1V0-4120 Certified Technical Associate - Network Virtualization (VCTA-NV) Practice Questions
Prepare for 1V0-4120 with more than an answer.
- Exam fee
- $250 USD
- Level
- Associate
- Valid for
- No expiration
Domains covered on the exam 3
- Architecture and Technologies20%
- VMware Products and Solutions60%
- Administrative and Operational Tasks20%
- 1
Which three of the following are distinct planes in the NSX-T architecture? (Select THREE)
Show answer details
Correct answer: A, C, D
The NSX-T architecture is fundamentally built on the separation of three distinct planes: the Management Plane (for configuration and API), the Control Plane (for calculating and maintaining runtime state), and the Data Plane (for forwarding packets). The Services Plane is not a formally defined plane in this architecture.
- 2
What is the function of an NSX-T Edge Node?
Show answer details
Correct answer: D
NSX-T Edge Nodes are service appliances that provide the bridge between the virtual and physical networks (North-South traffic). They are also responsible for running centralized services that cannot be distributed to the hypervisors, such as NAT, DHCP, VPN, and load balancing.
- 3
An administrator observes that workloads on an NSX-T overlay segment can communicate with each other, but cannot reach any external destinations. The Tier-0 gateway is correctly configured and has BGP adjacency with the physical routers. The administrator needs to verify the routing path from the logical network to the physical network. In the NSX Manager UI, where should the administrator navigate to check if the Tier-1 gateway is correctly advertising its connected routes to the Tier-0 gateway?
Show answer details
Correct answer: B
This specific setting determines which subnets connected to the Tier-1 are advertised 'upwards' to the Tier-0. If the connected segment's subnet is not enabled for advertisement, the Tier-0 will not know about it and cannot route traffic to it from the outside. The correct path in the UI is to go to Networking > Tier-1 Gateways, select the relevant gateway, click Edit, and expand the Route Advertisement settings.
- 4
A new administrator is trying to understand the packet flow for traffic between two VMs on different logical segments but connected to the same Tier-1 Gateway. Which statement accurately describes this traffic flow?
Show answer details
Correct answer: B
This scenario describes East-West routing, which is handled by the Distributed Router (DR) component of the Tier-1 Gateway. The DR is instantiated on every hypervisor (Transport Node). Traffic from the source VM goes to the DR on its local hypervisor, which performs the routing lookup and then forwards the traffic directly to the destination VM's hypervisor over the GENEVE overlay. The traffic never needs to 'hairpin' through a centralized Edge Node.
- 5
An administrator has deployed NSX-T and needs to provide internet access for a group of VMs on an overlay segment. The VMs have private IP addresses and should not be directly exposed to the internet. Which NSX-T service, configured on a Tier-0 or Tier-1 Gateway, should be used to achieve this?
graph TD subgraph NSX-T Overlay VM1[VM 10.10.10.1] --> Segment[Segment 10.10.10.0/24] Segment --> T1[Tier-1 Gateway] end subgraph Physical Network Internet((Internet)) end T1 --> T0[Tier-0 Gateway] T0 -- SNAT? --> InternetShow answer details
Correct answer: C
Source NAT (SNAT) is the correct service for this use case. An SNAT rule translates the private source IP address of the VMs to a public, routable IP address as the traffic exits the NSX domain (typically at the Tier-0 Gateway). This allows the VMs to initiate connections to the internet while hiding their internal IP addresses.
- 6
A financial services company is migrating from a traditional hardware-centric data center to a Software-Defined Data Center (SDDC). A primary goal is to automate the provisioning of network and security services to align with their agile development lifecycle. Which core principle of SDDC directly enables this goal?
Show answer details
Correct answer: B
The core principle of an SDDC is the abstraction of all infrastructure resources (compute, storage, networking, security) from the physical hardware. This abstraction allows for policy-based automation and programmatic control, which is essential for automating the provisioning of services in an agile environment. The other options are related concepts but not the fundamental enabler.
- 7
A network administrator is struggling with long lead times for deploying new applications. Each deployment requires manual configuration of VLANs, ACLs, and firewall rules on multiple physical switches and routers, leading to delays and configuration errors. How does the NSX-T network virtualization model primarily address this challenge?
Show answer details
Correct answer: B
NSX-T decouples the virtual network from the physical underlay. This allows network and security services to be created, modified, and deleted in software without touching the physical hardware. This decoupling is the key to providing the speed and agility needed for modern application deployments, directly addressing the challenge of manual, slow physical network configuration.
- 8
In an SDN architecture, which component is responsible for calculating network paths and pushing forwarding rules down to the network devices?
Show answer details
Correct answer: D
A fundamental concept of SDN is the separation of planes. The Control Plane acts as the 'brain' of the network, making intelligent decisions like calculating routes and determining forwarding policies. It then programs the Data Plane (the network devices themselves) with these decisions. The Data Plane is responsible only for executing the forwarding of packets based on the rules it receives.
- 9
A vSphere administrator needs to provide dedicated network bandwidth for vSphere vMotion traffic to ensure live migrations are not impacted by other traffic types. Which vSphere networking component should be created and configured for this purpose?
Show answer details
Correct answer: C
VMkernel ports provide network connectivity for the ESXi host's kernel services, such as vMotion, IP storage (iSCSI/NFS), and vSAN. To isolate and manage vMotion traffic, a dedicated VMkernel port should be created on each host and have the vMotion service enabled on it. This allows for specific IP addressing and traffic shaping for migration activities.
- 10
A company wants to implement a Zero Trust security model within its data center. The primary requirement is to enforce security policies at the individual workload level, regardless of where the workload is running. Which TWO VMware products are most essential for building this solution? (Select TWO)
Show answer details
Correct answer: A, C
vSphere provides the foundational compute virtualization platform where the workloads run. NSX-T provides the Distributed Firewall (DFW), which is the key technology for implementing micro-segmentation. The DFW operates at the vNIC level of each workload, enabling security policies to be enforced for individual workloads, which is the core tenet of a Zero Trust model.
