5V0-42-21 SD-WAN Design and Deploy Skills Practice Questions
Prepare for 5V0-42-21 with more than an answer.
- Exam fee
- $250 USD
- Level
- Skills
- Valid for
- 2 years
Domains covered on the exam 8
- VMware SD-WAN by VeloCloud Architecture15%
- VMware SD-WAN Design20%
- VeloCloud Key Components15%
- Gateway and Edge Deployment15%
- SD-WAN Component Management15%
- Business Policies Creation and Management20%
- CloudVPN and PKI10%
- Security10%
- 1
A retail company is using a Business Policy to ensure that all credit card transaction traffic is duplicated across both its primary fiber and backup LTE links to maximize reliability. Which two conditions must be met for per-packet duplication to occur? (Select TWO)
Show answer details
Correct answer: A, C
Packet duplication is a feature reserved for real-time, high-priority traffic to ensure zero packet loss. The traffic must be classified as 'High Priority' in the Business Policy for this feature to be considered.
Duplication requires at least two viable paths. Both links must be stable and performing within acceptable quality thresholds for the system to use them for duplication.
- 2
True or False: In a VMware SD-WAN design, it is a best practice to deploy Partner Gateways in the same physical data center as the SD-WAN Controllers for optimal performance.
Show answer details
Correct answer: B
This statement is false. Gateways and Controllers serve separate functions (data plane and control plane, respectively) and are designed to be geographically distributed. Gateways should be deployed strategically close to major cloud providers and internet peering points to optimize data paths, while Controllers are placed for resilient control plane connectivity to the Edges. Co-locating them is not a requirement or a universal best practice.
- 3
An administrator needs to upgrade the software on 500 remote Edges. The goal is to minimize risk by first upgrading a small pilot group of 10 non-critical sites, verifying stability, and then upgrading the remaining sites in batches. Which feature of the VMware SD-WAN Orchestrator facilitates this process?
Show answer details
Correct answer: C
The Edge Software Image Management feature in the Orchestrator is designed for this exact scenario. It allows administrators to assign specific software versions to individual Edges or, more efficiently, to all Edges within a specific Profile. The administrator can create a 'Pilot' profile for the 10 sites, assign the new software version to it, and then update the main production profile once testing is successful.
- 4
A customer has a custom, in-house application that runs on TCP port 8443. The Deep Application Recognition engine does not recognize this application. How can an administrator create a Business Policy to specifically manage and prioritize this application's traffic?
Show answer details
Correct answer: C
The correct method is to define a custom application in the Orchestrator. This allows the administrator to create a new application signature based on L3/L4 identifiers like IP addresses, FQDNs, and port numbers. Once this custom application is defined, it can be selected as a match condition in a Business Policy, just like any pre-defined application, allowing for specific QoS and steering actions.
- 5
An engineer is designing a routing plan for a new SD-WAN branch that connects to a legacy MPLS network. The branch needs to learn routes from the data center's OSPF domain and advertise its local subnets back to the data center. The branch Edge will form an OSPF adjacency with a CE router. How should OSPF be configured on the SD-WAN Edge?
Show answer details
Correct answer: B
The correct configuration involves two key steps: 1) Enabling OSPF on the appropriate LAN-side interface to form an adjacency with the CE router, allowing it to learn routes from the MPLS network. 2) Configuring route redistribution to advertise the Edge's local 'Connected' subnets into the OSPF domain, so the data center learns how to reach the branch.
- 6
A global logistics company is deploying VMware SD-WAN to 300 warehouses. Each warehouse has a primary broadband link and a backup LTE link. The company's primary requirement is to ensure that Point-of-Sale (PoS) transaction data, which is highly sensitive to latency and jitter, is always routed over the link with the best real-time performance metrics. All other traffic should use the broadband link unless it fails. Which Business Policy configuration is the most effective way to achieve this?
Show answer details
Correct answer: D
The most effective method is to create a Business Policy for the PoS application traffic and set the Link Steering to 'Mandatory' while selecting both available links. This activates Dynamic Multipath Optimization (DMPO) for that traffic class. DMPO will continuously monitor both links for latency, jitter, and loss, and it will steer the PoS traffic on a per-packet basis to the link that provides the best performance at any given moment, fulfilling the core requirement. Other methods do not guarantee routing based on real-time performance.
- 7
An architect is designing a VMware SD-WAN solution for a hospital's primary data center. The design requires that in the event of a primary Edge failure, all active traffic sessions, including stateful firewall connections and active VoIP calls, must fail over to the secondary Edge with no disruption. Which High Availability (HA) deployment mode must be specified in the design?
Show answer details
Correct answer: B
Enhanced High Availability (HA) is the only mode that provides stateful failover. In this mode, the active and standby Edges continuously synchronize flow and session information. This ensures that upon a failure of the active Edge, the standby Edge can take over immediately without dropping existing sessions, which is critical for stateful applications like firewalls and real-time traffic like VoIP.
- 8
A network administrator needs to establish a secure VPN tunnel from a VMware SD-WAN branch to a partner's data center, which uses a third-party (non-VMware) firewall as its VPN endpoint. Which VMware SD-WAN Cloud VPN topology is designed specifically for this use case?
Show answer details
Correct answer: C
The 'Branch to Non-VMware SD-WAN Site' topology is specifically designed to build standard IPsec tunnels between a VMware SD-WAN Edge and a third-party device like a firewall or router that is not part of the VMware SD-WAN fabric. This allows for secure interoperability with legacy or partner networks.
- 9
A deployment engineer is activating a new VMware SD-WAN Edge 620 at a remote office. The office has no local IT staff. The engineer has configured the Edge in the Orchestrator and shipped it to the site. What is the only piece of information the on-site contact needs to provide to the engineer over the phone to complete the activation process?
Show answer details
Correct answer: D
For Zero-Touch Provisioning (ZTP), the on-site contact simply needs to plug in the Edge and connect it to the internet. The engineer will then send an activation email containing a unique activation URL. The on-site contact clicks this link from a device on the local LAN, which directs the Edge to the correct Orchestrator to download its configuration and complete the activation. The URL is the key component that links the physical device to its cloud-managed configuration.
- 10
A university wants to provide internet access for students on a guest Wi-Fi network. The security policy mandates that this guest traffic must be completely isolated from the university's administrative network traffic and must be routed directly to the internet without traversing the data center. Which VMware SD-WAN feature provides the most scalable and secure method for this segmentation?
Show answer details
Correct answer: C
Segments are the superior feature for this requirement. They provide true logical, end-to-end network isolation with separate routing tables and firewall policies per segment. While VLANs provide Layer 2 separation at the branch, Segments extend this isolation across the entire WAN fabric, ensuring guest traffic can never reach the administrative network. A Business Policy can then be applied to the guest segment to enforce the direct internet breakout.
