Skip to content

5V0-23-20 vSphere with Tanzu Specialist Practice Questions

Prepare for 5V0-23-20 with more than an answer.

208 questions in the full set20 sample questionsUpdated Mar 13, 2026
Domains covered on the exam 7
  1. Introduction
  2. Introduction to Containers and Kubernetes
  3. Introduction to vSphere with Tanzu20%
  4. vSphere with Tanzu Core Services60%
  5. Tanzu Kubernetes Grid Service18%
  6. Monitoring and Troubleshooting
  7. vSphere with Tanzu Life Cycle2%
  1. 1

    When enabling Workload Management on a vSphere cluster, the process creates several virtual machines to form the Supervisor Cluster control plane. What is the minimum number of control plane VMs required for a production deployment?

    Show answer details

    Correct answer: C

    For a production deployment, vSphere with Tanzu deploys three Supervisor Control Plane VMs. This provides high availability (HA) for the Kubernetes API server and other control plane components. The three nodes run in an active-passive-passive configuration and use an etcd cluster that can tolerate the failure of one node.

  2. 2

    A Tanzu Kubernetes Cluster is defined with a worker node count of 3. A new version of the application requires more compute resources. The administrator edits the TKC manifest and changes the worker node count to 5 and applies the change. What is the expected outcome?

    Show answer details

    Correct answer: B

    The Tanzu Kubernetes Grid Service continuously monitors the state of the TanzuKubernetesCluster resource. When it detects a change in the desired replica count for worker nodes, it will reconcile the state by provisioning the required number of new virtual machines from the Content Library template and automatically joining them to the existing cluster.

  3. 3

    An administrator observes that when a developer creates a Kubernetes service of type LoadBalancer, it is not assigned an external IP from the Ingress CIDR configured during Workload Management setup. The cluster is using NSX-T as the networking stack. What is a potential cause for this issue?

    Show answer details

    Correct answer: B

    In an NSX-T backed environment, the Ingress CIDR range is backed by an IP Pool within NSX-T. The NSX Container Plugin (NCP) is responsible for allocating an IP from this pool for each LoadBalancer service. If all IPs in that pool have been allocated, new services will remain in a 'pending' state indefinitely without an external IP.

  4. 4

    What is the function of the tanzucluster command-line utility?

    Show answer details

    Correct answer: B

    The tanzucluster (or newer tanzu cluster) utility is part of the Tanzu CLI and provides a user-friendly abstraction over kubectl for common TKC lifecycle operations like create, list, scale, upgrade, and delete. It simplifies the process by handling the underlying YAML manifest generation and application.

  5. 5

    What are the two supported Container Network Interface (CNI) plugins for Tanzu Kubernetes Clusters deployed by the Tanzu Kubernetes Grid Service? (Select TWO)

    Show answer details

    Correct answer: B, D

    Calico is a widely used CNI known for its performance and support for network policies. It is a supported CNI for Tanzu Kubernetes Clusters.

    Antrea is an open-source Kubernetes networking project initiated by VMware that leverages Open vSwitch. It is the default CNI for Tanzu Kubernetes Clusters and is fully supported.

  6. 6

    A DevOps engineer is attempting to deploy a new Tanzu Kubernetes Cluster (TKC) into a vSphere Namespace. The deployment fails with an error message indicating 'no suitable VM class found'. The engineer has confirmed that multiple VM classes are defined in the Supervisor Cluster. What is the most likely cause of this issue?

    Show answer details

    Correct answer: A

    VM classes are defined at the Supervisor Cluster level but must be explicitly associated with a vSphere Namespace to be usable within it. If no VM classes are added to the namespace, the Tanzu Kubernetes Grid Service cannot find a suitable class to provision the control plane and worker nodes for a new TKC, leading to this specific error.

  7. 7

    A platform operator needs to provide developers with different T-shirt sizes for Tanzu Kubernetes Cluster nodes (e.g., small, medium, large). Which two components must be configured to achieve this? (Select TWO)

    Show answer details

    Correct answer: A, B

    VM Classes define the CPU, memory, and reservation settings for virtual machines, directly corresponding to the T-shirt sizes for TKC nodes. Multiple classes must be created to offer different sizes.

    After VM Classes are created at the Supervisor Cluster level, they must be assigned to the specific vSphere Namespace where developers will be deploying their TKCs. This makes the T-shirt sizes available within that namespace.

  8. 8

    True or False: When using vSphere with Tanzu with the vSphere Distributed Switch (VDS) for networking, a third-party IPAM provider is required for managing IP addresses for vSphere Pods.

    Show answer details

    Correct answer: B

    This statement is false. The Supervisor Cluster provides its own internal IPAM capabilities when configured with VDS networking, eliminating the need for an external or third-party IPAM solution for vSphere Pods.

  9. 9

    Company Background:
    A financial technology company, FinCorp, is modernizing its monolithic trading application by breaking it down into containerized microservices. They have chosen vSphere with Tanzu to leverage their existing VMware expertise and infrastructure. The environment is configured with NSX-T for advanced networking and security.

    Current Situation:
    The security team has mandated strict network isolation between the different microservices. Specifically, the 'order-processing' service should only be able to communicate with the 'trade-execution' service on TCP port 8080, and the 'trade-execution' service should only be able to initiate communication with the 'market-data' service on TCP port 9000. All other pod-to-pod communication within the namespace must be denied by default.

    Requirement:
    As the vSphere administrator, you must implement a solution using native Kubernetes objects that enforces this traffic flow policy within the 'trading-app' vSphere Namespace.

    Which approach satisfies the security requirement?

    Show answer details

    Correct answer: B

    This is the correct Kubernetes-native approach. A default-deny ingress policy establishes a zero-trust baseline. Then, specific 'allow' ingress policies are created for each service, using pod selectors to precisely define which source pods can connect to which destination pods on specific ports. The NSX Container Plugin (NCP) translates these Kubernetes objects into underlying NSX-T firewall rules automatically.

  10. 10

    A vSphere administrator is enabling Workload Management and must choose a networking stack. The existing environment uses a vSphere Distributed Switch (VDS) and the primary requirement is to get the Supervisor Cluster operational with minimal changes to the existing network infrastructure. Which component provides load balancing for Kubernetes services in this configuration?

    Show answer details

    Correct answer: C

    When vSphere with Tanzu is configured with VDS networking, a load balancer based on HAProxy is automatically deployed as a virtual machine. This appliance provides Layer 4 load balancing for the Supervisor Cluster's control plane and for Kubernetes services of type LoadBalancer created within the namespaces.

Create an account to continue.