VMware 5V0-43.21 VMware NSX Advanced Load Balancer(Avi) for Operators Skills Online Training
VMware 5V0-43.21 Online Training
The questions for 5V0-43.21 were last updated at Apr 07,2025.
- Exam Code: 5V0-43.21
- Exam Name: VMware NSX Advanced Load Balancer(Avi) for Operators Skills
- Certification Provider: VMware
- Latest update: Apr 07,2025
Which function is performed by the data plane?
- A . Log indexing
- B . Service engine lifecycle management
- C . Configuration backups
- D . Pool health monitoring
How would an operator replace the default certificate used by the Avi GUI with a trusted certificate?
- A . Generate a certificate of type Controller Certificate, then assign it to the management VS.
- B . Generate a certificate of type Controller Certificate, then update the Access Settings under Administration -> Settings.
- C . Avi can auto-generate a trusted certificate from the GUI and use it for the GUI access.
- D . The default certificate used by the Avi GUI is already trusted.
Which three techniques can an operator use to scale data plane performance? (Choose three.)
- A . BGP-based horizontal scaling of SES in an SE Group
- B . Native horizontal scaling of an individual SE
- C . Increase the maximum number of Virtual Services in an SE Group.
- D . Vertical scaling of an individual SE’s resources
- E . Native horizontal scaling of SES in an SE Group
- F . O OSPF-based horizontal scaling of SEs in an SE Group
An operator needs to configure a second Virtual Service that re-uses an existing VS IP on a separate service port.
How is this handled in the Create VS configuration?
- A . In the Basic Setup Wizard, create the second VS without Auto Allocate, and then type in the existing VS IP.
- B . In the Advanced Setup Wizard, create the second VS as a Child Virtual Service.
- C . In the Advanced Setup Wizard, create the second VS without Auto Allocate, and then type in the existing VS IP.
- D . In the Advanced Setup Wizard, create the second VS with a "Virtual Service for VIP Sharing":
Which method must be used by an Operator to create a new Virtual Service for multiple ports and network protocols?
- A . Create multiple Application Profiles for each required port.
- B . Create the Virtual Service using Basic Mode.
- C . Create the Virtual Service using Advanced Mode.
- D . Create the Virtual Service via the Service Engine CLI.
A virtual service is configured with an HTTP Security policy, Network Security policy, DataScript Response policy, and an HTTP Request policy.
In which order will these be evaluated?
- A . Network Security -> HTTP Security -> HTTP Request -> DataScript Response
- B . Network Security -> HTTP Request -> HTTP Security -> DataScript Response
- C . HTTP Security -> Network Security -> HTTP Request -> DataScript Response
- D . DataScript Response -> Network Security -> HTTP Request -> HTTP Security
An administrator has configured an existing Layer 7 Virtual Service terminating SSL/TLS with WAF enabled. The administrator needs to include support for SMTP on the same FQDN/Virtual Service IP.
Which is the correct configuration method?
- A . Create a second Virtual Service and IP for SMTP, and add a new record in DNS to handle SMTP separately.
- B . Add the SMTP listening ports with separate L4 Application Profile to the same L7 SSL/TLS VS, and use content switching to select SMTP Pool based on inbound port/protocol.
- C . Create a second Virtual Service that re-uses the same Virtual IP as the L7 SSL/TLS VS with separate listening ports, L4 Application Profile, and back-end SMTP pool.
- D . Add the SMTP listening ports with separate L4 Application Profile to the same L7 SSL/TLS VS, and disable destination port translation to the existing server pool.
What are two benefits of EC certificates over RSA certificates? (Choose two.)
- A . ECC provides similar strength as RSA but with much smaller keys.
- B . The certificates cost less money.
- C . Modern browsers no longer support RSA certificates.
- D . Processing for ECC is less CPU-intensive than for RSA.
- E . RSA certificates cannot be used in certain countries.
An operator configured a new content switch rule for HTTP Virtual Service and wants to check the logs on the Virtual Service level to verify that the rule was executed as expected. However, the request cannot be found in the logs.
Which action, if any, should the operator take so these logs can be seen?
- A . Enable non-significant logs on the Service Engine where Virtual Service is placed.
- B . Enable log headers option on the Virtual Service level.
- C . Enable non-significant logs on the Virtual Service level.
- D . No action will work because if the logs are not visible, it means there are no requests from the
client.
Which item can only be configured when the operator uses the Advanced Setup wizard?
- A . Auto Allocation of the VIP
- B . Service Port
- C . Pool Group
- D . IPv6 VIP