is the general process to accomplish this?

    sequenceDiagram participant Admin participant TMC as Tanzu Mission Control participant EKS as Existing K8s Cluster Admin->>TMC: Initiate 'Attach Cluster' action TMC-->>Admin: Generate registration YAML Admin->>EKS: kubectl apply -f registration.yaml EKS->>TMC: Agent connects and registers TMC-->>Admin: Cluster appears as 'Attached'
    Show answer details

    Correct answer: B

    The standard procedure for attaching a conformant, third-party Kubernetes cluster to TMC involves initiating the process in the TMC console, which generates a unique registration URL and a corresponding YAML manifest. The administrator then uses kubectl with credentials for the target cluster to apply this manifest, which deploys the necessary TMC agents onto the cluster, establishing a connection back to TMC.

  5. 5

    A developer has deployed an application to a TKG cluster. To expose the application to external traffic, they created a Kubernetes Service of type LoadBalancer. The cluster is integrated with NSX Advanced Load Balancer (Avi). After several minutes, the Service's EXTERNAL-IP remains in a state. Which of the following are potential root causes for this issue? (Select TWO)

    Show answer details

    Correct answer: A, C

    AKO is the controller responsible for watching Kubernetes Services and creating the corresponding objects in Avi. If AKO is not running, no new load balancers will be provisioned, and the Service will remain pending.

    When AKO requests a new virtual service from the Avi Controller, the controller needs to assign it a virtual IP (VIP) from a pre-configured IPAM pool. If this pool is exhausted, the controller cannot fulfill the request, and the EXTERNAL-IP will not be assigned.

  6. 6

    A platform engineering team is using Tanzu Mission Control (TMC) to manage a large fleet of Tanzu Kubernetes Grid (TKG) workload clusters. They need to ensure that all clusters within the 'pci-environment' cluster group use a specific, hardened OVA for their nodes and are restricted to a single vSphere resource pool. Which TMC policy type should be configured to enforce these infrastructure-level constraints?

    Show answer details

    Correct answer: B

    A custom policy in Tanzu Mission Control allows administrators to enforce specific configurations defined in a template, which can include infrastructure-level settings like VM image (OVA) and resource pool placement. This provides the necessary flexibility to enforce hardware and image standards that are not covered by other predefined policy types.

  7. 7

    A DevOps team is deploying a new TKG workload cluster on vSphere with Tanzu. The application requires access to two distinct networks: a corporate backend network for database access and a separate DMZ network for public-facing traffic. Which Tanzu package must be installed and configured on the cluster to enable pods to have multiple network interfaces?

    Show answer details

    Correct answer: D

    Multus CNI is a container network interface (CNI) plugin for Kubernetes that enables attaching multiple network interfaces to pods. It acts as a 'meta-plugin' that can call other CNI plugins to configure the additional interfaces, which is exactly what is required for pods that need to connect to multiple distinct networks.

  8. 8

    An administrator is configuring a Supervisor Cluster in a vSphere with Tanzu environment. They need to provide developers with three standardized T-shirt sizes for Kubernetes nodes: small, medium, and large. Which vSphere with Tanzu construct should the administrator create to define these standardized node sizes?

    Show answer details

    Correct answer: A

    A VM Class in vSphere with Tanzu defines a template for the size and resources (CPU, memory, storage) of a virtual machine. Administrators create these classes to offer standardized 'T-shirt sizes' for nodes in Tanzu Kubernetes Grid workload clusters, which developers can then select when provisioning their clusters.

  9. 9

    A security team wants to enforce a policy in Tanzu Mission Control that prevents any container image with a 'High' or 'Critical' CVE from being deployed to production clusters. They also want to ensure that only images from the company's approved Harbor registry can be used. Which TWO policy types in TMC should be configured to meet these requirements? (Select TWO)

    Show answer details

    Correct answer: A, B

    The image registry policy is used to whitelist approved container registries, satisfying the requirement to only allow images from the company's Harbor instance.

    The security policy in TMC is used to enforce various security controls, including the ability to block deployments of images that have vulnerabilities exceeding a specified threshold (e.g., 'High' or 'Critical' CVEs).

  10. 10

    True or False: When a vSphere with Tanzu Supervisor Cluster is enabled on a vSphere cluster, the ESXi hosts in that cluster become worker nodes that can run native Kubernetes pods scheduled directly by the Supervisor Cluster's control plane.

    Show answer details

    Correct answer: A

    This is a fundamental concept of vSphere with Tanzu. Enabling the Supervisor Cluster transforms the vSphere cluster into a Kubernetes platform. The ESXi hosts are enhanced with a Spherelet (the vSphere equivalent of a Kubelet), allowing them to function as Kubernetes worker nodes and run pods directly on the hypervisor.

Create an account to continue.