Courseiva

CCNA Configure and Manage vSphere Networking Questions

46 questions · Configure and Manage vSphere Networking · All types, answers revealed

1
Multi-Selecthard

An administrator is configuring a distributed switch with LACP. Which two statements are true regarding LACP support on vSphere distributed switches? (Choose two.)

Select 2 answers
A.LACP supports both active and passive modes.
B.LACP automatically distributes traffic based on IP hash.
C.LACP can be configured on standard vSwitches.
D.LACP requires a Link Aggregation Group (LAG) to be created on the distributed switch.
E.LACP is only supported for virtual machine traffic, not for management or vMotion.
AnswersA, D

LACP on a vSphere distributed switch supports both active and passive negotiation modes, letting the ESXi host initiate or await LACPDU exchange with the physical switch. This satisfies the stem's requirement for a true statement about LACP support.

Why this answer

Option A is correct because vSphere distributed switches support LACP in both active and passive modes, allowing the ESXi host to either initiate LACPDU negotiation (active) or respond to the physical switch's negotiation (passive). Option D is correct because LACP on a vSphere distributed switch requires creating a Link Aggregation Group (LAG), which is then bound to a distributed port group or uplink port group to aggregate multiple uplinks. Option B is incorrect because IP hash is a static NIC teaming load-balancing policy, not an LACP behavior; LACP uses a dynamic link aggregation hashing scheme.

Option C is incorrect because LACP is only supported on vSphere distributed switches, not on standard vSwitches. Option E is incorrect because LACP LAGs can carry management, vMotion, and VM traffic, not just virtual machine traffic.

Exam trap

VCP-DCV often tests the misconception that LACP works on standard vSwitches or that it uses IP hash automatically, when in fact it requires a distributed switch and a LAG.

2
MCQeasy

A vSphere administrator is configuring a vSphere Standard Switch (vSS) on an ESXi host. The host has two physical NICs, vmnic0 and vmnic1, connected to the same physical switch. The administrator wants to provide network redundancy for the VM network and ensure that if one uplink fails, traffic continues to flow. Which failover detection method should be used?

A.Beacon probing
B.Link status only
C.Route based on physical NIC load
D.Route based on IP hash
AnswerB

Link status only detects failures based on the physical link state of the uplink. If a cable is unplugged or the switch port goes down, the link status changes and failover occurs. This method is simple and works well when the physical switch is configured correctly, as it detects failures at the physical layer. It is the default and recommended for most scenarios where beacon probing is not needed.

Why this answer

For a vSphere Standard Switch, the failover detection method can be either link status only or beacon probing. Link status only is the simplest and most common method, detecting failures based on the physical link state. Beacon probing is used for more complex failure detection but is not required for basic redundancy.

The other options are teaming policies, not failover detection methods. Therefore, link status only is the correct choice.

Exam trap

The trap here is confusing teaming policies with failover detection methods; beacon probing is a detection method, but it is not necessary for simple link failure detection.

3
MCQmedium

An administrator is configuring a distributed switch for a cluster of ESXi hosts. The requirements are: VLAN 100 for production, VLAN 200 for management, and a separate VLAN 300 for vMotion. The management network should be isolated from production traffic. What is the best practice for configuring these networks on the distributed switch?

A.Create three separate distributed port groups, each with the appropriate VLAN ID, and assign each VM kernel adapter or VM to the correct port group.
B.Create one distributed port group with VLAN 100, and use VLAN tagging on the VMs for management and vMotion.
C.Use standard switches for management and vMotion to avoid complexity.
D.Create one distributed port group with VLAN trunk (4095) and use port-based VLAN filtering on the VMs.
E.Create two port groups: one for production (VLAN 100) and one for management+vMotion (VLAN 200) because vMotion can share VLAN with management.
AnswerA

Three distributed port groups with VLAN IDs 100, 200 and 300 keep production, management and vMotion traffic logically separated at layer 2, isolating management from production while letting each VMkernel adapter or VM attach to its correct segment.

Why this answer

Best practice on a vSphere Distributed Switch is to create one distributed port group per VLAN/network function, each with its own VLAN ID, and attach the appropriate VMkernel adapters (management, vMotion) or VM vNICs to the correct port group. This provides clean traffic isolation, simplifies troubleshooting, and aligns with VMware's recommended design for separating management, vMotion, and production traffic.

Exam trap

VCP-DCV often tests the misconception that guest OS VLAN tagging or trunk port groups can substitute for properly segmented distributed port groups — candidates must remember VMkernel traffic cannot be VLAN-tagged at the guest level.

How to eliminate wrong answers

Option B is wrong because using a single port group with VLAN 100 and relying on guest-level VLAN tagging for management/vMotion is not possible for VMkernel traffic — VMkernel adapters cannot tag VLANs in the guest, and this would mix management traffic into the production VLAN. Option C is wrong because reverting to standard switches defeats the purpose of a distributed switch and adds management complexity, not reduces it. Option D is wrong because VLAN 4095 is a trunk port group that passes all VLANs untagged to the guest; using guest-based VLAN filtering is unsupported for VMkernel traffic and creates security/segmentation risks.

Option E is wrong because vMotion and management should be isolated per VMware best practice; sharing a VLAN is allowed but not recommended, and the question explicitly requires isolation of management from production.

4
MCQhard

A company runs a three-tier application on vSphere 7.0. The web tier uses VLAN 100, app tier VLAN 200, and database tier VLAN 300. Each tier is on a separate port group on a vSphere distributed switch. The environment uses Network I/O Control (NIOC) with shares set to: Web (50), App (30), Database (20). The physical uplinks are two 10 GbE NICs in a team. Recently, the database team reports slow performance during peak hours. The network team checks the physical switches and finds no congestion. The ESXi host shows the two uplinks are heavily utilized with many dropped packets on the database port group. The administrator suspects that the database traffic is being starved by other traffic. Which action should the administrator take to resolve the issue? A. Increase the number of physical uplinks to four 10 GbE NICs. B. Change the NIOC shares to Web (10), App (30), Database (60). C. Create a separate vSphere standard switch for the database tier. D. Enable SR-IOV on the physical NICs and assign virtual functions to database VMs.

A.Create a separate vSphere standard switch for the database tier.
B.Enable SR-IOV on the physical NICs and assign virtual functions to database VMs.
C.Increase the number of physical uplinks to four 10 GbE NICs.
D.Change the NIOC shares to Web (10), App (30), Database (60).
AnswerD

NIOC shares allocate relative bandwidth only under contention, and the database's share of 20 is the lowest, so its traffic is starved on the saturated uplinks. Raising database shares to 60 gives that tier proportionally more bandwidth, directly addressing the constraint.

Why this answer

The database traffic is being starved due to low NIOC shares relative to the web and app tiers. By increasing the database shares to 60 and reducing web to 10, the database port group will receive a higher proportion of the available bandwidth during congestion, alleviating the dropped packets and slow performance. NIOC shares are relative and only take effect when there is contention, so adjusting them directly addresses the starvation without requiring additional hardware.

Exam trap

The trap here is that candidates often assume adding more physical uplinks or isolating traffic on a separate switch will solve performance issues, but they overlook that NIOC shares directly control bandwidth allocation during congestion, and adjusting them is the most efficient and cost-effective solution.

How to eliminate wrong answers

Option A is wrong because increasing the number of physical uplinks to four 10 GbE NICs does not address the root cause of traffic starvation; it only adds more bandwidth, which may not help if the existing bandwidth is not being fairly allocated due to NIOC share settings. Option B is wrong because enabling SR-IOV on the physical NICs and assigning virtual functions to database VMs bypasses the vSphere network stack, but it does not resolve the contention on the shared uplinks; it could introduce complexity and is not a direct fix for NIOC share misconfiguration. Option C is wrong because creating a separate vSphere standard switch for the database tier would isolate the traffic but would still share the same physical uplinks unless dedicated uplinks are assigned, which is not mentioned; it also does not leverage NIOC's traffic shaping capabilities and may lead to underutilization of resources.

5
MCQhard

Refer to the exhibit. An administrator notices that two uplinks are down on the VDS. Which step should be taken first to restore redundancy?

A.Check the physical switch ports and cables for uplink2 and uplink3.
B.Increase the MTU to 9000 to improve performance.
C.Disable LACP on the VDS to allow single-uplink operation.
D.Remove the down uplinks from the VDS.
AnswerA

Physical connectivity issues are the most common cause of down uplinks.

6
MCQmedium

A vSphere administrator is troubleshooting connectivity issues for a virtual machine that is unable to communicate with other VMs on the same VLAN. The VM is connected to a distributed port group on a vSphere Distributed Switch (vDS). The administrator verifies that the VM's IP configuration is correct and that the port group is configured with the correct VLAN ID. However, the VM can only communicate with other VMs on the same ESXi host. What is the most likely cause?

A.The vDS is not configured with a VLAN trunking policy.
B.The VM's network adapter is configured with the wrong MAC address.
C.The distributed port group has forging transmits set to reject.
D.The physical switch ports connecting the ESXi hosts are not configured as trunk ports for the VLAN.
AnswerD

A distributed port group carries its VLAN tag to the physical switch, which must trunk that VLAN to reach VMs on other hosts. Without trunking, frames stay confined to the local host's uplink, matching the symptom of same-host-only communication despite correct VM and port group settings.

Why this answer

If the VM can communicate with other VMs on the same ESXi host but not with VMs on other hosts in the same VLAN, the issue is almost certainly that the physical switch ports connecting the ESXi hosts are not configured as trunk ports carrying that VLAN. The vDS and port group are correctly configured, so the failure is at the physical uplink layer where VLAN tags must be allowed to pass between hosts.

Exam trap

VCP-DCV often tests whether candidates blame the vDS configuration when the real fault is upstream on the physical switch — remember that intra-host success with inter-host failure points to the physical uplink/trunk, not the virtual switch.

How to eliminate wrong answers

Option A is wrong because a vDS does not require a global 'VLAN trunking policy' to be enabled for a single-VLAN port group to work — VLAN tagging is set per port group, and the symptom is host-to-host, not trunk-related. Option B is wrong because a wrong MAC address would typically cause the VM to fail all communication, not selectively fail only cross-host traffic. Option C is wrong because 'forging transmits set to reject' blocks MAC address spoofing, not normal VM-to-VM traffic on the same VLAN.

7
MCQeasy

An administrator needs to provide redundancy for VM traffic across multiple physical NICs on a vSphere Standard Switch. Which NIC teaming policy should be used to ensure fault tolerance without load balancing?

A.Route based on IP hash
B.Route based on originating virtual port
C.Use explicit failover order (Active/Standby)
D.Route based on source MAC hash
AnswerC

Explicit failover order with Active/Standby keeps one NIC passing traffic and holds the others as standby, providing fault tolerance without distributing load. Other policies such as route based on originating port ID actively load balance, which the requirement excludes.

Why this answer

The 'Use explicit failover order (Active/Standby)' policy designates one or more NICs as active and the rest as standby, providing pure fault tolerance without any load balancing. When the active NIC fails, traffic automatically fails over to the standby NIC, ensuring redundancy without distributing traffic across multiple uplinks.

Exam trap

The trap here is that candidates often confuse 'fault tolerance without load balancing' with load-balancing policies like IP hash or source MAC hash, mistakenly thinking any teaming policy provides redundancy, but only the explicit failover order ensures a single active path with no traffic distribution.

How to eliminate wrong answers

Option A is wrong because 'Route based on IP hash' uses a hash of source and destination IP addresses to distribute traffic across multiple active NICs, which provides load balancing but not pure fault tolerance without load balancing. Option B is wrong because 'Route based on originating virtual port' distributes traffic based on the virtual switch port ID, which also load-balances across active NICs and does not guarantee a single active path for fault tolerance. Option D is wrong because 'Route based on source MAC hash' uses the source MAC address to distribute traffic across multiple active NICs, again providing load balancing rather than the required fault tolerance without load balancing.

8
MCQeasy

An administrator sees this health check output. What should be done to verify VLAN 100 connectivity?

A.Create a VMkernel adapter on VLAN 100 and ping a gateway.
B.Enable VLAN pruning on the physical switch.
C.Configure a port group for VLAN 100 and connect a VM.
D.Restart the management agents.
AnswerA

Placing a VMkernel adapter on VLAN 100 and pinging its gateway tests Layer 2 tag propagation and Layer 3 reachability end to end. This directly verifies whether VLAN 100 traffic passes the physical switch, which a health check alone cannot confirm.

Why this answer

To verify VLAN 100 connectivity at the ESXi host level, the administrator must create a VMkernel adapter tagged with VLAN 100 on the distributed or standard switch and then ping a gateway or another host in that VLAN. This tests the host's own L2/L3 path for that VLAN without involving a guest VM. It directly validates that the physical switch trunk, VLAN tagging, and uplink configuration are correct.

Exam trap

VCP-DCV often tests whether candidates know to verify host-level VLAN connectivity with a VMkernel adapter rather than a VM, confusing guest-level testing with host-level validation.

How to eliminate wrong answers

Option B is wrong because enabling VLAN pruning on the physical switch is a configuration change, not a verification step, and pruning could actually break VLAN 100 rather than confirm connectivity. Option C is wrong because connecting a VM to a VLAN 100 port group tests guest connectivity, not the host's own VLAN path, and adds variables (guest OS, NIC driver) that obscure the host-level check. Option D is wrong because restarting management agents does not test VLAN 100 connectivity and is a disruptive action unrelated to L2 reachability verification.

9
MCQmedium

An administrator has configured a vSphere Distributed Switch (VDS) with Network I/O Control. They need to guarantee bandwidth for a specific set of virtual machines. Which method should be used?

A.Create a port group with a custom network resource pool.
B.Enable SR-IOV on the physical NICs.
C.Set the virtual machine's network adapter to use a specific VLAN.
D.Configure Traffic Shaping on the distributed switch.
AnswerA

Network I/O Control guarantees bandwidth through network resource pools, which are assigned to distributed port groups. Creating a port group with a custom resource pool reserves shares, limits or reservations for the specific VMs placed on it.

Why this answer

Create a port group with a custom network resource pool. Network I/O Control allows administrators to create network resource pools to guarantee bandwidth for specific virtual machines or port groups. By creating a custom network resource pool and assigning it to a port group, you can reserve a certain amount of bandwidth.

Option B is incorrect because SR-IOV provides direct hardware passthrough but does not manage bandwidth guarantees; it can actually bypass Network I/O Control. Option C is incorrect because setting a VLAN tag does not guarantee bandwidth; it only separates traffic. Option D is incorrect because traffic shaping is used to limit bandwidth (throttle outgoing traffic) but does not guarantee a minimum bandwidth; it only caps it.

10
Multi-Selectmedium

Which four types of traffic can be assigned to a separate VMkernel adapter on an ESXi host?

Select 4 answers
A.Management traffic
B.vMotion
C.vSAN
D.Virtual machine network traffic
E.Fault Tolerance logging
AnswersA, B, C, E

Management traffic is one of the four traffic types that can be placed on a dedicated VMkernel adapter, alongside vMotion, vSAN and fault tolerance. Isolating it on its own VMkernel interface separates host administration from other network flows.

Why this answer

Management traffic (A) is a valid VMkernel service that can be enabled on a dedicated VMkernel adapter to isolate host management from other traffic. vMotion (B) is also a VMkernel service that can be assigned to its own VMkernel adapter to separate live migration traffic. vSAN (C) is a VMkernel service that can be enabled on a dedicated VMkernel adapter for vSAN storage communication. Fault Tolerance logging (E) is a VMkernel service that can be assigned to a separate VMkernel adapter for FT metadata traffic. Virtual machine network traffic (D) is not a VMkernel service; it is handled by standard or distributed virtual switches and port groups, not by a VMkernel adapter.

Exam trap

VCP-DCV often tests the confusion between VMkernel services and VM port group traffic — candidates incorrectly include 'virtual machine network traffic' as a VMkernel service.

11
MCQhard

A vSphere administrator is designing a network for a cluster of ESXi hosts. Each host has four 10GbE uplinks. The cluster will host mission-critical VMs that require maximum throughput and redundancy. The administrator plans to use Network I/O Control (NIOC) and a vSphere Distributed Switch (vDS). Which configuration best ensures consistent network performance for all VMs?

A.Configure a single vDS with all four uplinks, enable NIOC, and set shares and reservations for each traffic type.
B.Configure a single vDS with all four uplinks and enable NetFlow for monitoring.
C.Create two separate vDS, each with two uplinks, and separate VM traffic from VMkernel traffic.
D.Configure a single vDS with all four uplinks and use Route based on IP hash teaming.
AnswerA

A single vDS pooling all four uplinks with NIOC shares and reservations guarantees bandwidth allocation per traffic type, satisfying the consistent-performance and redundancy requirement. Reservations protect mission-critical VM throughput during contention across the 10GbE uplinks.

Why this answer

NIOC enables per-traffic-type resource management using shares, reservations, and limits, ensuring that mission-critical VMs receive consistent network throughput even under contention. Combining all four uplinks into a single vDS maximizes aggregate bandwidth and provides redundancy through teaming policies, while NIOC prioritizes traffic flows to prevent VMkernel or management traffic from starving VM traffic.

Exam trap

The trap here is that candidates often confuse load-balancing algorithms (like IP hash) with QoS mechanisms, assuming that distributing traffic across uplinks alone guarantees performance, when in fact NIOC's per-traffic-type resource controls are required to enforce consistent throughput for all VMs.

How to eliminate wrong answers

Option B is wrong because NetFlow is a monitoring and traffic analysis tool, not a QoS or performance guarantee mechanism; it does not allocate bandwidth or enforce fairness among traffic types. Option C is wrong because splitting uplinks across two separate vDS reduces the total available bandwidth per vDS and prevents NIOC from managing all traffic centrally, leading to potential underutilization and inconsistent performance. Option D is wrong because Route based on IP hash provides load balancing but does not offer per-traffic-type resource controls like shares and reservations, so it cannot guarantee consistent performance for all VMs under contention.

12
MCQhard

Refer to the exhibit. The administrator notices rx_dropped packets on vmnic0 but no errors. What is the most likely cause of the dropped packets?

A.There is a VLAN mismatch causing packets to be dropped.
B.The virtual switch port has insufficient buffer space.
C.The physical NIC's receive ring buffer is overflowing due to high traffic.
D.The physical switch is dropping packets due to congestion.
AnswerC

rx_dropped increments when the physical NIC's receive ring buffer has no free descriptors to accept incoming frames, so packets are discarded before reaching the vSwitch. The absence of errors confirms the drops stem from buffer exhaustion under high traffic, not link faults.

Why this answer

rx_dropped packets on a vmnic indicate that the physical NIC's receive ring buffer is overflowing, typically due to a burst of traffic that exceeds the buffer's capacity. This causes packets to be dropped before they can be processed by the network stack. The absence of errors suggests the drops are due to buffer exhaustion, not corruption or misconfiguration.

Exam trap

VCP-DCV often tests the confusion between physical NIC drops and virtual switch drops, leading candidates to incorrectly blame VLAN mismatches or virtual switch buffer issues instead of the physical NIC's ring buffer.

How to eliminate wrong answers

Option A is wrong because a VLAN mismatch would typically cause packets to be dropped at the virtual switch level, not necessarily increment rx_dropped on the physical NIC, and would often be accompanied by other errors. Option B is wrong because virtual switch port buffer space is not a common cause of rx_dropped on the physical NIC; the physical NIC's ring buffer is the primary suspect. Option D is wrong because drops on the physical switch would not be reflected in the ESXi host's vmnic statistics; rx_dropped is a local counter.

13
MCQmedium

An administrator is configuring a vSphere Distributed Switch (vDS) with multiple uplinks. The administrator wants to ensure that a single virtual machine's traffic uses only one physical uplink at a time to avoid out-of-order packet delivery. Which vDS teaming policy should the administrator select?

A.Route based on originating virtual port ID
B.Use explicit failover order
C.Route based on IP hash
D.Route based on physical NIC load
AnswerA

Route based on originating virtual port ID assigns each virtual machine's virtual port to a specific uplink. All traffic from that VM uses the same uplink, ensuring in-order delivery. This policy is the default and is suitable for most workloads that do not require more than one uplink's bandwidth.

Why this answer

Route based on originating virtual port ID pins each virtual machine's traffic to a single uplink, ensuring that packets from that VM are not spread across multiple uplinks and thus avoiding out-of-order delivery. IP hash and physical NIC load can distribute a VM's flows across uplinks, and explicit failover order does not provide per-VM distribution.

Exam trap

The trap here is assuming that IP hash or physical NIC load is better for performance, but they can cause out-of-order delivery for a single VM.

14
MCQeasy

A vSphere administrator needs to migrate a virtual machine from one ESXi host to another while the virtual machine remains powered on. The virtual machine has a single vNIC connected to a standard switch port group named 'Production'. The destination host is in the same cluster and has a standard switch with a port group named 'Production' but with different VLAN settings. What will happen if the administrator attempts a vMotion migration?

A.The vMotion migration will fail because the VLAN settings are different.
B.The vMotion migration will succeed, and the virtual machine will use the VLAN settings of the destination port group.
C.The vMotion migration will fail because the port group names do not match exactly.
D.The vMotion migration will succeed, and the virtual machine will continue to use the VLAN settings of the source port group.
AnswerB

vMotion requires that a port group with the same name exists on the destination host. The virtual machine's vNIC will be connected to that port group, and it will inherit the VLAN settings configured on that destination port group. Therefore, if the VLAN settings differ, the virtual machine will use the destination's VLAN settings after migration. This can cause connectivity issues if not planned for.

Why this answer

During a vMotion migration, the virtual machine's network adapter is reconnected to a port group on the destination host that has the same name as the source port group. The VLAN settings of the destination port group are applied, not the source. This means that if VLAN settings differ, the virtual machine will use the destination's VLAN after migration.

The migration itself will succeed as long as the port group name exists, regardless of VLAN differences.

Exam trap

The trap here is assuming that vMotion preserves the source VLAN settings or that it fails if VLANs differ, when in reality it adopts the destination port group's VLAN settings.

15
Multi-Selectmedium

Which three factors influence the behavior of Network I/O Control (NIOC) when allocating bandwidth to different traffic types? (Choose three.)

Select 3 answers
A.The total physical bandwidth
B.Reservation per traffic type
C.Shares per traffic type
D.Limit per traffic type
E.The number of physical uplinks
AnswersB, C, D

Reservations guarantee a minimum bandwidth share for each traffic type, so NIOC honours them before distributing any remaining capacity. This directly satisfies the stem's allocation behaviour: a traffic type with a reservation cannot be starved by busier flows, even when shares and limits would otherwise favour competing traffic.

Why this answer

Network I/O Control (NIOC) allocates bandwidth on a vSphere Standard or Distributed Switch based on three per-traffic-type settings: Reservation (B), which guarantees a minimum bandwidth in Mbps or Gbps that the traffic type can always use; Shares (C), which determine the relative priority for distributing any remaining bandwidth when the link is contended (e.g., High=100, Normal=50, Low=25 per active uplink); and Limit (D), which caps the maximum bandwidth the traffic type may consume. These three parameters together define how NIOC divides and prioritizes bandwidth among traffic types such as vMotion, iSCSI, and VM traffic. The total physical bandwidth (A) is not a configurable NIOC factor — it is the underlying capacity that reservations, shares, and limits act upon, and NIOC itself does not let you set it.

The number of physical uplinks (E) affects aggregate capacity and teaming behavior, but NIOC allocation is driven by the per-traffic-type reservation, shares, and limit values, not by the uplink count.

Exam trap

VCP-DCV often tests NIOC parameters by mixing in physical capacity factors (total bandwidth, number of uplinks), so candidates who confuse aggregate capacity with per-traffic-type allocation parameters pick the wrong options.

16
MCQmedium

A VM on a vSphere Distributed Switch is experiencing intermittent connectivity drops. The administrator checks the vDS health check and sees no errors. The physical switch logs show no issues. The VM is on a port group with VLAN 200. The administrator runs a ping from the VM to the gateway and notices packet loss. What should the administrator investigate next?

A.Verify the VMkernel port configuration
B.Check the VM's firewall settings
C.Check DNS resolution for the gateway
D.Review the NIC teaming failover order and ensure active uplinks are up.
AnswerD

Intermittent loss with clean health checks and switch logs points to uplink pathing. If the active uplink in the teaming failover order is down, traffic drops until failover, matching the observed packet loss on VLAN 200.

Why this answer

Intermittent connectivity drops on a VM connected to a vDS, despite no errors on the vDS health check or physical switch logs, often point to a NIC teaming misconfiguration. If the active uplinks are not properly set or one uplink is down, the VM traffic may fail over to a standby or unused uplink, causing packet loss. Verifying the teaming failover order and ensuring all active uplinks are operational directly addresses this common cause of intermittent drops.

Exam trap

The trap here is that candidates often assume intermittent connectivity must be a VM firewall or DNS issue, overlooking the NIC teaming failover order as a primary cause of packet loss on a vDS when physical and vDS health checks show no errors.

How to eliminate wrong answers

Option A is wrong because VMkernel port configuration is used for management traffic, vMotion, or storage, not for VM data traffic on a port group; investigating it would not resolve VM connectivity drops. Option B is wrong because the VM's firewall settings (e.g., Windows Firewall) would typically block all traffic or allow it consistently, not cause intermittent packet loss to a gateway; the issue is at the network layer, not the host firewall. Option C is wrong because DNS resolution is used for name-to-IP mapping, not for direct IP connectivity; the administrator is pinging the gateway IP, so DNS is irrelevant to packet loss.

17
Multi-Selecteasy

Which two actions must the administrator take to ensure network connectivity for VMs on a new distributed switch?

Select 2 answers
A.Configure a VMkernel interface on the distributed switch
B.Add the ESXi hosts to the distributed switch
C.Set the MTU to 9000
D.Create a port group and assign a VLAN
E.Enable Network I/O Control
AnswersB, D

Adding ESXi hosts to the distributed switch is mandatory because a vSphere Distributed Switch spans multiple hosts, and each host must be a member before its physical uplinks (vmnic) can be attached to dvUplinks. Without host membership, VMs cannot reach the dvPortGroup, so connectivity fails.

Why this answer

To provide network connectivity for VMs on a new vSphere Distributed Switch, the administrator must first add the ESXi hosts to the distributed switch (option B), because a vDS only manages networking on hosts that are members of it; without host membership, no physical uplinks or VM traffic can traverse the switch. The administrator must also create a port group and assign a VLAN (option D), since VM vNICs connect to distributed port groups, and the VLAN ID on that port group determines the Layer 2 broadcast domain for the VMs. Configuring a VMkernel interface (option A) is only required for host management, vMotion, iSCSI, or vSAN traffic, not for general VM connectivity.

Setting MTU to 9000 (option C) is an optional jumbo-frame tuning, and enabling Network I/O Control (option E) is an optional traffic-shaping/QoS feature; neither is required for basic VM network connectivity.

Exam trap

VCP-DCV often tests the confusion between host-level and VM-level networking requirements, tricking candidates into selecting VMkernel interfaces or optional features like MTU or NIOC instead of the mandatory host addition and port group creation.

18
MCQeasy

An administrator is configuring a vSphere Standard Switch on an ESXi host. The switch has two physical NICs (vmnic0 and vmnic1) and several virtual machine port groups. The administrator wants to ensure that if vmnic0 fails, all virtual machine traffic automatically fails over to vmnic1 without manual intervention. Which setting should the administrator verify?

A.The failover detection method is set to beacon probing.
B.The virtual machine port groups are assigned to different VLANs.
C.Both physical NICs are set as active uplinks in the teaming and failover policy.
D.The switch is configured with a single uplink and the second NIC is assigned to a different standard switch.
AnswerC

When both physical NICs are active uplinks, the teaming policy allows traffic to use either NIC. If one NIC fails, the other continues to carry traffic, providing automatic failover. This is the simplest and most common configuration for redundancy. The administrator should ensure that both NICs are listed as active and that the load balancing policy is appropriate.

Why this answer

For automatic failover on a vSphere Standard Switch, the physical NICs must be configured as active uplinks in the same team. When one NIC fails, the other active NIC takes over the traffic. This is the fundamental redundancy mechanism.

Other settings like beacon probing are optional and not required for basic failover.

Exam trap

The trap here is overcomplicating the failover requirement by focusing on advanced detection methods instead of the basic active uplink configuration.

19
MCQhard

After upgrading the physical switches, the LAG (Link Aggregation Group) on a VDS does not come up. The VDS LAG configuration shows LACP active mode. The physical switch ports are configured with LACP active mode as well. What is the most likely cause?

A.The physical switch uses a different LACP system priority
B.The physical switch ports are not in a port-channel
C.The ESXi hosts have different LAG IDs
D.The VDS LAG hashing algorithm is set to IP hash
AnswerB

LACP active mode on both sides requires the physical switch ports to be members of a port-channel; without that, LACP PDUs are exchanged but no aggregation forms, so the VDS LAG stays down. The stem's constraint is that both ends already run LACP active, leaving the missing switch-side port-channel as the cause.

Why this answer

For a VDS LAG in LACP active mode to come up, the physical switch ports must be configured as a port-channel (LAG) with LACP enabled. If the switch ports are left as individual access ports without a port-channel, the ESXi host's LACP PDUs are not matched to a LAG on the switch side, and the LAG never forms. This is the most common cause after a switch upgrade where the port-channel configuration was not reapplied.

Exam trap

VCP-DCV often tests the assumption that matching LACP modes is sufficient, when the real requirement is that the physical switch ports must be members of a port-channel/LAG.

How to eliminate wrong answers

Option A is wrong because differing LACP system priority values do not prevent a LAG from forming; system priority is used to elect the LACP actor and only matters in multi-chassis or tie-breaking scenarios, not for basic LAG formation. Option C is wrong because LAG IDs are local to each ESXi host and do not need to match across hosts; each host forms its own LAG with the switch independently. Option D is wrong because the hashing algorithm (IP hash vs. others) affects load balancing, not whether the LAG comes up; a LAG can form with any hashing algorithm.

20
MCQeasy

A VM cannot connect to the network after being migrated to a different host in the cluster. The VM's network adapter is connected to a standard switch port group that exists on the source host but not on the destination host. What is the most likely cause?

A.The standard switch is not configured on the destination host.
B.The VM's MAC address is not allowed on the destination port group.
C.The VLAN ID on the port group does not match.
D.The ESXi host's firewall is blocking the VM's traffic.
AnswerA

A vSphere Standard Switch is host-local, so its port groups exist only on hosts where it was created. Because the destination host lacks that standard switch, the VM's adapter has no matching port group to connect to, breaking network connectivity after migration.

Why this answer

A standard vSwitch and its port groups are host-local objects — they are not shared across ESXi hosts in a cluster. If the VM's port group exists only on the source host, the destination host has no matching port group, so the VM's network adapter cannot connect after migration. This is the classic cause of post-migration network loss with standard switches.

Exam trap

VCP-DCV often tests the host-local nature of standard vSwitches versus the cluster-wide scope of distributed switches, baiting candidates into VLAN or firewall answers.

How to eliminate wrong answers

Option B is wrong because MAC address restrictions are a security policy feature (e.g., on a distributed switch or port security), not the default behavior, and would not be triggered simply by migration. Option C is wrong because a VLAN mismatch would still allow the port group to exist and the VM to connect — it would cause connectivity issues but not a 'port group not found' condition. Option D is wrong because the ESXi firewall governs host management traffic, not VM guest traffic on a vSwitch, so it would not block the VM's network adapter.

21
MCQeasy

An administrator is reviewing the network configuration of a standard switch. The exhibit shows the current settings for a port group. Which change would improve load distribution for VM traffic?

A.Change the VLAN ID to 100.
B.Enable failover on the port group.
C.Change the load balancing policy to Route based on IP hash.
D.Set one NIC as active and the other as standby.
AnswerC

Route based on IP hash distributes traffic across physical uplinks by hashing source and destination IP addresses, spreading VM flows over multiple NICs. The default port-based policy pins each VM to one uplink, so this change directly improves load distribution for the port group's traffic.

Why this answer

Route based on IP hash uses a hash of source and destination IP addresses to determine which uplink to use for each traffic flow, ensuring that all packets in a given flow use the same uplink while distributing different flows across multiple uplinks. This improves load distribution for VM traffic compared to the default Route based on the originating virtual port, which only considers the vNIC port ID and can lead to uneven distribution when multiple VMs share the same port group.

Exam trap

The trap here is that candidates often confuse 'failover' with 'load balancing' and assume enabling failover (Option B) will distribute traffic, but failover only provides redundancy, not active load sharing, while Route based on IP hash (Option C) is the correct method for distributing VM traffic across multiple uplinks.

How to eliminate wrong answers

Option A is wrong because changing the VLAN ID to 100 would alter the VLAN tagging for the port group, which does not affect load balancing or distribution of VM traffic across uplinks. Option B is wrong because failover is already implicitly enabled on a standard switch with multiple uplinks; enabling failover is not a configurable toggle and does not improve load distribution—it only ensures redundancy. Option D is wrong because setting one NIC as active and the other as standby would disable load balancing entirely, forcing all traffic through the active NIC and leaving the standby NIC unused until a failure occurs, which reduces rather than improves load distribution.

22
MCQmedium

An administrator configures a VDS with two uplinks and sets the load balancing policy to 'Route based on IP hash'. What additional configuration is required on the physical switches to ensure proper traffic distribution?

A.Use individual ports with no aggregation.
B.Set port security to allow multiple MAC addresses.
C.Enable Link Aggregation Control Protocol (LACP).
D.Configure a static EtherChannel.
AnswerD

IP hash hashes each flow to one uplink based on source and destination IP, so the physical switch ports must be bundled into a static EtherChannel. Without that link aggregation, the switch treats the uplinks as separate links and may drop or misdirect traffic.

Why this answer

'Route based on IP hash' on a vSphere Distributed Switch requires the physical switch ports to be configured as a static EtherChannel (or equivalent LAG). IP hash uses a hash of source and destination IPs to select an uplink, and the physical switch must treat the uplinks as a single logical link so return traffic flows correctly.

Exam trap

VCP-DCV often tests the distinction between static EtherChannel (for IP hash) and LACP (for dynamic LAG), causing candidates to pick LACP when the question specifies IP hash without LACP.

How to eliminate wrong answers

Option A is wrong because individual, non-aggregated ports would cause the physical switch to see the same MAC on multiple ports, leading to MAC flapping and dropped frames. Option B is wrong because port security allowing multiple MACs does not create the required link aggregation and does not solve the hashing/return-path problem. Option C is wrong because LACP is used with 'Route based on IP hash' only when the VDS is configured for LACP; the classic IP hash setup uses a static EtherChannel, not dynamic LACP.

23
MCQhard

Refer to the exhibit. An administrator notices that the ESXi host is listening on both IPv4 and IPv6 for HTTPS. However, IPv6 traffic is not being forwarded to the host. Which configuration change is most likely needed?

A.Configure a default gateway for the IPv6 stack on the host.
B.Disable IPv6 and use only IPv4.
C.Remove the IPv4 HTTPS listener to force IPv6.
D.Enable IPv6 on the vSphere Distributed Switch.
AnswerA

Without a default IPv6 gateway, the host can receive IPv6 traffic on its local subnet but cannot route replies beyond it, so forwarded IPv6 packets fail. Configuring the gateway satisfies the stem's requirement that IPv6 traffic reach the host across subnets, restoring bidirectional HTTPS connectivity.

Why this answer

If the ESXi host is listening on IPv6 for HTTPS but IPv6 traffic isn't being forwarded to it, the host likely lacks a default gateway for its IPv6 stack. Without an IPv6 default gateway, the host can communicate on-link but cannot route replies to off-subnet IPv6 clients, so forwarded traffic never returns. Configuring an IPv6 default gateway on the host resolves the routing gap.

Exam trap

The trap is focusing on the listener/service state ('it's listening on IPv6, so IPv6 must be enabled') and overlooking that a bound listener without an IPv6 default gateway cannot route replies to off-subnet clients — candidates often pick switch-level or disable-IPv6 options instead of the host routing fix.

How to eliminate wrong answers

Option B is wrong because disabling IPv6 and using only IPv4 doesn't fix the requirement to forward IPv6 traffic — it abandons IPv6 entirely rather than enabling it. Option C is wrong because removing the IPv4 HTTPS listener doesn't make IPv6 work; the host would still lack an IPv6 default gateway and the problem would persist (and you'd lose IPv4 management). Option D is wrong because enabling IPv6 on the vSphere Distributed Switch is a switch-level setting; the symptom is host-level routing (listener present, traffic not forwarded), and the DVS already carries the traffic — the missing piece is the host's IPv6 default gateway.

24
MCQmedium

A VM experiences high packet loss during peak hours. The VM is connected to a distributed switch port group with a traffic shaping policy: average bandwidth 100 Mbps, peak bandwidth 200 Mbps, burst size 50 KB. What is the most likely cause?

A.The peak bandwidth limit is being exceeded.
B.The burst size is too small, causing packets to be dropped when burst traffic exceeds the average.
C.The traffic shaping policy is disabled.
D.The physical uplink speed is less than 200 Mbps.
AnswerB

With 50 KB burst, sustained bursts above average cause drops.

Why this answer

Traffic shaping allows sustained traffic up to the average bandwidth (100 Mbps) and only permits bursts up to the peak bandwidth (200 Mbps) within the configured burst size. If the burst size is too small, burst traffic above the average during peak hours will be dropped, causing packet loss. The peak bandwidth limit is not necessarily being exceeded, a disabled policy would remove these shaping drops, and while a physical uplink slower than 200 Mbps could cause loss, the most likely cause given the configured policy and peak-hour burst behavior is the too-small burst size.

25
MCQeasy

An administrator needs to configure a vSphere Standard Switch (vSS) for a small environment. Which component must be created first before adding a virtual machine to the network?

A.Create a standard switch.
B.Configure a VMkernel interface.
C.Create a virtual machine port group.
D.Add a physical uplink to the host.
AnswerA

A standard switch provides the Layer 2 forwarding fabric that port groups and VM vNICs attach to. Without it, no uplink or virtual network exists, so it must be created before any virtual machine can be placed on the network.

Why this answer

Before a VM can be attached to a network on a vSphere Standard Switch, a standard switch must exist. The switch is the foundational layer; port groups and VMkernel interfaces are created on top of it. Therefore, creating the standard switch is the first required step.

Exam trap

VCP-DCV often tests the dependency order of vSS components — candidates pick 'port group' because that is what the VM connects to, forgetting the switch must exist first as the parent object.

How to eliminate wrong answers

Option B is wrong because a VMkernel interface is for host management, vMotion, iSCSI, etc., and is not required for VM network connectivity — it is created after the switch exists. Option C is wrong because a virtual machine port group is created on an existing standard switch; it cannot exist without the switch. Option D is wrong because adding a physical uplink is optional for a vSS (you can have an internal-only switch) and is done after the switch is created, not before.

26
MCQmedium

A vSphere administrator is configuring a vSphere Standard Switch on an ESXi host. The physical switch port is configured as a trunk allowing VLANs 10, 20, and 30. The administrator needs to ensure that virtual machine traffic tagged with VLAN 20 is properly isolated and that the ESXi host itself can communicate on VLAN 10 for management. Which configuration should the administrator apply to the port group used by the VMs?

A.Set the port group VLAN ID to 0 (None).
B.Set the port group VLAN ID to 4095 (All).
C.Set the port group VLAN ID to 20.
D.Set the port group VLAN ID to 10.
AnswerC

Setting the port group VLAN ID to 20 ensures that all traffic from VMs connected to this port group is tagged with VLAN 20 (if the virtual switch tagging is used) or placed into VLAN 20. This matches the trunk configuration on the physical switch, allowing proper isolation. The host's management traffic is separate, typically on a different port group or VMkernel adapter with VLAN 10, so this port group correctly serves the VMs.

Why this answer

The port group VLAN ID must match the desired VLAN for the VMs, which is 20. This ensures that traffic from VMs is tagged with VLAN 20 and isolated from other VLANs. Using None or All would not correctly tag the traffic, and using VLAN 10 would misplace the VMs.

The physical switch trunk already allows VLAN 20, so the configuration aligns.

Exam trap

The trap here is confusing VLAN 0 (None) with VLAN 4095 (All) and assuming that None allows the physical switch to assign the VLAN based on the trunk's native VLAN, which would not isolate VLAN 20.

27
Multi-Selecthard

Which THREE are valid methods to isolate and secure management traffic on a vSphere Distributed Switch? (Choose three.)

Select 3 answers
A.Enable Route based on IP hash on the management port group.
B.Assign a specific VLAN ID to the management port group.
C.Use Private VLANs on the management port group.
D.Configure the ESXi firewall to restrict management access.
E.Create a dedicated VMkernel port group for management.
AnswersB, D, E

VLANs provide isolation.

Why this answer

Assigning a specific VLAN ID to the management port group isolates management traffic at Layer 2 by tagging frames with a unique VLAN identifier. This prevents unauthorized access from other VLANs and ensures that management traffic is logically separated from other network traffic on the same vSphere Distributed Switch.

Exam trap

The trap here is that candidates often confuse load-balancing policies (like Route based on IP hash) with security features, or they overcomplicate isolation by choosing Private VLANs instead of the simpler and more reliable VLAN assignment.

28
MCQhard

A vSphere administrator is configuring a vSphere Distributed Switch (vDS) with multiple uplinks. The environment requires that vMotion traffic and virtual machine traffic use separate physical uplinks to avoid contention. The administrator creates two distributed port groups: one for vMotion and one for VM traffic. Which vDS feature should be used to ensure that vMotion traffic uses only vmnic2 and VM traffic uses only vmnic3?

A.Configure Network I/O Control (NIOC) with shares and reservations for the vMotion and VM traffic.
B.Use the teaming and failover policy on each distributed port group to specify active and standby uplinks.
C.Create a LAG and assign vmnic2 and vmnic3 to it, then configure NIOC to prioritize vMotion.
D.Assign each port group to a different VLAN and rely on VLAN tagging to direct traffic to the correct uplink.
AnswerB

By setting the teaming and failover policy on the vMotion port group to use vmnic2 as active and vmnic3 as standby, and on the VM port group to use vmnic3 as active and vmnic2 as standby, the administrator ensures that each traffic type uses its designated uplink. This provides the required separation and also offers failover protection if one uplink fails.

Why this answer

The teaming and failover policy on a distributed port group allows you to specify which physical uplinks are active and which are standby for that port group. By configuring the vMotion port group to use vmnic2 as active and vmnic3 as standby, and the VM port group to use vmnic3 as active and vmnic2 as standby, traffic is separated onto distinct uplinks. This also provides redundancy in case of uplink failure.

Exam trap

The trap here is confusing bandwidth prioritization (NIOC) with physical uplink selection, which is controlled by teaming and failover policies.

29
MCQmedium

An administrator needs to capture traffic from a specific virtual machine for troubleshooting. Which vSphere networking feature should be used?

A.Port mirroring on the VDS.
B.LLDP on the VDS.
C.NetFlow on the VDS.
D.Traffic shaping on the VDS.
AnswerA

Port mirroring on a vSphere Distributed Switch copies frames from a source VM's dvPort to a destination dvPort or uplink, satisfying the requirement to capture one specific virtual machine's traffic without disrupting its connectivity. Standard vSwitches lack this capability, so the VDS is required.

Why this answer

Port mirroring on a vSphere Distributed Switch (VDS) copies traffic from a source VM's vNIC (or uplink) to a destination port where a packet analyzer is attached. It is the purpose-built feature for capturing VM traffic for troubleshooting, supporting both ingress/egress directions and multiple session types.

Exam trap

VCP-DCV often tests the distinction between monitoring features — port mirroring (packet capture), NetFlow (flow metadata), and LLDP (topology discovery) — baiting candidates who conflate them.

How to eliminate wrong answers

Option B is wrong because LLDP is a link-layer discovery protocol used to advertise switch identity and topology, not to capture traffic. Option C is wrong because NetFlow exports flow metadata (IPs, ports, byte counts) for traffic analysis, not full packet captures. Option D is wrong because traffic shaping controls bandwidth allocation and burst limits, not packet duplication for analysis.

30
MCQhard

A vSphere administrator notices that VMs on a specific ESXi host lose connectivity intermittently. The VMs are on a distributed switch port group. The administrator finds that the Uplink 1 on that host is down. What should the administrator do first?

A.Increase the number of uplinks in the teaming policy
B.Check the physical switch port configuration for the failed uplink
C.Set the load balancing policy to Route based on source MAC
D.Configure a different failover order
AnswerB

A down uplink usually stems from the physical layer, so verify the connected switch port's configuration, VLAN trunking and status before touching vSphere settings. This identifies whether the fault lies with the physical switch or cabling.

Why this answer

When an uplink is down on a host attached to a distributed switch, the first step is to verify the physical layer — the physical switch port, cable, and SFP — because the most common cause is a physical link failure or misconfiguration on the upstream switch. Only after confirming the physical layer should you adjust vSphere teaming or failover settings.

Exam trap

VCP-DCV often tests whether candidates jump to vSphere-level remediation (teaming, failover order) instead of first checking the physical network layer, which is the actual root cause in most uplink-down scenarios.

How to eliminate wrong answers

Option A is wrong because adding uplinks to the teaming policy does not fix a down physical link and is not a first troubleshooting step. Option C is wrong because changing the load balancing policy does not restore a failed uplink and may mask the real issue. Option D is wrong because reconfiguring failover order is a workaround, not a diagnosis, and should come after confirming why Uplink 1 is down.

31
MCQeasy

A vSphere administrator needs to ensure that a specific virtual machine's network traffic is isolated from all other virtual machines on the same ESXi host, even if they are on the same VLAN. Which vSphere networking feature should the administrator use?

A.Private VLANs (PVLANs) on a vSphere Distributed Switch
B.Network I/O Control (NIOC) on a vSphere Distributed Switch
C.VLAN tagging on the virtual machine's vNIC
D.Traffic shaping on a standard switch port group
AnswerA

Private VLANs allow isolation of virtual machines at layer 2 by using secondary VLANs. A PVLAN can isolate ports so that VMs cannot communicate with each other even if they are on the same primary VLAN. This provides the required isolation without changing the VLAN of the VMs.

Why this answer

Private VLANs (PVLANs) on a vSphere Distributed Switch enable isolation of virtual machines at layer 2 by using secondary VLANs. This allows VMs on the same primary VLAN to be isolated from each other, which is not possible with standard VLAN tagging alone. NIOC, traffic shaping, and VLAN tagging do not provide this level of isolation.

Exam trap

The trap here is thinking that VLAN tagging alone can isolate VMs; VMs on the same VLAN can still communicate unless PVLANs are used.

32
MCQmedium

Refer to the exhibit. A virtual machine on the VM Network is experiencing intermittent connectivity. The administrator notices that vmnic0 is saturated. Which action would improve performance without causing a single point of failure?

A.Change the active uplinks for VM Network to vmnic1 only.
B.Increase the MTU on vSwitch0 to 9000.
C.Configure load-based teaming on vSwitch0 for the VM Network portgroup.
D.Move the VM Network to vSwitch1.
AnswerC

Load-based teaming distributes traffic across physical uplinks according to current load, relieving the saturated vmnic0 while retaining multiple adapters so no single NIC becomes a point of failure. Route-based policies would not balance the existing flows causing saturation.

Why this answer

Load-based teaming (LBT) on vSwitch0 dynamically balances VM traffic across all active uplinks based on real-time utilization, so vmnic0's load is shared with vmnic1, relieving saturation. It also maintains redundancy because both uplinks remain active; if one fails, the other takes over. This directly addresses the intermittent connectivity caused by vmnic0 saturation without introducing a single point of failure.

Exam trap

VCP-DCV often tests the misconception that simply changing the active uplink or increasing MTU will solve saturation, when the real solution requires dynamic load balancing across multiple uplinks without sacrificing redundancy.

How to eliminate wrong answers

Option A is wrong because setting vmnic1 as the only active uplink for VM Network removes vmnic0 from the team, creating a single point of failure and leaving vmnic0's saturation unaddressed for other traffic. Option B is wrong because increasing MTU to 9000 does not reduce congestion on a saturated uplink; it only reduces per-packet overhead, which is negligible for typical VM traffic and may cause fragmentation if the physical network doesn't support jumbo frames. Option D is wrong because moving the VM Network to vSwitch1 does not guarantee that vSwitch1 has additional uplinks or that the traffic will be balanced; it could simply shift the problem or create a new single point of failure if vSwitch1 has only one uplink.

33
MCQmedium

The administrator configured this LAG on a distributed switch and corresponding LACP settings on the physical switch. But the LAG is not coming up. What is a likely issue?

A.The load balancing policy should be IP hash.
B.The LAG name is not used by the physical switch.
C.The LAG mode is passive, but the physical switch is also configured as passive.
D.The uplinks should be in active/active mode.
AnswerC

LACP requires at least one side to initiate negotiation by sending LACPDUs. With both the distributed switch LAG and the physical switch set to passive, neither transmits, so no aggregation forms. Configuring the vSphere side as active satisfies the requirement that one endpoint actively initiates the LAG.

Why this answer

When both the vSphere distributed switch LAG and the physical switch are configured in passive mode, LACP negotiation fails because neither side initiates the negotiation. One side must be set to active for LACP to establish. Option A is incorrect because the load balancing policy (e.g., IP hash) is separate from LACP mode; it controls traffic distribution, not LACP negotiation.

Option B is incorrect because the LAG name is not used by LACP; LACP uses system identifiers and port keys, so a name mismatch does not prevent the LAG from coming up. Option D is incorrect because active/active mode refers to the uplink teaming policy, not the LACP mode setting.

34
MCQeasy

An administrator has created a standard vSwitch port group with VLAN ID 100. Virtual machines in this port group can communicate with each other but not with devices on the physical network. What is a possible cause?

A.The vSwitch has only one uplink.
B.The virtual machines have duplicate MAC addresses.
C.The physical switch port is not configured to pass VLAN 100.
D.The virtual machines are using different subnets.
AnswerC

A standard vSwitch port group tags egress frames with VLAN 100, but if the physical switch port is left as an access port on a different VLAN, or lacks VLAN 100 in its allowed list, tagged frames are dropped. This breaks the uplink path to physical devices while intra-host traffic still flows.

Why this answer

When a standard vSwitch port group is assigned VLAN ID 100, the ESXi host tags outbound frames with VLAN 100 (802.1Q). For those frames to reach the physical network, the physical switch port that the uplink connects to must be configured as a trunk that permits VLAN 100. If the physical switch port is an access port on a different VLAN or does not allow VLAN 100, traffic stays isolated within the virtual switch, which is exactly the symptom described.

Exam trap

VCP-DCV often tests whether candidates assume the problem is inside vSphere (uplinks, MACs, subnets) when the actual cause is the physical switch port not trunking the required VLAN — a classic 'look outside the hypervisor' trap.

How to eliminate wrong answers

Option A is wrong because having only one uplink does not prevent external communication — a single uplink can still carry VLAN 100 traffic if the physical switch port is configured correctly. Option B is wrong because duplicate MAC addresses would cause intermittent connectivity or MAC flapping, not a clean isolation where VMs talk to each other but never reach the physical network. Option D is wrong because different subnets would prevent VM-to-VM communication too (absent routing), but the scenario states VMs can communicate with each other, so subnetting is not the cause.

35
MCQeasy

A company has a single ESXi host with a standard switch. The administrator creates a new port group for a DMZ network and assigns a VM to it. The VM cannot ping the default gateway. The physical switch port is configured as a trunk with VLAN 100 allowed. The port group VLAN ID is set to 100. The physical NIC is connected to the switch port and shows link up. What should the administrator do to resolve the issue?

A.Enable VLAN tagging on the physical switch port
B.Change the VLAN ID to 0
C.Verify the VM's IP configuration
D.Add a second physical NIC to the standard switch
AnswerC

With the trunk allowing VLAN 100 and the port group tagged 100, the virtual switching path is already correct, so the fault lies inside the guest. Checking the VM's IP configuration verifies its address, subnet mask and default gateway before further changes.

Why this answer

The physical switch port is already configured as a trunk allowing VLAN 100, and the port group VLAN ID is correctly set to 100, so the virtual networking layer is properly tagged. The most likely remaining cause is that the VM itself has an incorrect IP address, subnet mask, or default gateway setting for the DMZ subnet. Verifying the guest OS IP configuration is the correct next troubleshooting step.

Exam trap

VCP-DCV often tests whether candidates jump to switch or vSwitch configuration changes when the real fault is inside the guest OS — always verify the VM's IP settings before altering network infrastructure.

How to eliminate wrong answers

Option A is wrong because the physical switch port is already configured as a trunk with VLAN 100 allowed, so enabling VLAN tagging again is redundant and not the issue. Option B is wrong because setting the port group VLAN ID to 0 would place the VM on the native/untagged VLAN, which would break DMZ connectivity rather than fix it. Option D is wrong because adding a second physical NIC does not address a guest-level IP misconfiguration and is unnecessary for a single-VM connectivity problem.

36
MCQeasy

A network administrator needs to isolate traffic between VMs in the same VLAN on a distributed switch. Which feature should be used?

A.Network I/O Control
B.Private VLAN
C.VLAN trunking
D.Traffic shaping
E.Port binding
AnswerB

Private VLANs subdivide a single VLAN into isolated secondary VLANs, preventing VM-to-VM traffic on the same segment while permitting promiscuous uplinks. This delivers the required Layer 2 isolation on a distributed switch, which port groups alone cannot enforce between members of one VLAN.

Why this answer

Private VLANs (PVLANs) on a vSphere Distributed Switch allow Layer 2 isolation between VMs in the same VLAN by using primary and secondary VLANs with promiscuous, isolated, and community port types. This is the specific feature designed to prevent VM-to-VM traffic within a single VLAN while still allowing communication with a gateway or designated promiscuous ports. It directly addresses the requirement to isolate same-VLAN VM traffic.

Exam trap

VCP-DCV often tests the confusion between bandwidth features (NIOC, traffic shaping) and isolation features (PVLAN), catching candidates who pick a QoS option for a segmentation requirement.

How to eliminate wrong answers

Option A is wrong because Network I/O Control manages bandwidth allocation and shares, not L2 traffic isolation between VMs. Option C is wrong because VLAN trunking carries multiple VLANs over one uplink; it does not isolate traffic within a single VLAN. Option D is wrong because traffic shaping controls average bandwidth, peak bandwidth, and burst size — it has no isolation function.

Option E is wrong because port binding determines how a VM's vNIC is assigned to a dvPort (static, dynamic, ephemeral), not whether VMs can communicate with each other.

37
MCQmedium

Refer to the exhibit. An administrator cannot resolve the hostname of a DNS server using the ESXi host. What is the most likely cause?

A.The search domain is incorrectly set to localdomain.
B.The DNS servers are unreachable.
C.The DNS servers are not configured correctly for the domain.
D.The ESXi host is not configured to use DNS.
AnswerC

The hostname resolution failed, indicating the DNS server cannot resolve the name.

38
Drag & Dropmedium

Order the steps to perform a vMotion migration of a powered-on virtual machine.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Prerequisites check, initiate migration, select type, choose destination, and confirm.

39
MCQhard

A vSphere administrator is configuring Network I/O Control (NIOC) on a vSphere Distributed Switch. The administrator creates a new network resource pool named 'High Priority' and assigns it a shares value of 'High'. The administrator then assigns a VM's vNIC to a port group that uses this resource pool. However, the VM's traffic is not receiving the expected prioritization during congestion. What is a possible reason for this?

A.The VM's vNIC is not configured with a reservation.
B.The physical switch is not configured to trust CoS/DSCP tags.
C.The port group is not assigned to a VLAN.
D.NIOC is not enabled on the vSphere Distributed Switch.
AnswerD

NIOC must be enabled on the vSphere Distributed Switch for network resource pools and shares to take effect. If NIOC is disabled, all traffic is treated equally, and no prioritization occurs regardless of the shares configured. The administrator must enable NIOC on the switch before resource pools can be used to prioritize traffic.

Why this answer

NIOC must be enabled on the vSphere Distributed Switch for network resource pools and shares to function. If NIOC is disabled, the shares values are ignored, and all traffic is treated equally. The other options are either unrelated to NIOC (VLAN, physical switch QoS) or misconceptions (reservations are not required for shares).

Therefore, the administrator should verify that NIOC is enabled on the switch.

Exam trap

The trap here is assuming that configuring shares alone is sufficient, but NIOC must be explicitly enabled on the distributed switch for those shares to be enforced.

40
MCQeasy

An administrator is creating a new vSphere Standard Switch on an ESXi host. The host has two physical NICs: vmnic0 and vmnic1. The administrator wants to use vmnic0 for VM traffic and vmnic1 for management traffic. How should the administrator configure the switch?

A.Create one standard switch with vmnic0 only and use VLANs for separation.
B.Create one standard switch with both vmnics and separate port groups for VM and VMkernel.
C.Create two standard switches: one with vmnic0 and a VM port group, and another with vmnic1 and a VMkernel port group.
D.Create a vSphere Distributed Switch with both vmnics.
AnswerC

Separating vmnic0 and vmnic1 onto distinct standard switches gives each traffic type a dedicated uplink, satisfying the requirement that VM traffic and management traffic never share a physical NIC. The VM port group binds to vmnic0, while the VMkernel port group on the second switch carries management traffic over vmnic1.

Why this answer

The requirement is to use separate physical NICs for different traffic types (VM traffic on vmnic0 and management traffic on vmnic1). In vSphere, a standard switch is a per-host virtual switch that connects virtual machines and VMkernel interfaces to physical NICs. To isolate traffic at the physical NIC level, you must create two distinct standard switches: one with vmnic0 and a VM port group for VM traffic, and another with vmnic1 and a VMkernel port group for management traffic.

This ensures that management traffic never traverses vmnic0 and VM traffic never traverses vmnic1, providing physical separation and avoiding contention.

Exam trap

The trap here is that candidates often assume a single standard switch with multiple uplinks and separate port groups is sufficient for traffic separation, but they overlook that physical NIC assignment is per-switch, not per-port-group, so both traffic types could still share the same NICs via teaming or failover unless explicit NIC binding is configured.

How to eliminate wrong answers

Option A is wrong because creating a single standard switch with only vmnic0 and using VLANs for separation does not physically separate management traffic onto vmnic1; management traffic would still be forced through vmnic0, violating the requirement. Option B is wrong because creating one standard switch with both vmnics and separate port groups for VM and VMkernel traffic would allow both traffic types to use either NIC (via teaming or failover), failing to enforce the dedicated NIC assignment. Option D is wrong because a vSphere Distributed Switch (VDS) requires vCenter Server and is not created directly on an ESXi host; it also does not inherently force specific traffic types to dedicated physical NICs without explicit configuration, and the question specifies a standard switch.

41
Drag & Dropmedium

Order the steps to enable vSphere HA on a cluster.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for enabling vSphere HA ensures that all prerequisites are met, starting with cluster selection, then accessing the HA configuration page, toggling the enable option, customizing settings, and applying changes. Common mistakes include attempting to configure options before enabling HA or accessing settings before selecting the cluster.

42
MCQeasy

An administrator needs to separate vMotion traffic from management traffic. Which should be created?

A.A new physical NIC.
B.A new VMkernel adapter on a different subnet.
C.A new VLAN on the existing port group.
D.A new standard switch port group.
AnswerB

A separate VMkernel adapter placed on a distinct subnet isolates vMotion traffic from management at layer 3, giving each its own IP stack and routing. This satisfies the requirement to fully separate the two traffic types.

Why this answer

Separating vMotion traffic from management traffic requires a dedicated VMkernel adapter, because VMkernel adapters carry vMotion, management, and other system traffic. Placing it on a different subnet ensures traffic isolation at Layer 3 and prevents vMotion from competing with management on the same network.

Exam trap

VCP-DCV often tests whether candidates confuse Layer 2 constructs (port groups, VLANs) with the Layer 3 VMkernel adapter that is actually required to carry vMotion traffic.

How to eliminate wrong answers

Option A is wrong because adding a physical NIC alone does not create a VMkernel interface; vMotion traffic still needs a VMkernel adapter to be enabled. Option C is wrong because a VLAN on an existing port group does not by itself create a separate VMkernel interface for vMotion. Option D is wrong because a standard switch port group is a Layer 2 construct; without a VMkernel adapter enabled for vMotion, traffic cannot be separated.

43
MCQmedium

A vSphere administrator is troubleshooting a virtual machine that cannot communicate on the network. The VM is connected to a port group on a vSphere Standard Switch. The administrator verifies that the physical switch port is configured as an access port for VLAN 10, and the port group VLAN ID is set to 10. The VM's guest OS has a static IP address in the correct subnet. Which step should the administrator take next to diagnose the issue?

A.Change the port group VLAN ID to 4095.
B.Check the virtual machine's network adapter settings to ensure it is connected and the correct port group is selected.
C.Verify that the physical switch port is configured as a trunk.
D.Restart the management agents on the ESXi host.
AnswerB

The most likely cause is that the VM's network adapter is disconnected or connected to the wrong port group. Verifying the adapter's connection status and port group assignment is a fundamental troubleshooting step. If the adapter is disconnected or on a different port group, the VM will not communicate. This should be checked before more complex diagnostics.

Why this answer

The physical switch and port group VLAN configurations are correct. The next logical step is to verify the VM's network adapter settings, as a disconnected adapter or wrong port group is a common cause. Checking the adapter is non-disruptive and directly addresses the VM's connectivity.

Other options involve changing correct configurations or taking unnecessary actions.

Exam trap

The trap here is overlooking the VM's adapter settings and instead assuming a mismatch between the physical switch and port group, even though they are already aligned.

44
Multi-Selectmedium

Which TWO of the following are functions of a vSphere Distributed Switch that are not available in a vSphere Standard Switch? (Select exactly two.)

Select 2 answers
A.Port mirroring (Distributed Port Mirroring).
B.NIC teaming with explicit failover order.
C.Network I/O Control (NIOC).
D.Traffic shaping policies.
E.VLAN tagging and trunking.
AnswersA, C

Distributed Port Mirroring requires a centralised control plane to replicate traffic across multiple hosts, which the vSphere Standard Switch lacks entirely. It satisfies the stem's constraint of a Distributed Switch-only function, since standard switches offer no equivalent monitoring capability at that scale.

Why this answer

Option A (Port mirroring / Distributed Port Mirroring) is correct because the vSphere Distributed Switch provides a centralized, dvSwitch-wide port mirroring feature configured at the distributed switch or distributed port group level, whereas a vSphere Standard Switch has no native port mirroring capability and requires third-party tools or workarounds. Option C (Network I/O Control / NIOC) is correct because NIOC, which uses shares, reservations, and limits to prioritize and manage bandwidth across traffic types (e.g., vMotion, iSCSI, NFS, VM traffic) on a per-dvSwitch basis, is a Distributed Switch-only feature and is not available on a Standard Switch. Option B (NIC teaming with explicit failover order) is not correct because Standard Switches also support NIC teaming with configurable failover order, so it is not exclusive to the Distributed Switch.

Option D (Traffic shaping policies) is not correct because both Standard and Distributed Switches support traffic shaping, though the Distributed Switch offers more granular per-port-group control. Option E (VLAN tagging and trunking) is not correct because VLAN tagging (VST, EST, VGT) and trunking are supported on both Standard and Distributed Switches.

45
MCQhard

A vSphere administrator is configuring Network I/O Control (NIOC) on a vSphere Distributed Switch. The environment has multiple traffic types: vMotion, iSCSI, and virtual machine traffic. The administrator wants to ensure that during periods of congestion, vMotion traffic does not starve iSCSI traffic, but vMotion should be able to use more bandwidth than iSCSI when available. Which NIOC configuration should the administrator apply?

A.Assign vMotion a higher limit than iSCSI.
B.Assign vMotion a higher shares value than iSCSI.
C.Assign vMotion a higher reservation than iSCSI.
D.Assign iSCSI a higher shares value than vMotion.
AnswerB

NIOC uses shares to allocate bandwidth during congestion. Shares define relative priority: a higher shares value gives vMotion more bandwidth than iSCSI when contention occurs. This meets the requirement that vMotion does not starve iSCSI (since iSCSI still gets its proportional share) and can use more bandwidth when available. Setting shares appropriately balances the two traffic types.

Why this answer

NIOC shares determine relative bandwidth allocation during congestion. Giving vMotion more shares than iSCSI ensures vMotion gets more bandwidth when needed, but iSCSI still receives its proportional share, preventing starvation. Limits and reservations do not provide the same relative prioritization.

Therefore, adjusting shares is the correct approach.

Exam trap

The trap here is confusing shares with limits or reservations, thinking that a higher limit or reservation automatically provides priority during congestion, when shares are the mechanism for relative priority.

46
Matchingmedium

Match each vSphere feature to its correct description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Distributes VM workloads across hosts based on resource usage

Provides continuous availability by maintaining a secondary VM

Migrates VM storage without downtime

Powers hosts on/off to save energy based on demand

Standardizes host configuration across a cluster

Why these pairings

Key vSphere features: vMotion (live migration), HA (automatic restart), DRS (load balancing), FT (continuous availability via lockstep). Common confusions involve swapping the feature and its description.

Ready to test yourself?

Try a timed practice session using only Configure and Manage vSphere Networking questions.