Curriculum by exam
Every objective of the 14 exam blueprints the Academy covers, mapped to the topic, lab and quiz material that addresses it. Objective numbers are the Academy's own index of each blueprint (section.objective, both 1-based, in the order of content/exam-metadata.json) — not Broadcom's official numbering. Coverage is derived from the quiz banks' objective mapping and their study links; an objective with no mapped question is shown honestly as a gap.
Objective ids are the Academy index (section.objective) used by the quiz banks and the weak-area heatmap, not the official blueprint numbering. Always check the official exam guide. Coverage rule: covered = at least one quiz question and at least one topic or lab link; partial = quiz questions but no resolvable link, or links but fewer than 2 questions; gap = no mapped quiz question.
2V0-17.25 — VMware Cloud Foundation 9.0 Administrator
Section 1 — VCF Architecture and Components 12%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 1.1 | Differentiate between VCF Standard and Consolidated deployment architectures and identify minimum host requirements for each | VCF Cluster & Host RequirementsManagement & Workload Domain DesignCluster Sizing PatternsVCF Architecture Options & TopologyArchitecture Options Analysis | 2 | covered |
| 1.2 | Describe the VCF 9 hierarchy: Private Cloud → Fleet → Instance → Workload Domain and explain fleet-level vs. instance-level operations | VCF 9.0 Management HierarchyVCF 9.0 Taxonomy & New Constructs | 2 | covered |
| 1.3 | Identify VCF 9 Management Domain components: SDDC Manager, vCenter, NSX Manager cluster, vSAN datastore, VCF Operations, and VCF Automation | VCF 9.0 Management Domain ComponentsVCF Shutdown & Startup ProceduresNSX Management Plane ArchitectureVCF 5.2 to 9.0 Component ChangesManagement vs Workload Domain DesignVCF 5.2 Component Dependencies | 5 | covered |
| 1.4 | Explain the role of the VCF Installer (replaces Cloud Builder in VCF 9) for day-0 bring-up including the deployment JSON specification | VCF 5.2 to 9.0 Component ChangesVCF 9.0 Day-0/Day-1 Deployment FlowBring-up: 5.2 vs 9.0 Lab | 2 | covered |
| 1.5 | Describe SDDC Manager’s core capabilities: lifecycle management, workload domain orchestration, host commissioning, certificate management, password rotation, and network pool management | Bundles & Depot ConfigurationSDDC Manager Users, Roles & IdentityFleet Lifecycle Management | 2 | covered |
| 1.6 | Differentiate between the SDDC Manager UI (VCF 5.2) and the VCF Operations Console (VCF 9) as the primary administrative interface | VCF Management InterfacesUI Consolidation in VCF 9.0Fleet LCM, Certificates & Passwords | 2 | covered |
| 1.7 | Explain the VCF Operations Console’s dual role: Fleet Management (infrastructure operations) and Integrated Monitoring (observability) | Fleet Management & MonitoringFleet-Level Operations | 1 | partial |
| 1.8 | Compare VCF 9 vs. VCF 5.2 architecture changes including Cloud Builder deprecation, Aria Suite rebranding to VCF Operations/Automation, and SDDC Manager UI absorption | VCF 5.2 Bring-up SequenceVCF 9.0 Component RenamingVCF 5.2 Architecture & ComponentsManagement Plane OverviewKubernetes Services on VCFVMware Cloud Foundation Overview | 5 | covered |
| 1.9 | Identify VCF licensing models: subscription-only, VCF vs. VVF feature differences, and vSAN capacity entitlements (1 TiB/core for VCF) | VCF 9.0 Licensing & Subscription ModelLicense Management Lab | 3 | covered |
| 1.10 | Describe VI Workload Domain isolation: dedicated vCenter, NSX deployment options (shared vs. isolated), dedicated vSAN datastore, and independent lifecycle | — | 0 | gap |
| 1.11 | Explain the SDDC Manager REST API endpoints for automated VCF deployments, workload domain creation, upgrade management, and certificate rotation | VCF 5.2 Day-2 Operations | 1 | partial |
Section 2 — vSphere, vSAN, and NSX Administration 18%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 2.1 | Configure vSphere Distributed Switches (VDS) with uplinks, port groups, LACP, traffic shaping, Network I/O Control (NIOC), and NIC teaming policies | — | 0 | gap |
| 2.2 | Manage ESXi host lifecycle: commissioning in SDDC Manager, maintenance mode data migration options (Full, Ensure Accessibility, No Data Migration), and decommissioning | — | 0 | gap |
| 2.3 | Differentiate vSAN OSA (disk groups with cache/capacity tiers) from vSAN ESA (single NVMe storage pool, no disk groups) and identify hardware requirements for each | vSAN ESA vs OSA ArchitecturevSAN Storage DesignvSAN Acronyms & TerminologyvSAN Internals at ScalevSAN Storage Core Concepts | 3 | covered |
| 2.4 | Create and apply vSAN storage policies using SPBM: FTT values, RAID-1 mirroring vs. RAID-5/6 erasure coding, object space reservation, and compression settings | Lab: vSAN Erasure Coding DesignvSAN ESA Day-2 OperationsvSAN Storage DesignVCF Storage FundamentalsLab: vSAN Cluster with ESAvSAN Storage Core Concepts | 3 | covered |
| 2.5 | Configure vSAN fault domains for rack awareness, stretched clusters with witness appliance, and HCI Mesh for remote datastore mounting | — | 0 | gap |
| 2.6 | Explain vSAN ESA RAID-5 2+1 configuration requiring only 3 hosts vs. OSA RAID-5 requiring 4 hosts, and ESA pre-network compression benefits | Lab: vSAN Erasure Coding DesignvSAN ESA vs OSA Architecture | 1 | partial |
| 2.7 | Manage NSX segments, Tier-0 and Tier-1 Gateways, Edge Clusters, and transport zones within VCF workload domains | NSX Edge Cluster SizingNSX Architecture & Control PlaneVCF 5.2 to 9.0 Breaking ChangesEdge & Gateway Logical DesignT0/T1 Routing Topology LabEdge Dataplane Performance & DPDK | 5 | covered |
| 2.8 | Configure NSX VPCs (Virtual Private Clouds) with Projects and Transit Gateways for multi-tenant isolation in VCF 9 | NSX VPC & Advanced Features (9.0)Lab: VPC Construct in VCF 9.0VCF 9.0 Networking Changes | 4 | covered |
| 2.9 | Manage vSphere DRS automation levels, migration thresholds, VM-Host affinity/anti-affinity rules, DRS groups, and Proactive HA | VCF Cluster Configuration Defaultsesxtop CPU Performance MetricsPerformance Analysis with esxtopvSphere Cluster Administration | 3 | covered |
| 2.10 | Configure vSphere HA admission control policies, VM restart priorities, VM Component Protection (VMCP) for PDL/APD, and heartbeat datastores | VCF Cluster Configuration DefaultsESXi Storage Path TroubleshootingHA Design & Admission ControlHA Reservation Design Guidance | 3 | covered |
| 2.11 | Explain vSphere 9 changes: vCLS deprecated (replaced by embedded key-value store), Host Profiles deprecated (replaced by JSON-based vSphere Configuration Profiles), ELM deprecated, IWA removed | Identity Sources & AuthenticationIdentity & SSO ChangesVCF Identity Management & RBAC | 1 | partial |
| 2.12 | Manage vSAN encryption: data-at-rest (AES-256 with KMS), data-in-transit (TLS 1.2), OSA cluster-level vs. ESA object-level encryption | — | 0 | gap |
| 2.13 | Configure vSAN File Services (NFS v3/v4.1, SMB 3.0) and vSAN iSCSI Target Service for non-VM workloads | — | 0 | gap |
Section 3 — Planning and Design 10%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 3.1 | Evaluate organizational requirements for VCF adoption including hybrid cloud models, scalability targets, and resiliency requirements | NSX Multi-Site Federation DesignVCF Architecture & Topology OptionsNSX Federation Deep DiveLab: NSX Federation Across InstancesMulti-Site Design Patterns | 2 | covered |
| 3.2 | Design scalable VCF environments considering Management Domain sizing (minimum 4 hosts), VI Workload Domain placement, and network pool planning | VCF 9.0 Edge PatternsVCF 5.2 Configuration MaximumsReference Design BlueprintsVCF Architecture & Topology OptionsVCF 5.2 Architecture & Components | 5 | covered |
| 3.3 | Plan network architecture: management, vMotion, vSAN, NSX TEP VLANs, MTU requirements (9000 for vSAN/NSX, 1600 minimum for GENEVE overlay) | NSX Overlay ArchitectureVCF Network Design & VLANsOverlay Encapsulation & MTU LabPhysical Network Design DecisionsLab: Workload Domains & Network PoolsOverlay Segments & Tunnel Endpoints | 2 | covered |
| 3.4 | Plan vSAN storage capacity considering FTT overhead, slack space requirements (25-30% recommended), compression ratios, and growth projections | Lab: vSAN Erasure Coding DesignStorage Capacity Sizing MathvSAN Storage Core ConceptsLab: Multi-Domain Design & SizingVCF Storage FundamentalsPhysical Storage Design Decisions | 3 | covered |
| 3.5 | Design identity management strategy: vCenter SSO domain topology, Active Directory LDAP integration, Identity Federation (ADFS, Okta, Entra ID) for VCF 9, and VCF Identity Broker | VCF 5.2 Identity FederationIdentity Broker Deployment OptionsIdentity & Federation ManagementLab: Identity Broker Integration | 3 | covered |
| 3.6 | Plan EVC mode for clusters with mixed CPU generations and understand impact on VM migration compatibility | — | 0 | gap |
| 3.7 | Design content library strategy: published and subscribed libraries for golden image distribution across workload domain vCenters | — | 0 | gap |
| 3.8 | Plan backup strategy for SDDC Manager database, NSX Manager database, and vCenter configuration using SFTP-based backups | VCF 5.2 Backup & Restore DefaultsLab: VCF Backup & RestoreMulti-Instance Fleet Operations | 5 | covered |
| 3.9 | Evaluate trade-offs between cost, performance, and resiliency when choosing OSA vs. ESA, RAID-1 vs. RAID-5/6, and standard vs. consolidated architecture | — | 0 | gap |
| 3.10 | Plan vSphere Kubernetes Service (VKS) prerequisites: NSX configuration, Avi Load Balancer deployment, Content Library for node OVA templates, and storage policies | Avi Controller Cluster & HASupervisor ArchitectureVKS Architecture & ComponentsAvi Architecture & DeploymentSupervisor Services & VKSLab: Deploy Avi Controller HA Cluster | 3 | covered |
Section 4 — Deploy, Configure, and Operate VCF 36%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 4.1 | Perform VCF 9 day-0 bring-up using VCF Installer: prepare the deployment JSON specification with host networking, DNS, NTP, and credential configuration | — | 0 | gap |
| 4.2 | Commission and decommission ESXi hosts in SDDC Manager: validate DNS forward/reverse records, NTP sync, SSH reachability, and hardware compatibility | Host Commissioning Lifecycle LabVCF Compute & Host CommissioningWorkload Domains & Network Pools | 1 | partial |
| 4.3 | Deploy VI Workload Domains using SDDC Manager: create network pools, select NSX deployment option, configure vSAN architecture, and monitor deployment workflow | — | 0 | gap |
| 4.4 | Add and remove clusters from existing workload domains and scale clusters by adding or removing ESXi hosts | — | 0 | gap |
| 4.5 | Perform LCM upgrades in the correct dependency order: SDDC Manager → Aria Suite Lifecycle → NSX → vCenter → ESXi/vSAN (VCF 5.2 management-domain order; Aria Suite Lifecycle is upgraded manually), and use pre-check validations before initiating upgrades | VCF 5.2 LCM PrechecksVCF 5.x to 9.0 Upgrade SequencevCenter Patching & Upgrade ModesAria to VCF 9.0 Component RenamingVCF Upgrade Phases & ComponentsFleet Lifecycle Management | 16 | covered |
| 4.6 | Manage certificates using SDDC Manager: connect to Microsoft CA or OpenSSL, generate CSRs, replace certificates for vCenter, NSX Manager, and SDDC Manager, and configure auto-renewal in VCF 9 | Certificate Management & CA IntegrationCertificates & Password ManagementCertificate Lifecycle OperationsCertificate Rotation Lab | 3 | covered |
| 4.7 | Configure password management: rotate passwords for vCenter, NSX, ESXi root, and SDDC Manager service accounts using the encrypted credential vault | VCF 5.2 Password OperationsCertificates & Password ManagementIdentity & Password ManagementLab: Password & Secrets Management | 3 | covered |
| 4.8 | Configure VCF Operations for monitoring: deploy dashboards, configure alerts, integrate VCF Operations for Logs, and set up VCF Operations for Networks | Multi-Site & Witness Design PatternsVCF Operations KPIs & ReportingVCF 9.0 Deployment ModelsVCF Operations Cluster Architecture | 3 | covered |
| 4.9 | Configure VCF Automation for self-service: deploy catalog items, configure cloud accounts, create blueprints/templates, and manage tenant projects | VCF 9.0 Deployment ModelsVCF Automation Organization TypesVCF Automation FundamentalsAutomation Multi-Tenancy ArchitectureConsumption & Tenant DesignService Broker Catalog Design | 5 | covered |
| 4.10 | Manage vLCM Images for cluster patching: define cluster images with ESXi base image, vendor add-ons, firmware add-ons, and Hardware Support Manager integration | vSphere Lifecycle Manager ModelsvLCM Baselines to Images TransitionVCF Host Lifecycle BasicsvLCM Cluster Image LabvLCM Cluster Image Management | 2 | covered |
| 4.11 | Configure VM storage policies and validate policy compliance using vSAN health checks and SDDC Manager dashboards | — | 0 | gap |
| 4.12 | Perform brownfield import of existing vSphere environments as VCF workload domains using SDDC Manager API | Brownfield vSphere-to-VCF AdoptionVCF 5.x to 9.0 Upgrade & ConversionVCF Upgrade & vSphere ConversionLab: Converting vSphere to VCF | 2 | covered |
| 4.13 | Configure vSphere resource pools with shares, reservations, and limits for workload prioritization within clusters | — | 0 | gap |
| 4.14 | Manage vMotion, Storage vMotion, and Cross-vCenter vMotion operations including encrypted vMotion configuration | — | 0 | gap |
| 4.15 | Configure NSX Distributed Firewall rules and Gateway Firewall policies for workload security within VCF | Distributed Firewall Deep DiveDFW Rule Engine InternalsDFW Realization & Enforcement LabDFW Security Policy Lab | 2 | covered |
Section 5 — Troubleshooting 24%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 5.1 | Troubleshoot VCF Installer (day-0) bring-up failures: DNS resolution errors, NTP drift, network connectivity issues, and JSON specification validation errors | — | 0 | gap |
| 5.2 | Troubleshoot SDDC Manager host commissioning failures: SSH connectivity, DNS forward/reverse lookup mismatches, hardware compatibility list (HCL) violations, and NTP synchronization | — | 0 | gap |
| 5.3 | Troubleshoot workload domain deployment failures: vCenter OVA deployment errors, vSAN datastore creation failures, NSX host preparation failures, and mid-workflow retry procedures | VCF Log Locations & DiagnosticsVCF Lifecycle TroubleshootingDeployment Failure Troubleshooting Lab | 1 | partial |
| 5.4 | Troubleshoot LCM upgrade failures: pre-check validation errors, version compatibility issues, upgrade sequence violations, and rollback procedures | LCM Bundle & Upgrade FailuresBundle Management & AvailabilityUpgrade Troubleshooting Scenario | 1 | partial |
| 5.5 | Troubleshoot vSAN health issues: disk balance warnings, component limit alerts, resync operations, degraded objects, and vSAN HCL database updates | esxtop Storage Latency MetricsAdvanced esxtop Performance Analysis | 2 | covered |
| 5.6 | Troubleshoot NSX connectivity issues: TEP communication failures, overlay segment reachability, BGP/OSPF neighbor establishment, and Edge cluster failover | NSX Troubleshooting ToolsTraceflow & IPFIX Lab | 1 | partial |
| 5.7 | Troubleshoot certificate management failures: CA connectivity issues, expired certificates, CSR generation errors, and certificate chain validation | SDDC Manager Component ConnectivityVCF Lifecycle Troubleshooting Scenarios | 1 | partial |
| 5.8 | Troubleshoot password rotation failures: credential vault synchronization issues, service account lockouts, and dependent component password mismatches | — | 0 | gap |
| 5.9 | Use VCF Operations for Logs to aggregate and analyze log data: create custom dashboards, configure alerts, and generate SOS diagnostic bundles | SoS Utility Deep DiveVCF Operations Adapter TroubleshootingSoS, Log Bundles & API DiagnosticsSoS Diagnostics LabVCF Operations & Logs TroubleshootingVCF Log File Locations | 4 | covered |
| 5.10 | Troubleshoot vSphere HA split-brain scenarios: management network partitions, datastore heartbeat failures, and admission control violations | — | 0 | gap |
| 5.11 | Troubleshoot VDS networking issues: uplink failures, port group misconfiguration, MTU mismatches, LACP negotiation failures, and NIOC contention | — | 0 | gap |
| 5.12 | Identify log file locations for key VCF components: SDDC Manager (/var/log/vmware/vcf/), vCenter (/var/log/vmware/), NSX Manager (/var/log/), and ESXi (/var/log/) | ESXi Log File LocationsCollect Support Bundle & Analyze Logs | 1 | partial |
| 5.13 | Troubleshoot vMotion failures: CPU incompatibility (EVC mode mismatch), network bandwidth saturation, encrypted vMotion AES-NI requirements, and storage accessibility | — | 0 | gap |
2V0-13.25 — VMware Cloud Foundation 9.0 Architect
Section 1 — Architecture Design Methodology 15%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 1.1 | Differentiate between business requirements (what the organization needs to achieve) and technical requirements (how technology will meet those needs) | — | 0 | gap |
| 1.2 | Differentiate between a Conceptual Model (high-level business-aligned view), Logical Design (technology-specific but hardware-independent), and Physical Design (specific products, versions, quantities, and configurations) | Conceptual, Logical & Physical LayersLogical Design DecisionsPhysical Design Decisions | 2 | covered |
| 1.3 | Differentiate between requirements (mandatory conditions), assumptions (believed-true statements), constraints (limitations on the design), and risks (potential negative outcomes) | RCAR: Requirements & ConstraintsRCAR Framework MasteryBusiness Requirements AnalysisRCAR Documentation Practice | 2 | covered |
| 1.4 | Apply the AMPRS framework: Availability (uptime SLAs), Manageability (operational complexity), Performance (throughput, latency, IOPS), Recoverability (RPO/RTO), Security (compliance, access control) | AMPRS Design QualitiesRecoverability Design (RPO/RTO)Availability Design & SLAs | 2 | covered |
| 1.5 | Develop and document a risk mitigation strategy that maps identified risks to specific design decisions and countermeasures | Risk Handling & DocumentationRisk Register Practices | 1 | partial |
| 1.6 | Document design decisions with established relationships to requirements, including justification, implications (positive and negative), and alternatives considered | Design Decision Record TemplateVCF Design Methodology Objectives | 1 | partial |
| 1.7 | Develop a design validation strategy that verifies the implemented solution meets all documented requirements through testing and acceptance criteria | Design Validation & TraceabilityValidation Strategy in RCAR | 1 | partial |
| 1.8 | Evaluate trade-offs between conflicting AMPRS qualities (e.g., maximum availability vs. cost constraint, security isolation vs. manageability simplicity) | AMPRS Trade-off AnalysisCluster Design Patterns | 1 | partial |
| 1.9 | Create design documentation artifacts: requirements matrices, design decision logs, risk registers, and validation checklists | — | 0 | gap |
| 1.10 | Apply industry-standard design methodologies to VCF solution architecture including TOGAF principles, capacity planning frameworks, and ITIL-aligned operational design | — | 0 | gap |
Section 2 — VCF Infrastructure and Fleet Design 20%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 2.1 | Differentiate between VCF architecture options: Standard (separate management and workload hosts) vs. Consolidated (shared hosts) and identify use cases for each | VCF 5.2 Architecture ModelsWorkload Domain Boundary StrategyVCF 5.2 Architecture & ComponentsLogical Design DecisionsMulti-Workload Domain Design | 2 | covered |
| 2.2 | Design VCF Fleet topologies for single-site, multi-site, and multi-region deployments considering latency, bandwidth, and regulatory requirements | Multi-Site Topology ChoicesThe VCF Fleet ConceptVCF Architecture & Topology Options | 1 | partial |
| 2.3 | Design Management Domain sizing: host count (minimum 4 for FTT=1), vCenter sizing (Tiny/Small/Medium/Large/X-Large based on managed objects), NSX Manager cluster resources, and SDDC Manager requirements | VCF 5.2 Bring-up Cluster MinimumsCloud Builder ApplianceManagement Domain SizingOvercommit Design RemindersDomain Host Minimums | 7 | covered |
| 2.4 | Design VI Workload Domain placement strategy: number of domains, cluster sizing, NSX deployment model (shared vs. isolated), and vSAN architecture selection (OSA vs. ESA) | Management vs Workload DomainsShared vs Dedicated NSX Manager5.2 Appliance Sizing BlueprintsMulti-Workload Domain Design | 2 | covered |
| 2.5 | Design decisions for VCF Fleet topology — Logical Design: fleet boundaries, instance grouping by geography or business unit, VCF Operations placement for fleet-wide monitoring | The VCF Fleet ConceptVCF 9.0 Fleet Lifecycle ManagementMulti-Instance Fleet Operations | 1 | partial |
| 2.6 | Design decisions for VCF Fleet topology — Physical Design: specific hardware models, rack layouts, power distribution, network cabling, and ToR switch configurations | — | 0 | gap |
| 2.7 | Design decisions for VCF Management Domain — Logical Design: SSO domain topology, identity source integration, management network segmentation, and backup strategy | — | 0 | gap |
| 2.8 | Design decisions for VCF Management Domain — Physical Design: server specifications, NIC configuration, storage device selection, and firmware versions aligned to VCF BOM | Logical vs Physical DecisionsPhysical Design Decisions | 1 | partial |
| 2.9 | Design decisions for VCF Workload Domain — Logical Design: cluster boundaries, resource pool hierarchy, content library strategy, and VM storage policy framework | — | 0 | gap |
| 2.10 | Design decisions for VCF Workload Domain — Physical Design: host hardware specifications, drive count and type for vSAN, network adapter speeds, and GPU/DPU requirements for specialized workloads | — | 0 | gap |
| 2.11 | Design for Scalability: horizontal scaling (adding hosts/clusters/domains), vertical scaling considerations, and maximum configuration limits | VCF 5.2 Configuration MaximumsScalability & Cluster Sizing LimitsWorkload Domain Scale in 5.2Cluster Design Patterns | 3 | covered |
| 2.12 | Design for Capacity Management: proactive capacity planning using VCF Operations forecasting, buffer capacity allocation, and capacity reclamation strategies | — | 0 | gap |
Section 3 — Network and Storage Design 30%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 3.1 | Design network infrastructure — Logical Design: VLAN segmentation (management, vMotion, vSAN, NSX TEP, VM network), MTU strategy (9000 for storage/overlay, 1600+ minimum for GENEVE), and IP addressing plan | VCF 5.2 Network Requirements & MTUVCF 5.2 Design Requirement IDsTEP & MTU ValidationNSX Architecture Deep Dive | 2 | covered |
| 3.2 | Design network infrastructure — Physical Design: ToR switch selection, uplink speeds (25/100 GbE), LAG/LACP configuration, spine-leaf topology, and out-of-band management network | vDS Profile Choice at Bring-upHost NIC & Uplink RequirementsNetwork Design Fundamentals5.2 vDS Profile OptionsPhysical Network Design | 3 | covered |
| 3.3 | Design NSX networking — Logical Design: transport zone topology, segment design, Tier-0/Tier-1 gateway hierarchy, NSX VPC construct for multi-tenancy, and Edge cluster sizing | — | 0 | gap |
| 3.4 | Design NSX networking — Physical Design: Edge Node placement (VM vs. bare-metal), Edge cluster HA mode (active-active ECMP vs. active-standby), and BGP/OSPF peering with physical infrastructure | VCF 5.2 BGP RequirementsTier-0 Gateway Modes5.2 Network Design RequirementsBGP & ECMP RoutingT0/T1 Routing Topology LabNSX Edge Cluster Deployment Lab | 3 | covered |
| 3.5 | Design vSAN storage solutions: OSA vs. ESA selection criteria, drive count and type per host, fault domain configuration for rack awareness, stretched cluster topology for multi-site, and HCI Mesh for disaggregated storage | vSAN ESA vs OSAStretched Cluster RequirementsvSAN Transport & RDT5.2 Stretched Cluster Latency LimitsVCF Storage FundamentalsMulti-AZ Prerequisites | 6 | covered |
| 3.6 | Design storage policy framework: tiered policies (Gold/Silver/Bronze) mapping to FTT, FTM, compression, and encryption settings aligned with workload SLA requirements | — | 0 | gap |
| 3.7 | Design for vSAN capacity: calculate raw-to-usable ratios considering FTT overhead, slack space (25-30%), metadata overhead, and compression ratios | vSAN Capacity CalculationvSAN Storage Policies & OverheadMathematical Sizing WalkthroughvSAN Storage Design Practice | 2 | covered |
| 3.8 | Design supplemental storage integration: NFS v3/v4.1, iSCSI, Fibre Channel, and NVMe-oF as workload domain principal or supplemental storage | Principal vs Supplemental StorageVCF 5.2 Storage Options | 1 | partial |
| 3.9 | Design NSX multi-tenancy with Projects, VPCs, and Transit Gateways for tenant isolation while maintaining shared services access | NSX Projects & VPC Multi-TenancyVPC Construct Lab | 1 | partial |
| 3.10 | Design NSX security zones: Distributed Firewall micro-segmentation, Gateway Firewall perimeter security, and vDefend integration for advanced threat protection | — | 0 | gap |
Section 4 — Availability, Recoverability, and Security Design 15%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 4.1 | Design for availability within a single availability zone: vSphere HA (admission control, restart priorities), DRS (resource balancing, anti-affinity rules), and vSAN FTT policies | HA Admission Control PoliciesHA Admission Control ValidationCompute & Cluster Design | 1 | partial |
| 4.2 | Design for availability across availability zones: vSAN stretched clusters (dual data sites + witness), NSX multi-site design, and cross-site vMotion requirements | Witness Placement PatternsNSX Federation ArchitecturevSAN Stretched Cluster Storage DesignGlobal Manager & Local ManagersFault Domains & WitnessStretched Cluster Design Lab | 3 | covered |
| 4.3 | Differentiate between BCDR strategies for management components (SDDC Manager backup/restore, vCenter backup, NSX Manager backup) and workloads (VM-level backup, replication, snapshots) | VCF Backup StrategyManagement Domain RecoveryVCF Backup & Restore Lab | 1 | partial |
| 4.4 | Design for Business Continuity: RPO/RTO targets mapping to protection mechanisms, active-active vs. active-passive site configurations, and automated failover workflows | — | 0 | gap |
| 4.5 | Design for Disaster Recovery: VCF-native DR using vSAN snapshot replication, third-party backup integration, HCX for workload mobility, and site recovery orchestration | DR Tiers & Site RecoveryNSX Federation for Multi-SiteDisaster Recovery Design Lab | 1 | partial |
| 4.6 | Design decisions for securing VCF Management Components: certificate management strategy, password rotation policy, identity federation configuration, and administrative access controls | — | 0 | gap |
| 4.7 | Design decisions for securing VCF Workloads: NSX micro-segmentation, VM encryption (vSAN encryption, VM-level encryption), vTPM for guest OS security, and compliance scanning | — | 0 | gap |
| 4.8 | Design VCF Identity Broker strategy for centralized authentication across fleet using SAML 2.0/OIDC with external identity providers | Identity & SSO Logical DesignIdentity & Certificate ManagementIdentity Design Personas | 1 | partial |
| 4.9 | Design for compliance: map regulatory requirements (PCI-DSS, HIPAA, SOC 2) to VCF security controls including encryption, access logging, network segmentation, and audit trails | Compliance-Driven Security DesignDFW Micro-SegmentationZero-Trust Migration Playbook | 1 | partial |
| 4.10 | Design for zero-trust networking: never-trust-always-verify approach using NSX Distributed Firewall rules applied at the vNIC level with application-aware policies | Distributed Firewall Deep DiveZero-Trust Security ArchitectureZero-Trust DFW Design LabDFW Realization & Enforcement Lab | 2 | covered |
Section 5 — Operations, Automation, and Migration Design 20%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 5.1 | Design for Lifecycle Management: upgrade planning across fleet instances, maintenance windows, rolling upgrade strategy, and compatibility matrix validation | VCF Upgrade SequencingFleet Lifecycle ManagementUpgrade Path Planning | 1 | partial |
| 5.2 | Design VCF Automation tenant architecture: organization structure, project boundaries, cloud account configuration, and approval workflow policies | Automation Multi-Tenancy ModelVCF Automation ConstructsMulti-Tenant Project Lab | 1 | partial |
| 5.3 | Design for Self-Service and Governance: catalog item design, entitlement policies, resource quotas, lease management, and cost allocation/chargeback | — | 0 | gap |
| 5.4 | Design decisions for automating VCF infrastructure components: Infrastructure-as-Code templates, API-driven workflows, and CI/CD pipeline integration with SDDC Manager API | Infrastructure-as-Code with VCF AutomationManageability & Operations at ScaleConsumption Strategy DesignVCF Automation APIStandardization & Drift Control | 2 | covered |
| 5.5 | Design decisions for supporting Modern Applications: vSphere Kubernetes Service (VKS) Supervisor cluster design, namespace resource allocation, storage class mapping, and network policy design | VKS Architecture & ComponentsSupervisor Architecture Deep DiveModern Apps Design on VCF | 1 | partial |
| 5.6 | Design monitoring strategy for VCF management components: VCF Operations dashboard layout, alert severity framework, escalation procedures, and SLA reporting | — | 0 | gap |
| 5.7 | Design monitoring strategy for VCF workloads: application-level monitoring, custom metrics collection, log aggregation with VCF Operations for Logs, and network traffic analysis with VCF Operations for Networks | — | 0 | gap |
| 5.8 | Design a workload migration/onboarding strategy: HCX migration types (bulk, vMotion, replication-assisted), brownfield import via SDDC Manager, and V2V conversion procedures | HCX Migration TypesL2 Stretch & VPN OptionsBrownfield vSphere AdoptionHCX Workload Mobility Lab | 3 | covered |
| 5.9 | Design VCF Operations deployment: sizing for fleet-wide monitoring, retention policies for metrics and logs, remote collector placement for multi-site, and integration with third-party tools (ServiceNow, Splunk) | VCF Operations Node RolesOperations Deployment Architecture | 1 | partial |
| 5.10 | Design capacity forecasting models: predict resource demand using VCF Operations trend analysis, plan procurement cycles, and set automated alerts for capacity thresholds | Capacity Planning & ForecastingCapacity Management ConceptsCapacity Planning Analysis Lab | 1 | partial |
| 5.11 | Design cost management framework: cost drivers mapped to business units, showback/chargeback models, and optimization recommendations from VCF Operations | — | 0 | gap |
2V0-15.25 — VMware Cloud Foundation 9.0 Support
Section 1 — Troubleshooting Methodology and Tools 10%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 1.1 | Apply a structured troubleshooting methodology: identify symptoms, collect data, formulate hypothesis, test hypothesis, implement fix, verify resolution, and document root cause | Structured troubleshooting frameworkLayered isolation methodology | 1 | partial |
| 1.2 | Identify log file locations for all VCF components: SDDC Manager (/var/log/vmware/vcf/), vCenter (/var/log/vmware/), NSX Manager (/var/log/), ESXi (/var/log/), VCF Operations appliance logs | VCF component log locationsWhere VCF logs live | 1 | partial |
| 1.3 | Generate and interpret SOS diagnostic bundles using the SDDC Manager CLI: python /opt/vmware/sddc-support/sos with flags for domain scope, health checks, and log collection | SoS utility syntax and optionsPractice: SoS diagnostics labLog collection with SoSVCF credential store behavior | 3 | covered |
| 1.4 | Use VCF Operations for Logs to aggregate, search, filter, and correlate log entries across all VCF components for root cause analysis | Centralized logging and log searchIntelligent logging and analyticsPractice: Ops for Logs syslog | 1 | partial |
| 1.5 | Use the VCF Operations Observability Workbench to create custom diagnostic views combining metrics, logs, and topology for complex issue analysis | — | 0 | gap |
| 1.6 | Generate log bundles for individual components: vCenter support bundle, NSX support bundle, ESXi vm-support log bundle, and upload via Log Assist for Broadcom support cases | — | 0 | gap |
| 1.7 | Create custom dashboards, reports, and alerts in VCF Operations to proactively identify issues before they cause outages | — | 0 | gap |
| 1.8 | Use esxcli, vmkping, vmkfstools, and other ESXi CLI tools for host-level troubleshooting of network, storage, and configuration issues | Jumbo frame and MTU validationPractice: VDS health and MTUvSAN network health checks | 1 | partial |
| 1.9 | Interpret vSAN health check results and map failures to specific remediation procedures using VMware KB articles | — | 0 | gap |
| 1.10 | Use NSX CLI tools (get logical-switch, get edge-cluster status, get firewall rules) and Central CLI for distributed troubleshooting across transport nodes | NSX CLI diagnostics from ManagerNSX troubleshooting toolingnsxcli command reference | 1 | partial |
| 1.11 | Understand escalation procedures: when to engage Broadcom support, required information for support cases (SOS bundle, component versions, error messages, timeline) | Support case preparation checklistEvidence for LCM upgrade failuresPractice: Broadcom case managementDiagnostic bundle collectionPractice: upgrade failure remediation | 2 | covered |
Section 2 — vSphere and Compute Troubleshooting 22%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 2.1 | Troubleshoot ESXi host connectivity issues: management network failures, hostd service crashes, vpxa agent disconnects, and purple screen of death (PSOD) analysis using vmkernel.log | ESXi log file mapPSOD decoding and core dumpsESXi host diagnosticsESXi host issue triage | 2 | covered |
| 2.2 | Troubleshoot vCenter Server issues: service startup failures (vpxd, vsan-health, sps), database corruption, certificate expiration, and SSO authentication failures | vCenter services and their logsVCSA database and disk issuesPractice: vCenter service recovery | 2 | covered |
| 2.3 | Troubleshoot VM issues: VM fails to power on (resource constraints, storage connectivity, snapshot consolidation needed), VM performance degradation (CPU ready time, memory ballooning, swapping), and VMware Tools connectivity | — | 0 | gap |
| 2.4 | Troubleshoot vSphere cluster configuration issues: DRS rule conflicts, HA failover failures (admission control violations, split-brain), EVC mode incompatibility, and vCLS agent VM health (vSphere 8) or key-value store issues (vSphere 9) | vCLS in vSphere 9HA isolation settings and heartbeat designAvailability design for HA | 2 | covered |
| 2.5 | Troubleshoot vMotion failures: CPU incompatibility (EVC mode mismatch between source and destination), network bandwidth saturation, encrypted vMotion AES-NI requirements, and storage accessibility issues | vMotion failure diagnosticsESXi host and CPU compatibility | 2 | covered |
| 2.6 | Troubleshoot vLCM remediation failures: host fails to enter maintenance mode (DRS cannot evacuate VMs), image push failures, firmware update failures via Hardware Support Manager, and post-reboot compliance mismatches | Maintenance-mode and evacuation blockersPractice: vLCM staged remediationvLCM remediation workflow | 1 | partial |
| 2.7 | Analyze ESXi log files: vmkernel.log (kernel events, storage errors, network errors), hostd.log (host management operations), vpxa.log (vCenter agent communication), and vobd.log (hardware health alerts) | — | 0 | gap |
| 2.8 | Troubleshoot VM snapshot issues: consolidation failures due to locked VMDK files, snapshot chain exceeding recommended depth, and orphaned delta disks consuming datastore space | — | 0 | gap |
| 2.9 | Troubleshoot ESXi host performance: use esxtop to identify CPU contention (%RDY > 10%), memory pressure (balloon/swap activity), storage latency (DAVG > 20ms), and network dropped packets | esxtop CPU metric interpretationesxtop column referencePractice: esxtop performance analysis | 1 | partial |
| 2.10 | Troubleshoot vSphere Configuration Profile drift: identify hosts not compliant with the cluster desired-state JSON profile, remediate non-compliant settings, and resolve profile application failures | — | 0 | gap |
| 2.11 | Troubleshoot identity and authentication: SSO service failures, expired SAML tokens, Identity Federation configuration errors, and AD LDAP connectivity issues | — | 0 | gap |
Section 3 — vSAN Storage Troubleshooting 22%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 3.1 | Troubleshoot vSAN datastore creation failures: ineligible disks (wrong controller mode, HCL violations), insufficient hosts for selected FTT/FTM policy, and VMkernel adapter connectivity issues | — | 0 | gap |
| 3.2 | Troubleshoot vSAN health check failures: hardware compatibility warnings (firmware mismatch), network MTU inconsistency, disk balance degradation, component limit warnings, and resync health issues | vSAN network health categoriesMTU consistency troubleshootingNetwork health thresholdsPractice: vSAN health checksPractice: network issue diagnosis | 2 | covered |
| 3.3 | Troubleshoot degraded vSAN objects: identify objects with reduced redundancy, understand the impact of absent/degraded components, and monitor resync progress for automatic repair | — | 0 | gap |
| 3.4 | Troubleshoot vSAN stretched cluster issues: witness connectivity failures, site partition behavior (which site continues, which pauses), cross-site replication latency exceeding 5ms threshold, and site affinity misconfigurations | Stretched cluster and witness behaviorMulti-site vSAN patternsPractice: stretched cluster design | 1 | partial |
| 3.5 | Troubleshoot vSAN supplemental storage: iSCSI connectivity failures (initiator configuration, target discovery), NFS mount failures (export permissions, network reachability), and FC path management issues | — | 0 | gap |
| 3.6 | Troubleshoot vSAN performance: use vSAN Performance Service to identify high-latency disk groups or hosts, diagnose congestion (vSAN DOM congestion threshold), and identify VMs with non-compliant storage policies causing performance degradation | — | 0 | gap |
| 3.7 | Troubleshoot vSAN disk failures: identify failed or degraded disks in Disk Management, understand disk group rebuild behavior (OSA: entire group rebuilt if cache fails), and perform disk replacement procedures | Disk and cache device failure behaviorDisk group failure handlingPractice: vSAN disk failure recovery | 1 | partial |
| 3.8 | Troubleshoot vSAN encryption issues: KMS connectivity failures, key rotation errors, and encryption state mismatches between policy and actual object encryption | — | 0 | gap |
| 3.9 | Troubleshoot vSAN capacity issues: cluster approaching full (>80% used triggers warning, >95% triggers critical), identify largest consumers using vSAN capacity analytics, and perform space reclamation (delete snapshots, storage vMotion VMs to other datastores) | vSAN capacity thresholds and responsevSAN ESA day-2 operationsCapacity warning remediationPractice: vSAN capacity emergencyPractice: ESA capacity impact analysis | 2 | covered |
| 3.10 | Use vSAN CLI tools for diagnostics: esxcli vsan health cluster list, esxcli vsan storage list, vsan-trace for performance analysis, and cmmds-tool for Cluster Monitoring Membership and Directory Service inspection | vSAN health CLI commandsCMMDS inspection toolingvSAN log file locationsesxcli vSAN command referenceESXi and vSAN log mapPractice: vSAN failure scenarios | 4 | covered |
| 3.11 | Troubleshoot vSAN File Services issues: file service VM deployment failures, NFS/SMB share access errors, and file service networking configuration problems | — | 0 | gap |
Section 4 — NSX Networking Troubleshooting 22%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 4.1 | Troubleshoot VDS (vSphere Distributed Switch) issues: uplink failures, port group misconfiguration, MTU mismatches between VDS and physical switches, LACP negotiation failures, and NIOC traffic classification errors | — | 0 | gap |
| 4.2 | Troubleshoot NSX configuration issues: NSX Manager cluster health (split-brain, node failures), transport node preparation failures, and NSX Controller connectivity errors | NSX Manager log locationsHost data-plane and transport node checksNSX control-plane diagnosticsPractice: NSX connectivity troubleshooting | 3 | covered |
| 4.3 | Troubleshoot NSX routing issues: Tier-0 BGP neighbor establishment failures (AS mismatch, IP reachability), OSPF adjacency issues, static route blackholes, and route redistribution misconfiguration | BGP neighbor state troubleshootingBGP peering fundamentalsPractice: BGP convergence on Edges | 2 | covered |
| 4.4 | Troubleshoot NSX Gateway issues: Edge Node failures, Edge cluster failover behavior (active-standby vs. ECMP active-active), NAT translation failures, and gateway service (DHCP, DNS, VPN) operational issues | — | 0 | gap |
| 4.5 | Troubleshoot NSX services: DHCP relay/server configuration errors, DNS forwarding issues, IPSec VPN tunnel establishment failures (IKE phase 1/2 negotiation), and L2 VPN connectivity issues | IPSec VPN negotiation parameters | 1 | partial |
| 4.6 | Troubleshoot NSX VPC issues: VPC creation failures, Transit Gateway routing errors, inter-VPC connectivity problems, and VPC-level firewall policy conflicts | — | 0 | gap |
| 4.7 | Troubleshoot NSX overlay connectivity: TEP (Tunnel Endpoint) communication failures between hosts, GENEVE encapsulation issues, BFD (Bidirectional Forwarding Detection) failures between TEPs, and overlay segment reachability | TEP connectivity and overlay MTUPractice: Geneve MTU validationOverlay encapsulation fundamentalsPractice: verify tunnel endpoints | 2 | covered |
| 4.8 | Troubleshoot NSX Distributed Firewall: rule hit analysis, rule ordering issues (first-match processing), applied-to scope misconfiguration, and DFW performance impact on data plane latency | DFW rule scope and enforcementDFW rule evaluation internalsPractice: DFW rule debugging | 1 | partial |
| 4.9 | Use NSX troubleshooting tools: NSX Manager UI (Traceflow for packet path analysis, Live Traffic Analysis), NSX CLI (get logical-switch, get interfaces, get route), and Central CLI for distributed troubleshooting | NSX path-tracing toolsPractice: Traceflow and IPFIXPractice: DFW debugging with Traceflow | 1 | partial |
| 4.10 | Troubleshoot NSX transport zone issues: hosts not joined to transport zones, VTEP IP allocation failures from IP pools, and mixed overlay/VLAN transport zone configuration errors | — | 0 | gap |
| 4.11 | Troubleshoot NSX backup and restore: backup job failures, restore prerequisites validation, and post-restore connectivity verification | — | 0 | gap |
Section 5 — VCF Operations and Platform Troubleshooting 24%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 5.1 | Troubleshoot VCF fleet deployment issues: VCF Installer failures (JSON validation errors, network connectivity, DNS resolution), and scaling a fleet by adding/removing VCF Instances | Bring-up pre-flight validationDNS checks during commissioningPractice: deployment failure triage | 1 | partial |
| 5.2 | Troubleshoot VCF 5.x to 9.0 upgrade: pre-upgrade compatibility checks, Aria to VCF Operations migration issues, SDDC Manager upgrade failures, and post-upgrade validation procedures | Bundle download and depot connectivityDepot and proxy troubleshootingOnline vs offline depot model | 1 | partial |
| 5.3 | Troubleshoot vSphere to VCF 9.0 conversion: brownfield import prerequisites, workload domain import failures, and post-conversion configuration validation | Brownfield import prerequisitesvSphere-to-VCF conversion requirementsPractice: brownfield conversion | 1 | partial |
| 5.4 | Troubleshoot VCF workload domain creation failures: vCenter OVA deployment errors, vSAN cluster creation failures, NSX host preparation errors, and network pool IP exhaustion | Failed task analysisNetwork pools and workload domainsLCM task retry workflowWorkload domain prerequisitesPractice: workload domain provisioningPractice: VCF API task diagnostics | 2 | covered |
| 5.5 | Troubleshoot workload domain scaling: adding/removing clusters, adding/removing hosts (commissioning failures, decommissioning data migration), and cluster stretch/unstretch operations | — | 0 | gap |
| 5.6 | Troubleshoot certificate management: certificate replacement failures, auto-renewal failures in VCF 9, CA configuration errors, external certificate import issues, and CSR generation errors | VCF certificate management architecturePractice: certificate rotationCertificate-related lifecycle failures | 2 | covered |
| 5.7 | Troubleshoot password management: credential rotation failures, service account lockouts after rotation, and credential vault synchronization errors between SDDC Manager and managed components | SDDC Manager task log locationsPassword rotation architecturePractice: VCF Password Manager | 1 | partial |
| 5.8 | Troubleshoot VCF Identity Broker: SAML/OIDC federation configuration errors, token validation failures, identity provider connectivity issues, and user role mapping problems | — | 0 | gap |
| 5.9 | Troubleshoot VCF Operations configuration: adapter connectivity issues, data collection failures, dashboard rendering errors, and alert notification delivery failures | VCF Operations adapter and collection issuesVCF Operations data collectionPractice: Ops adapter troubleshooting | 1 | partial |
| 5.10 | Troubleshoot using VCF Operations for Logs: log source configuration issues, log parsing errors, missing log data, and query performance optimization | — | 0 | gap |
| 5.11 | Troubleshoot using VCF Operations for Networks: flow collection issues, topology discovery errors, and network path analysis failures | — | 0 | gap |
| 5.12 | Troubleshoot license management: license assignment failures, license entitlement validation errors, and license expiration handling | — | 0 | gap |
| 5.13 | Troubleshoot VCF Automation configuration: cloud account connectivity failures, blueprint deployment errors, and tenant provisioning issues | — | 0 | gap |
| 5.14 | Troubleshoot Supervisor/VKS issues: Supervisor enablement failures, namespace creation errors, VKS cluster provisioning failures, and storage class/network configuration issues for Kubernetes workloads | — | 0 | gap |
| 5.15 | Troubleshoot HCX: site pairing failures, network extension errors, migration job failures (compatibility issues, network bandwidth, timeout), and post-migration connectivity validation | HCX Service Mesh and migration sizingPractice: HCX migration troubleshooting | 1 | partial |
2V0-16.25 — VMware vSphere Foundation 9.0 Administrator
Section 1 — Architecture and Technologies 12%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 1.1 | Describe virtualization principles, hypervisor types, and IT infrastructure fundamentals | Hypervisor types and abstractionESXi host architecture | 1 | partial |
| 1.2 | Differentiate between VCF and VVF licensing, feature sets, and use cases | VVF licensing tiersvDS capabilities and requirementsVVF editions and features | 1 | partial |
| 1.3 | Identify VVF included components: vSphere 9, vCenter Standard, VCF Operations, optional vSAN | VVF vs VCF component scopeMonitoring tooling in VVFVVF component stackvSphere Foundation overviewVCF Operations for vSphere FoundationvSAN in a VVF deployment | 3 | covered |
| 1.4 | Explain components NOT included in VVF: NSX, HCX, VCF Automation, VCF Operations Fleet Management | What VVF excludesNetworking available in VVFSelf-service and automation in VVF | 2 | covered |
| 1.5 | Describe industry standards relevant to VVF deployments (security compliance, interoperability) | — | 0 | gap |
| 1.6 | Identify VVF hardware compatibility requirements and HCL validation | Hardware compatibility and VCGDriver and firmware compatibilityHardware preparation for VVF | 1 | partial |
| 1.7 | Explain the VVF subscription licensing model and per-core entitlements | VCF 9.0 licensing modelVVF license managementVVF licensing positioning | 2 | covered |
| 1.8 | Differentiate between VVF Standard and VVF Premier edition capabilities | — | 0 | gap |
Section 2 — vSphere Configuration and Management 20%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 2.1 | Deploy and configure ESXi 9.0 hosts for VVF environments | — | 0 | gap |
| 2.2 | Deploy and configure vCenter Server 9.0 for VVF management | — | 0 | gap |
| 2.3 | Create and manage vSphere clusters with DRS and HA | DRS automation levelsDRS features in cluster designCluster DRS configurationWorkload optimization with DRSvMotion and CPU compatibility | 3 | covered |
| 2.4 | Configure resource pools, shares, reservations, and limits | Resource allocation constructsCluster resource design | 1 | partial |
| 2.5 | Manage virtual machine lifecycle: create, clone, template, snapshot, migrate | — | 0 | gap |
| 2.6 | Configure VM hardware versions, virtual devices, and VMware Tools | vMotion of GPU-backed VMsGPU-enabled cluster design | 1 | partial |
| 2.7 | Implement vSphere Lifecycle Manager (vLCM) for image-based host management | Image-based host lifecycleCreating and applying cluster imagesvLCM cluster image management | 1 | partial |
| 2.8 | Compare host profiles vs configuration profiles for host standardization | vSphere Configuration ProfilesHost Profiles and host configuration | 1 | partial |
| 2.9 | Configure and manage content libraries for template and ISO distribution | Content library typesContent libraries and templates | 1 | partial |
| 2.10 | Manage vCenter roles, permissions, and privilege propagation | — | 0 | gap |
Section 3 — Storage Management 18%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 3.1 | Differentiate between principal storage (vSAN) and external/supplemental storage in VVF | — | 0 | gap |
| 3.2 | Configure and manage VMFS 6 datastores on FC, iSCSI, and local storage | VMFS versions and datastore typesvSphere storage options | 1 | partial |
| 3.3 | Configure and manage NFS 3 and NFS 4.1 datastores | NFS and block protocol optionsNFS datastores on ESXi | 2 | covered |
| 3.4 | Configure iSCSI software and hardware initiators on ESXi hosts | — | 0 | gap |
| 3.5 | Configure FC zoning requirements and best practices for ESXi | — | 0 | gap |
| 3.6 | Implement multipathing policies (Fixed, Round Robin, MRU) for SAN storage | Path selection policies and SATPStorage path analysis with esxcli | 1 | partial |
| 3.7 | Create and manage VM storage policies for VVF environments | vSAN FTT and RAID levelsVM storage policy assignmentStorage QoS and IOPS limitsFailures to tolerate and capacity mathvSAN storage policy conceptsBuilding a vSAN cluster with policies | 3 | covered |
| 3.8 | Configure Storage DRS and datastore clusters for automated load balancing | Storage DRS in VCF 9.x | 1 | partial |
| 3.9 | Manage vSAN in VVF: understand the 0.25 TiB/core entitlement and optional add-on | vSAN ESA versus OSAvSAN architecture selectionvSAN architecture comparison | 1 | partial |
| 3.10 | Implement storage vMotion for non-disruptive datastore migrations | VM migration operations | 1 | partial |
Section 4 — Networking 15%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 4.1 | Configure vSphere Standard Switches (VSS) with port groups, VLANs, and security policies | — | 0 | gap |
| 4.2 | Configure vSphere Distributed Switches (VDS) with distributed port groups | — | 0 | gap |
| 4.3 | Implement VDS features: NIOC, port mirroring, NetFlow, LACP, traffic filtering | Network I/O Control on vDSVDS health check and diagnostics | 3 | covered |
| 4.4 | Configure NIC teaming and failover policies (active/standby, load-based, IP hash) | NIC teaming policies on a vDSvDS teaming and uplink policies | 2 | covered |
| 4.5 | Implement network segmentation using VLANs and PVLAN on VDS | — | 0 | gap |
| 4.6 | Configure VMkernel adapters for management, vMotion, vSAN, and NFS traffic | VMkernel adapter servicesVMkernel configuration checksPhysical network MTU design | 2 | covered |
| 4.7 | Troubleshoot network connectivity between VMs, hosts, and external networks | Diagnosing VM connectivity lossVM network issue isolationNetwork issue diagnosis practice | 1 | partial |
| 4.8 | Understand VVF networking limitations: no NSX overlay, no micro-segmentation | Networking capabilities in VVFNSX-only capabilities | 1 | partial |
| 4.9 | Configure TCP/IP stacks for traffic isolation | TCP/IP stacks for VMkernel trafficvMotion network isolation | 1 | partial |
Section 5 — Operations and Troubleshooting 35%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 5.1 | Configure and use VCF Operations (Aria Operations) for VVF monitoring | Green Score & SustainabilityCosting and pricing in VCF OperationsOrchestrator role and use casesCapacity analysis and reclamationThe VCF fleet conceptVCF Operations Console navigation | 9 | covered |
| 5.2 | Create custom dashboards, views, and reports in VCF Operations | — | 0 | gap |
| 5.3 | Configure alerts, symptoms, and notification rules | Symptoms and alert definitionsObject model and alert constructsAlert correlation conceptsAlert policies in VCF Operations | 2 | covered |
| 5.4 | Implement vSphere HA: admission control, heartbeat datastores, isolation response | vSphere HA restart behaviourHA design for availabilityHA admission control validationCluster HA settingsHA and cluster design practice | 2 | covered |
| 5.5 | Configure DRS rules: affinity, anti-affinity, VM-Host rules | Affinity and anti-affinity rulesDesigning DRS placement rulesVM placement and availability | 1 | partial |
| 5.6 | Implement Proactive HA and vSphere Fault Tolerance | Proactive HA and hardware healthCompute availability layersHost health monitoring and HADesigning HA protection layers | 2 | covered |
| 5.7 | Use vSphere Lifecycle Manager for host patching and firmware updates | — | 0 | gap |
| 5.8 | Configure and manage vSphere certificates and Certificate Authority | Certificate authority modesVMCA and certificate managementCertificate rotation across components | 1 | partial |
| 5.9 | Troubleshoot ESXi host boot failures, PSOD, and connectivity issues | Restarting management servicesHost agent troubleshootingvCenter service recovery | 1 | partial |
| 5.10 | Troubleshoot vCenter service health and VPXD issues | Log file map by componentvCenter service and log diagnostics | 1 | partial |
| 5.11 | Troubleshoot VM performance: CPU ready, memory ballooning, storage latency | Performance chart metricsesxtop CPU metricsesxtop performance analysis | 1 | partial |
| 5.12 | Use esxcli, vim-cmd, and dcli for command-line troubleshooting | — | 0 | gap |
| 5.13 | Generate and analyze vm-support diagnostic bundles | ESXi support bundle collectionCollecting and analyzing support bundlesKey CLI commands reference | 1 | partial |
| 5.14 | Monitor host and cluster performance using vCenter performance charts | — | 0 | gap |
| 5.15 | Implement backup and recovery strategies for vCenter and ESXi configurations | Backup methods per componentVCF 9.0 backup and restore | 1 | partial |
2V0-18.25 — VMware vSphere Foundation 9.0 Support
Section 1 — Troubleshooting Methodology 12%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 1.1 | Apply structured troubleshooting methodology: identify, diagnose, resolve, verify, document | Structured troubleshooting methodologyVVF support triage basics | 3 | covered |
| 1.2 | Differentiate between VVF and VCF troubleshooting scope (no NSX, no HCX, no VCF Automation in VVF) | VVF support scope boundariesNSX changes from 5.2 to 9.0DFW enforcement pointVPC networking in VCF 9.0Tier-0 gateways and external routingEdge dataplane performance modes | 14 | covered |
| 1.3 | Identify appropriate support resources: VMware KB articles, Broadcom support portal, community forums | Knowledge base search strategySupport portal and case workflow | 1 | partial |
| 1.4 | Describe the process for opening and escalating VMware support requests (SR) | PSOD evidence for escalationESXi coredump configuration | 1 | partial |
| 1.5 | Understand severity levels and SLA expectations for VVF support cases | Support severity levels and SLAsEscalation tiers and priority scoringCase severity practice | 1 | partial |
| 1.6 | Generate and collect diagnostic bundles for VMware Support | Host diagnostic bundle collectionSupport bundle collection methodsSupport bundle collection lab | 2 | covered |
| 1.7 | Interpret vSphere event logs and alarm history for initial triage | Triage and event correlationLog sources used in triage | 1 | partial |
Section 2 — vSphere Compute Issues 25%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 2.1 | Troubleshoot ESXi host boot failures: PSOD causes, boot device issues, driver incompatibilities | PSOD analysis and dump filesESXi coredump targets | 1 | partial |
| 2.2 | Troubleshoot ESXi host connectivity: management network, DCUI, SSH, direct console | — | 0 | gap |
| 2.3 | Troubleshoot vCenter Server service failures: VPXD, VMware Directory Service, Postgres DB | vCenter database service issuesVCSA service architecturevCenter service recovery lab | 1 | partial |
| 2.4 | Troubleshoot vCenter appliance deployment and configuration issues | — | 0 | gap |
| 2.5 | Diagnose VM power-on failures: resource constraints, EVC mode mismatches, invalid configurations | VM power-on and file locksLock file cleanup labHA admission control practice | 2 | covered |
| 2.6 | Troubleshoot vMotion failures: network misconfiguration, CPU compatibility, provisioning errors | vMotion failure diagnosticsvMotion types and requirementsMTU and vmkping checksCompute and vMotion fundamentals | 2 | covered |
| 2.7 | Troubleshoot DRS and HA cluster issues: split-brain, admission control failures, FDM agent errors | — | 0 | gap |
| 2.8 | Diagnose VM performance problems: CPU contention, memory pressure, snapshot growth | esxtop memory countersesxtop memory viewesxtop performance lab | 2 | covered |
| 2.9 | Troubleshoot vSphere certificate issues: expired certificates, STS token failures, certificate chain errors | Certificates and SSO servicesvCenter certificate renewalVCSA certificate renewal lab | 1 | partial |
| 2.10 | Use esxcli, vim-cmd, and dcli for host-level diagnostics | ESXi esxcli command referenceUnresponsive VM handling | 2 | covered |
Section 3 — Storage Issues 22%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 3.1 | Troubleshoot VMFS datastore access issues: APD (All Paths Down) and PDL (Permanent Device Loss) | Storage disconnects on ESXiPath failover and dead pathsesxcli command reference | 3 | covered |
| 3.2 | Troubleshoot iSCSI connectivity: initiator configuration, CHAP authentication, port binding failures | vSAN iSCSI & Block Storage | 1 | partial |
| 3.3 | Troubleshoot FC storage: zoning issues, LUN masking, HBA driver problems | — | 0 | gap |
| 3.4 | Troubleshoot NFS datastore mounting: DNS resolution, export permissions, firewall rules, NFS locks | NFS and datastore types | 1 | partial |
| 3.5 | Diagnose storage performance: high latency, KAVG/DAVG/GAVG analysis, queue depth tuning | Storage latency counters in esxtopesxtop disk viewAdvanced esxtop analysis lab | 2 | covered |
| 3.6 | Troubleshoot vSAN issues in VVF: disk group failures, object compliance, rebuild operations | — | 0 | gap |
| 3.7 | Troubleshoot vSAN stretched cluster synchronization and witness failures | — | 0 | gap |
| 3.8 | Troubleshoot Storage vMotion failures and datastore migration issues | — | 0 | gap |
| 3.9 | Troubleshoot VM snapshot management: consolidation failures, orphaned snapshots, delta disk growth | Snapshot consolidation and locksSnapshot consolidation lab | 1 | partial |
| 3.10 | Analyze SCSI sense codes and storage error messages in vmkernel.log | ESXi log file locationsSCSI errors in vmkernel logLog locations and rotation | 2 | covered |
Section 4 — Networking Issues 18%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 4.1 | Troubleshoot vSphere Standard Switch (VSS) issues: port group misconfigurations, VLAN tagging | — | 0 | gap |
| 4.2 | Troubleshoot vSphere Distributed Switch (VDS) issues: uplink failures, LACP negotiation, NIOC | vDS teaming and LACPRecovering from vDS changesvDS and NIC teaming labVDS health check lab | 2 | covered |
| 4.3 | Diagnose VM network connectivity: incorrect port groups, MAC address conflicts, security policy blocks | Port group VLAN checksVM connectivity diagnosticsVM-level network checks | 2 | covered |
| 4.4 | Troubleshoot VMkernel adapter issues: vMotion failures due to network, iSCSI port binding, NFS mount failures | — | 0 | gap |
| 4.5 | Troubleshoot physical NIC (vmnic) failures: link state, driver issues, firmware compatibility | ESXi network CLI diagnosticsesxcli command reference | 1 | partial |
| 4.6 | Diagnose network performance: packet loss, CRC errors, MTU mismatches, jumbo frame issues | End-to-end jumbo frame MTUOverlay MTU requirementsMTU-related packet loss checks | 3 | covered |
| 4.7 | Troubleshoot VDS migration issues when moving from VSS to VDS | VSS to VDS migration risksVMkernel adapters and uplinks | 1 | partial |
| 4.8 | Use network troubleshooting tools: pktcap-uw, tcpdump-uw, net-stats, esxcli network commands | ESXi packet capture toolingVMkernel interface CLIesxcli command referenceESXi network diagnostics lab | 2 | covered |
Section 5 — Upgrade and Migration Issues 23%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 5.1 | Troubleshoot vSphere to VVF 9.0 conversion process | — | 0 | gap |
| 5.2 | Troubleshoot VVF 9.0 initial deployment and configuration issues | — | 0 | gap |
| 5.3 | Troubleshoot ESXi host upgrade failures: compatibility issues, boot bank problems, VIB conflicts | ESXi upgrade troubleshootingvLCM images and OEM driversESXi upgrade via vLCM labUpgrade failure remediation lab | 2 | covered |
| 5.4 | Troubleshoot vCenter Server upgrade and migration failures | vCenter upgrade stagesPre-check failures and logs | 2 | covered |
| 5.5 | Troubleshoot vSphere Lifecycle Manager remediation failures: pre-check errors, hardware incompatibility | vLCM hardware compatibility checksUpgrade troubleshooting logsVCG driver and firmware validation | 2 | covered |
| 5.6 | Troubleshoot cluster scaling: adding/removing ESXi hosts, cluster reconfiguration issues | — | 0 | gap |
| 5.7 | Troubleshoot VVF license assignment, entitlement verification, and expiration issues | VVF license assignmentVCF 9.0 licensing modelLicense model change in 9.0 | 2 | covered |
| 5.8 | Troubleshoot VCF Operations configuration in VVF: adapter connectivity, data collection failures | VCF Operations adapter configurationVCF Operations in VVFDeploy VCF Operations lab | 1 | partial |
| 5.9 | Troubleshoot VCF Operations Orchestrator: workflow execution failures, plugin issues | — | 0 | gap |
| 5.10 | Troubleshoot VCF Operations for Logs: log forwarding, retention, archiving configuration | ESXi syslog configurationOps for Logs syslog lab | 1 | partial |
2V0-41.24 — VMware NSX 4.x Professional V2
Section 1 — Architecture and Technologies 12%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 1.1 | Describe VMware Virtual Cloud Network vision and NSX platform role | — | 0 | gap |
| 1.2 | Explain NSX architecture: management plane, control plane, data plane | NSX three-plane architectureControl plane vs data planeNSX Manager cluster diagnostics | 2 | covered |
| 1.3 | Identify NSX Manager cluster components and deployment models | NSX Manager cluster designNSX form factors and sizing | 1 | partial |
| 1.4 | Describe the NSX data plane: N-VDS, VDS-based transport, host transport nodes, edge transport nodes | — | 0 | gap |
| 1.5 | Explain transport zones: overlay and VLAN types, their purpose and scope | Transport zone types and scopeOverlay transport zone lab | 1 | partial |
| 1.6 | Describe Geneve encapsulation format and TEP (Tunnel Endpoint) communication | GENEVE overlay encapsulationGeneve encapsulation deep diveOverlay segment and TEP labTEP connectivity checks | 2 | covered |
| 1.7 | Identify N-VDS vs VDS integration modes for transport node configuration | NSX data plane componentsOverlay segment and TEP lab | 1 | partial |
| 1.8 | Explain DPU-based acceleration for NSX data plane offload | DPU-Based Acceleration | 1 | partial |
Section 2 — Installation and Configuration 18%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 2.1 | Deploy NSX Manager cluster (3-node) for production environments | NSX Manager cluster HAManager cluster sizing | 1 | partial |
| 2.2 | Prepare ESXi hosts as transport nodes: install NSX VIBs, configure TEP interfaces | Overlay MTU validation labTEP tunnel and MTU checksUnderlay MTU requirements | 1 | partial |
| 2.3 | Configure transport zones and assign to transport nodes | — | 0 | gap |
| 2.4 | Configure IP pools and IP addressing for TEP interfaces | TEP addressing on transport nodesTransport node profile design | 1 | partial |
| 2.5 | Deploy and configure NSX Edge nodes (VM-based and bare-metal) | Edge node sizing guidelinesEdge sizing for advanced servicesEdge cluster deployment lab | 2 | covered |
| 2.6 | Configure NSX Edge clusters with appropriate HA mode (active-active, active-standby) | Tier-0 HA modes and ECMPECMP and dynamic routingT0/T1 routing topology lab | 1 | partial |
| 2.7 | Configure segments (overlay and VLAN-backed) with segment profiles | VLAN vs overlay transport zonesTransport zone and profile design | 1 | partial |
| 2.8 | Manage NSX users, roles, and RBAC with LDAP and VMware Identity Manager integration | NSX identity source integration | 1 | partial |
| 2.9 | Configure NSX backup and restore, syslog forwarding | NSX Manager backup practiceBackup and recovery design | 1 | partial |
Section 3 — Logical Switching 15%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 3.1 | Explain logical switching concepts: segments, segment profiles, MAC learning | — | 0 | gap |
| 3.2 | Describe overlay segment packet forwarding: Geneve encapsulation, TEP-to-TEP tunneling | Overlay east-west forwardingVM-to-VM overlay validation | 2 | covered |
| 3.3 | Differentiate between overlay segments and VLAN segments | VLAN-backed segments | 2 | covered |
| 3.4 | Configure segment profiles: security, QoS, IP discovery, MAC discovery, spoofguard | Segment profiles overviewSegment profile exploration | 2 | covered |
| 3.5 | Explain BUM (Broadcast, Unknown unicast, Multicast) traffic handling in overlay networks | BUM replication modesControl plane BUM handling | 1 | partial |
| 3.6 | Configure L2 bridging between overlay segments and VLAN segments | VLAN segments and physical connectivity | 1 | partial |
| 3.7 | Describe NSX packet walk for east-west (within segment) and cross-segment traffic | Intra-segment forwarding on a hostHost data plane switching | 1 | partial |
Section 4 — Logical Routing 18%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 4.1 | Explain NSX logical routing architecture: distributed router (DR) and service router (SR) | Where stateful gateway services runDistributed router first-hop routingNSX routing path walkthroughTier-0 and Tier-1 routing model | 2 | covered |
| 4.2 | Configure Tier-0 gateways for north-south traffic and external connectivity | Tier-0 north-south gatewayT0/T1 routing topology lab | 1 | partial |
| 4.3 | Configure Tier-1 gateways for tenant/workload isolation and east-west routing | Tier-1 services and Edge clustersTier-1 gateway configuration lab | 1 | partial |
| 4.4 | Configure static routes on Tier-0 and Tier-1 gateways | — | 0 | gap |
| 4.5 | Configure BGP peering on Tier-0 gateways for dynamic routing with physical routers | Route redistribution on Tier-0BGP peering and redistribution labRoute redistribution into BGP | 1 | partial |
| 4.6 | Configure OSPF on Tier-0 gateways as an alternative dynamic routing protocol | — | 0 | gap |
| 4.7 | Explain ECMP (Equal-Cost Multi-Path) for load distribution across multiple uplinks | Tier-0 HA modesECMP path behavior | 1 | partial |
| 4.8 | Configure VRF Lite for multi-tenant routing on shared Tier-0 gateways | VRF-Lite on Tier-0VRF-Lite and route leaking lab | 1 | partial |
| 4.9 | Explain the logical routing packet walk: DR forwarding vs SR forwarding | — | 0 | gap |
| 4.10 | Configure NAT: SNAT, DNAT, reflexive NAT, and NO-NAT rules on gateways | NAT on Tier-1 gatewaysRouting and NAT topology lab | 1 | partial |
| 4.11 | Configure DHCP and DNS services on NSX gateways | — | 0 | gap |
Section 5 — Security Services 18%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 5.1 | Describe NSX Distributed Firewall (DFW) architecture and east-west traffic control | Where DFW rules are enforcedKernel-level DFW enforcement lab | 1 | partial |
| 5.2 | Configure DFW rules: allow, drop, reject actions with logging | DFW rule evaluation pipelineDFW rule tables and matchingDFW policy build lab | 2 | covered |
| 5.3 | Implement micro-segmentation using security groups, tags, and DFW policies | Tag-based micro-segmentation designGroup membership criteriaSecurity policy with tags labLateral security design decisions | 2 | covered |
| 5.4 | Describe NSX Gateway Firewall for north-south traffic control at Tier-0/Tier-1 gateways | Gateway firewall placementvDefend component overview | 1 | partial |
| 5.5 | Configure Gateway Firewall rules with service profiles | — | 0 | gap |
| 5.6 | Configure IDS/IPS on distributed and gateway firewalls | Distributed IDS/IPS enforcementIDS/IPS deployment labIDS/IPS placement design | 1 | partial |
| 5.7 | Explain NSX integration with VMware Identity Manager for Identity Firewall | Identity firewall and AD groups | 1 | partial |
| 5.8 | Configure IPSec VPN: route-based and policy-based site-to-site VPN | IPSec VPN modes on NSX | 1 | partial |
| 5.9 | Configure L2 VPN for extending Layer 2 networks across sites | — | 0 | gap |
| 5.10 | Describe NSX ALB (Avi Load Balancer) integration for application delivery | NSX load balancing and AviAdvanced load balancing solutionAvi architecture and deployment | 1 | partial |
Section 6 — Operations and Troubleshooting 19%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 6.1 | Use NSX Manager UI and CLI for operational management | Support bundle collectionSoS and log bundle workflow | 1 | partial |
| 6.2 | Configure syslog forwarding for NSX components | Syslog forwarding to a SIEMCentralized logging solution | 1 | partial |
| 6.3 | Perform NSX backup and restore operations | — | 0 | gap |
| 6.4 | Use log files to troubleshoot NSX issues: /var/log/proton, /var/log/nsx-syslog.log | NSX Manager log file locationsLog locations and collection | 1 | partial |
| 6.5 | Use NSX CLI tools: get logical-switch, get logical-router, get firewall rules | Logical switch state on transport nodesNSX CLI command reference | 2 | covered |
| 6.6 | Troubleshoot transport node connectivity: TEP communication failures, tunnel status | Tunnel status CLI checksTEP tunnel verification lab | 1 | partial |
| 6.7 | Troubleshoot logical switching issues: segment connectivity, MAC learning, BUM flooding | — | 0 | gap |
| 6.8 | Troubleshoot logical routing issues: BGP peering failures, route advertisement, ECMP | Tier-1 to Tier-0 route advertisementBGP neighbor diagnosticsNSX routing troubleshootingBGP session fundamentalsRoute advertisement configurationBGP convergence on Edges lab | 2 | covered |
| 6.9 | Troubleshoot DFW and Gateway Firewall rule evaluation order and default rules | DFW default rule behaviorBaseline before enforcement | 1 | partial |
| 6.10 | Identify and use NSX Traceflow for packet path visualization and troubleshooting | Traceflow path analysis labTraceflow for connectivity issuesDFW debugging with Traceflow | 2 | covered |
| 6.11 | Monitor NSX Edge node health: CPU, memory, interface statistics, tunnel status | — | 0 | gap |
2V0-32.24 — VMware Cloud Operations 8.x Professional V2
Section 1 — Architecture and Technologies 15%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 1.1 | Differentiate between VMware Cloud Management offerings: SaaS vs On-Premises deployment models | Automation component rolesConsuming and automating VCFCloud template design patterns | 1 | partial |
| 1.2 | Identify features and capabilities of Aria Suite Lifecycle Manager (vRealize Suite LCM) | Aria suite components and rolesAria stack deployment sequence | 1 | partial |
| 1.3 | Identify features and capabilities of Aria Operations (vRealize Operations) | — | 0 | gap |
| 1.4 | Identify features and capabilities of Aria Log Insight (vRealize Log Insight) | Aria product renaming mapLegacy vRealize to Aria names | 1 | partial |
| 1.5 | Describe Aria Operations architecture: analytics cluster, collector groups, cloud proxies | Aria Operations collection tiersOperations node roles explainedValidated operations design | 3 | covered |
| 1.6 | Describe Aria Operations deployment sizes: extra-small to extra-large, and resource requirements | Operations sizing and deployment optionsOperations sizing in VCFObject-count sizing guidance | 1 | partial |
| 1.7 | Describe Aria Operations HA and Continuous Availability (CA) modes | Operations availability model changesAnalytics cluster node roles | 1 | partial |
| 1.8 | Describe Aria Log Insight architecture: standalone vs clustered with ILB (Integrated Load Balancer) | Operations for Logs cluster designValidated logging cluster design | 1 | partial |
Section 2 — Policies and Capacity Management 20%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 2.1 | Configure operational policies for object groups and custom groups | What Operations policies controlAlert policy and symptom framework | 1 | partial |
| 2.2 | Configure capacity policies: allocation model, demand model, and hybrid model | Demand, allocation and utilization modelsCapacity planning dimensions | 2 | covered |
| 2.3 | Implement capacity analytics: time remaining, capacity projections, optimization recommendations | Capacity metric definitionsCapacity remaining and headroom | 1 | partial |
| 2.4 | Configure what-if analysis scenarios for workload placement and resource planning | What-if analysis and capacity modelingCapacity and what-if practice lab | 2 | covered |
| 2.5 | Implement workload optimization: right-sizing (oversized/undersized VM detection), reclaim recommendations | Rightsizing recommendation modelDemand versus allocationRight-sizing automation policies | 3 | covered |
| 2.6 | Configure cost analysis: cost drivers, rate cards, showback/chargeback models | Showback and chargeback cost modelsCost model and rate cardsCost optimization super metrics lab | 1 | partial |
| 2.7 | Implement compliance policies: vSphere Security Configuration Guide, custom benchmarks | Compliance frameworks and drift detectionCompliance policy typesCompliance benchmarking labCompliance drift detection lab | 3 | covered |
| 2.8 | Configure business intent policies for application performance SLAs | — | 0 | gap |
| 2.9 | Use Automation Central for automated remediation actions (power off idle VMs, right-size, reclaim snapshots) | Automation and reclamation policiesAutomated remediation actionsReclaimable capacity types | 1 | partial |
Section 3 — Troubleshooting with Analytics 22%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 3.1 | Use Aria Operations for root cause analysis: symptoms, alerts, and anomaly detection | Dynamic thresholds and symptomsDemand, allocation and contentionThreshold modes comparedRightsizing signals | 3 | covered |
| 3.2 | Create and interpret custom dashboards for infrastructure health monitoring | CPU performance counters to watchPerformance troubleshooting workflowContention scoring super metrics | 1 | partial |
| 3.3 | Configure and use super metrics for composite performance indicators | Super metric formulas and scopeSuper metric recipe examples | 1 | partial |
| 3.4 | Use the Troubleshooting Workbench for guided root cause analysis | Root-cause workflow in OperationsCross-component correlation | 1 | partial |
| 3.5 | Interpret health, risk, and efficiency badges for objects | Object badges in OperationsAlert impact and badge types | 2 | covered |
| 3.6 | Configure integration between Aria Operations and Aria Log Insight for correlated analysis | Operations and Logs integrationLaunch-in-context between metrics and logs | 1 | partial |
| 3.7 | Use Aria Log Insight for log search, filtering, and pattern detection | Explore Logs and field extractionLog sources and vCenter logsLog analytics solution designLog onboarding and alerting lab | 2 | covered |
| 3.8 | Configure Aria Log Insight agents, log forwarding, log masking, and filtering | — | 0 | gap |
| 3.9 | Create log-based alerts and notifications in Aria Log Insight | — | 0 | gap |
| 3.10 | Use metric charts, heat maps, and relationship maps for troubleshooting | — | 0 | gap |
Section 4 — Custom Content 18%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 4.1 | Create custom dashboards with widgets: scoreboard, heat map, top-N, metric chart, alert list, object list | Dashboard widget typesDashboard building labExecutive dashboard build lab | 2 | covered |
| 4.2 | Create custom views: list, summary, trend, distribution, and text views | View types and their usesCreating custom views | 1 | partial |
| 4.3 | Create custom reports: scheduled, ad-hoc, PDF/CSV export | Views and scheduled reportingCustom views and reportsNotification channels | 2 | covered |
| 4.4 | Create and manage super metrics: formulas, object scope, policy association | Super metric architectureWorked super metric formulas | 1 | partial |
| 4.5 | Install and configure management packs for third-party monitoring (AWS, Azure, storage arrays) | Adapters and management packsIntegration and extensibility options | 1 | partial |
| 4.6 | Install and configure content packs in Aria Log Insight (VMware, Linux, Windows, network devices) | Content packs for Operations for LogsContent pack management design | 1 | partial |
| 4.7 | Create custom content in Aria Log Insight: extracted fields, saved queries, custom dashboards | — | 0 | gap |
| 4.8 | Use the True Visibility Suite for extended monitoring capabilities | — | 0 | gap |
| 4.9 | Share and export custom content between Aria Operations instances | Management pack packagingContent packs and prebuilt contentExporting dashboard definitions | 1 | partial |
Section 5 — Operations Management 25%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 5.1 | Deploy and configure Aria Suite Lifecycle Manager (vRSLCM) | — | 0 | gap |
| 5.2 | Use vRSLCM for deploying Aria Operations and Aria Log Insight | — | 0 | gap |
| 5.3 | Configure vRSLCM binary mapping, license management, and certificate management | Aria Suite Lifecycle in the BOM | 1 | partial |
| 5.4 | Apply patches and upgrades via vRSLCM to Aria Operations and Aria Log Insight | — | 0 | gap |
| 5.5 | Configure RBAC and identity management in Aria Operations (local, LDAP, SAML, VMware Identity Manager) | Identity sources for OperationsIdentity and access management design | 1 | partial |
| 5.6 | Manage Aria Operations cluster: add/remove nodes, scale analytics cluster, manage data retention | Cluster composition and scalingOperations cluster maintenance lab | 1 | partial |
| 5.7 | Configure data sources: vCenter adapter, NSX adapter, storage adapters, cloud adapters | — | 0 | gap |
| 5.8 | Configure Aria Operations event log forwarding to external systems | Alert-to-ticket integrationOutbound alert actionsNotification and remediation pipeline | 1 | partial |
| 5.9 | Manage Aria Log Insight: configure retention policies, archiving (NFS), storage management | Log retention and archive designLog retention and archiving | 1 | partial |
| 5.10 | Manage Aria Log Insight agents and agent groups for OS-level log collection | — | 0 | gap |
| 5.11 | Configure Aria Log Insight log forwarding destinations and log routing | — | 0 | gap |
| 5.12 | Use Skyline and Federated Analytics for proactive support and cross-instance analytics | Skyline proactive healthMulti-instance operations topologiesMulti-cloud observability options | 2 | covered |
| 5.13 | Generate log bundles for troubleshooting Aria Operations and Aria Log Insight issues | — | 0 | gap |
6V0-21.25 — VMware vDefend Security for VCF 5.x Administrator
Section 1 — vDefend Architecture 20%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 1.1 | Describe the vDefend security platform and its role within VMware Cloud Foundation | Security compliance benchmarks in VCF | 1 | partial |
| 1.2 | Explain the Distributed Firewall (DFW) architecture and hypervisor-level enforcement at each vNIC | DFW kernel enforcement pointvDefend component stackDFW realization at the kernel | 3 | covered |
| 1.3 | Describe the Gateway Firewall (GFW) for north-south perimeter security | Where Gateway Firewall runsvDefend component map | 1 | partial |
| 1.4 | Explain the Security Services Platform (SSP) for scale-out analytics and visibility | — | 0 | gap |
| 1.5 | Differentiate between east-west (DFW) and north-south (GFW) traffic security models | Gateway Firewall vs DFWEast-west enforcement pointVPC constructs and NSX security servicesvDefend component stackvDefend component mapVPC isolation and security policy | 3 | covered |
| 1.6 | Describe the vDefend licensing model: Firewall add-on vs Firewall with ATP add-on | vDefend licensing tiersvDefend component stackDistributed IDS/IPS prerequisites | 3 | covered |
| 1.7 | Identify vDefend integration points with NSX Manager, vCenter, and VCF Operations | — | 0 | gap |
| 1.8 | Explain the data plane components including kernel-level packet processing at vfilter | DFW data path architectureHypervisor-native enforcement principles | 1 | partial |
| 1.9 | Describe the role of NSX Application Platform (NAPP) for advanced security services | NAPP platform design decisionsAdvanced threat service componentsSecurity services platform in VCF 9.0 | 2 | covered |
Section 2 — Micro-Segmentation 30%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 2.1 | Configure DFW policies across predefined categories: Ethernet, Emergency, Infrastructure, Environment, Application, and Default | Default rule in zero-trust designsRule categories and the default ruleZero-trust rule set design | 1 | partial |
| 2.2 | Explain DFW rule processing order: categories evaluated left-to-right, rules top-to-bottom within each category, first match wins | DFW rule processing pipelinePolicy categories and orderingCategory order in practice | 1 | partial |
| 2.3 | Configure security groups with static membership (manual VM/IP assignment) | — | 0 | gap |
| 2.4 | Configure security groups with dynamic membership using tag-based criteria, VM name patterns, and OS type | Security groups and membership typesTag-based dynamic groupingGroup membership design decisions | 1 | partial |
| 2.5 | Implement NSX tag-based grouping for automated workload classification | Security groups vs IP-based rulesTag-based micro-segmentationGrouping strategy design decisions | 1 | partial |
| 2.6 | Configure Active Directory integration for Identity Firewall (IDFW) user-based policies | Identity Firewall prerequisitesContext-aware identity rules | 1 | partial |
| 2.7 | Explain the Applied To field for scoping rule enforcement to specific groups, segments, or DFW-wide | Applied-To scope optimizationApplied-To design patternsScoping rules to reduce host footprint | 1 | partial |
| 2.8 | Design and implement zone-based segmentation (Production vs Development, PCI vs non-PCI) | — | 0 | gap |
| 2.9 | Implement application-level micro-segmentation with ring-fencing and tier-based controls | — | 0 | gap |
| 2.10 | Configure context-aware firewall policies using Layer 7 application identification | Layer 7 rules and context profilesDFW L2-L7 rule capabilitiesFQDN and TLS-aware rule features | 2 | covered |
| 2.11 | Protect container workloads using vDefend Firewall for Kubernetes/VKS environments | — | 0 | gap |
| 2.12 | Plan segmentation strategy using Security Intelligence flow analysis and rule recommendations | Rule actions and loggingFlow-based rule recommendationsNSX Intelligence recommendation engineLogging guidance and flow analytics | 2 | covered |
Section 3 — Threat Prevention 20%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 3.1 | Configure distributed IDS/IPS with signature-based threat detection at each workload vNIC | Signature profiles and rule bindingProfile design per workload tierApplying IDS/IPS profiles to rules | 1 | partial |
| 3.2 | Manage IDS/IPS signature profiles including automatic downloads and custom signature import | Signature sources and updatesSignature bundle updates | 1 | partial |
| 3.3 | Differentiate between distributed IDS/IPS (east-west) and gateway IDS/IPS (north-south) | — | 0 | gap |
| 3.4 | Configure IDS/IPS rule actions: Detect only vs Detect and Prevent (Reject/Drop) | IDS vs IPS operational modesDetection mode behaviour | 2 | covered |
| 3.5 | Implement IDS/IPS Turbo mode architecture for enhanced performance | NSX Datapath Acceleration | 1 | partial |
| 3.6 | Configure NSX Malware Prevention Service using Guest Introspection (GI) framework | — | 0 | gap |
| 3.7 | Deploy NSX Distributed Malware Prevention service VMs on ESXi host clusters | Malware Prevention architectureComponent deployment requirements | 1 | partial |
| 3.8 | Explain file introspection capabilities: hash-based detection, local analysis, and cloud analysis | File analysis pipelineAdvanced threat prevention componentsNAPP-hosted security services | 2 | covered |
| 3.9 | Configure URL filtering and FQDN-based filtering for outbound traffic control | Gateway Firewall URL filtering | 1 | partial |
| 3.10 | Integrate vDefend with third-party security services (Palo Alto, Check Point) via service insertion | — | 0 | gap |
Section 4 — Network Detection and Response 15%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 4.1 | Describe the NDR architecture: aggregation, correlation, and context engine | NDR data collection layerTelemetry flow between components | 1 | partial |
| 4.2 | Explain how NDR combines signals from IDS/IPS, Malware Prevention, and NTA | NDR signal aggregationCampaign correlation engine | 1 | partial |
| 4.3 | Configure Network Traffic Analysis (NTA) for behavior-based anomaly detection using ML algorithms | What NTA analysesBehavioural vs signature detectionBehavioural detection models | 2 | covered |
| 4.4 | Interpret NDR campaign visualization linking related alerts into unified intrusion campaigns | NDR campaigns and confidence scoringCampaign correlation engineCampaign investigation walkthrough | 3 | covered |
| 4.5 | Deploy and configure NDR Sensor for non-vSphere workload monitoring | NSX Datapath Acceleration | 1 | partial |
| 4.6 | Use NDR Intelligent Assist (GenAI/LLM-powered) for threat analysis and response guidance | — | 1 | partial |
| 4.7 | Integrate NDR alerts with external SIEM platforms for centralized security operations | — | 0 | gap |
| 4.8 | Configure air-gapped NDR environments for regulated/isolated deployments | NDR connectivity requirements | 1 | partial |
Section 5 — Operations 15%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 5.1 | Configure Role-Based Access Control (RBAC) for security administration | NSX role assignments and RBAC | 2 | covered |
| 5.2 | Automate security workflows for policy deployment and compliance enforcement | NSX Manager configuration backupStaging rules before enforcementVCF Automation policy capabilitiesBackup design for VCF componentsVersion-controlled infrastructure as codeValidating rules in monitor mode | 3 | covered |
| 5.3 | Monitor security events and perform incident response using vDefend dashboards | File verdicts and reportingUnified security dashboard | 1 | partial |
| 5.4 | Troubleshoot DFW rule enforcement using packet tracing, flow monitoring, and log analysis | Traceflow for DFW troubleshootingVerifying rules on the ESXi hostTraceflow for DFW validationDFW troubleshooting commands | 2 | covered |
| 5.5 | Generate and analyze PCAP captures for IDS/IPS signature validation | — | 0 | gap |
| 5.6 | Use Security Intelligence segmentation assessment to evaluate security posture | Flow-based segmentation assessmentNSX Intelligence security postureSecurity Intelligence in the VVS design | 1 | partial |
| 5.7 | Implement Firewall Rule Analysis to identify suboptimal or redundant policies | DFW rule hygiene analysisRule consolidation strategies | 1 | partial |
| 5.8 | Configure syslog forwarding and log export for security audit compliance | DFW logging and syslog planningSOC and compliance reporting integration | 2 | covered |
6V0-22.25 — VMware Avi Load Balancer 30.x Administrator
Section 1 — Avi Architecture 20%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 1.1 | Describe the Avi Load Balancer three-tier architecture: Controller, Service Engines, and applications | Service Engine data planeAvi control and data planes | 1 | partial |
| 1.2 | Explain Controller cluster deployment: 3-node cluster, leader election, cluster VIP, follower synchronization | Controller cluster and quorumAvi architecture overviewDeploying a Controller cluster | 2 | covered |
| 1.3 | Describe Service Engine (SE) lifecycle management by the Controller | SE deployment prerequisites in VCFCloud access modes | 1 | partial |
| 1.4 | Explain the distributed data plane architecture with SEs handling all data traffic | Where packets are processedControl plane vs data plane | 1 | partial |
| 1.5 | Differentiate between L4 and L7 load balancing characteristics | — | 0 | gap |
| 1.6 | Describe Service Engine Groups: logical grouping, shared configuration, HA mode settings | Service Engine Groups explainedAvi objects in VCF | 1 | partial |
| 1.7 | Explain elastic scale-out: automatic SE deployment for performance scaling | SE autoscale policiesSE fabric scale-out practice | 1 | partial |
| 1.8 | Describe the interaction between Virtual Services, Pools, and Virtual IPs (VIPs) | — | 0 | gap |
| 1.9 | Identify VCF integration: SDDC Manager deployment, NSX Cloud Connector, vCenter discovery | Avi integration into VCFAvi deployment in VCF 9.0Migrating NSX LB to AviAvi deployment access modesNSX segments and load balancing | 3 | covered |
Section 2 — Virtual Service Configuration 25%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 2.1 | Create and configure Virtual Services with VIP, port, and application profile assignments | — | 0 | gap |
| 2.2 | Configure pools with backend server definitions and health monitors | — | 0 | gap |
| 2.3 | Implement load balancing algorithms: Round Robin, Least Connections, Consistent Hash, Fastest Response | Pool load balancing behaviourLoad distribution methods | 2 | covered |
| 2.4 | Configure health monitors: TCP, HTTP, HTTPS, UDP, DNS, and custom monitors | Health monitor configurationHealth monitor protocolsHealth monitor mismatch pitfalls | 2 | covered |
| 2.5 | Implement persistence profiles: IP-based, cookie-based, custom header, App Cookie, TLS | Session persistence optionsPersistence on NSX and Avi | 2 | covered |
| 2.6 | Configure SSL/TLS termination: certificate management, SSL profiles, client certificate authentication | SSL termination and bridgingSSL profiles and certificates | 1 | partial |
| 2.7 | Manage EC and RSA certificates: generation, import, renewal, and chain validation | — | 0 | gap |
| 2.8 | Configure Perfect Forward Secrecy (PFS) cipher suites in SSL profiles | Cipher suite selectionTLS handshake comparison lab | 1 | partial |
| 2.9 | Implement content switching using HTTP request policies and DataScripts | Content switching on L7 | 1 | partial |
| 2.10 | Configure DNS virtual services for DNS load balancing and GSLB | — | 0 | gap |
Section 3 — Application Profiles 20%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 3.1 | Identify features inside HTTP application profiles: connection multiplexing, compression, caching | HTTP virtual service behaviour | 1 | partial |
| 3.2 | Configure L4 application profiles for TCP/UDP pass-through load balancing | L4 versus L7 virtual services | 2 | covered |
| 3.3 | Configure DNS application profiles for DNS-based services | — | 0 | gap |
| 3.4 | Implement SSL/TLS application profiles with appropriate cipher suites and protocol versions | TLS version and cipher policyTLS profile configuration lab | 1 | partial |
| 3.5 | Configure Web Application Firewall (WAF): enable/disable, OWASP CRS, detection vs enforcement mode | WAF rollout and tuningAvi advanced L7 services | 3 | covered |
| 3.6 | Explain WAF learning mode for positive security model development | — | 0 | gap |
| 3.7 | Describe the WAF security pipeline: allow list, positive security model, signature engine (CRS) | — | 0 | gap |
| 3.8 | Configure WAF paranoia levels and false-positive mitigation | OWASP CRS rule tuning | 1 | partial |
| 3.9 | Identify the capacity impact of enabling WAF on Service Engines | WAF deployment considerationsSE CPU and sizing | 1 | partial |
| 3.10 | Implement rate limiting per application at L3/L4 and L7 layers | — | 0 | gap |
Section 4 — Analytics and Troubleshooting 20%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 4.1 | Enable and interpret real-time analytics for virtual services | — | 0 | gap |
| 4.2 | Analyze end-to-end timing breakdown: Client RTT, Server RTT, App Response, Data Transfer | Latency breakdown metricsEnd-to-end analytics lab | 1 | partial |
| 4.3 | Differentiate between significant and non-significant logging and their resource impact | Client log modesReading Avi application logs | 2 | covered |
| 4.4 | Interpret application logs for HTTP status codes, error rates, and response times | — | 0 | gap |
| 4.5 | Analyze client insights: geographic distribution, browser types, connection quality | — | 0 | gap |
| 4.6 | Interpret health scores and understand factors that affect scoring | What health score measuresVirtual service performance analysis | 2 | covered |
| 4.7 | Use analytics to identify the source of latency: client-side, network, or server-side | End-to-end timing breakdownL7 analytics troubleshooting | 1 | partial |
| 4.8 | Identify how logs change when WAF is enabled (additional WAF match fields) | WAF logging and tuning | 1 | partial |
| 4.9 | Troubleshoot pool member health monitor failures using logs and connectivity tests | Diagnosing pool member failuresAnalytics-driven troubleshooting | 2 | covered |
| 4.10 | Diagnose SE performance issues using SE-level metrics and resource utilization | Packet-level evidence collectionPCAP and HAR export | 1 | partial |
Section 5 — Operations 15%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 5.1 | Identify SE capacity limitations and SE group maximum configurations | — | 0 | gap |
| 5.2 | Configure SE anti-affinity rules for fault domain separation | SE and Controller placement rulesSE placement across hosts | 1 | partial |
| 5.3 | Implement elastic HA modes: N+M (default), Active/Active, Legacy Active/Standby | Service Engine HA modesSE sizing and HA choicesConfiguring SE group HA | 2 | covered |
| 5.4 | Configure buffer Service Engines for N+M fault tolerance | — | 0 | gap |
| 5.5 | Perform Controller and SE upgrades with minimal disruption using rolling upgrades | Avi upgrade order and workflow | 2 | covered |
| 5.6 | Configure Global Server Load Balancing (GSLB): sites, DNS virtual services, GSLB services, geo-location policies | GSLB site componentsGSLB design considerationsMulti-site GSLB build | 3 | covered |
| 5.7 | Implement GSLB health monitors for cross-site application availability | — | 0 | gap |
| 5.8 | Configure RBAC with tenant isolation and granular role assignments | Avi tenancy models and rolesMulti-tenant SE groups | 2 | covered |
| 5.9 | Integrate Avi with Kubernetes/OpenShift as ingress controller | — | 0 | gap |
| 5.10 | Perform backup and restore of Controller configuration | Controller configuration backupInfrastructure as code practicesBackup and restore for DR | 2 | covered |
3V0-21.25 — Advanced VMware Cloud Foundation 9.0 Automation
Section 1 — Architecture and Design 15%
Section 2 — Blueprint and Template Design 30%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 2.1 | Author advanced cloud templates using VCF Automation YAML template language with inputs, resources, and outputs | Cloud template YAML structureCloud template capabilities | 1 | partial |
| 2.2 | Design multi-tier application blueprints with compute, network, storage, and load balancer resources | Load balancer resources in templatesMulti-tier template with load balancer | 1 | partial |
| 2.3 | Implement property bindings, conditional resource deployment, and iterative resource creation in blueprints | Cloud template iteration and inputsTemplate resource design patternsConditional inputs and form logic | 3 | covered |
| 2.4 | Configure Cloud Zones with placement policies, tags, capability constraints, and flavor mappings | Cloud zones and capability tagsCloud accounts, zones and profilesConstraints in cloud templatesConfiguring cloud zones and mappings | 3 | covered |
| 2.5 | Design and manage image mappings, flavor mappings, and network profiles for multi-cloud resource abstraction | — | 0 | gap |
| 2.6 | Implement custom naming conventions using naming templates for VMs and resources | — | 0 | gap |
| 2.7 | Configure property groups to share reusable input configurations across multiple blueprints | Reusing inputs across templates | 1 | partial |
| 2.8 | Manage blueprint versioning, release management, and catalog publication workflows | Template versioning and catalog publishContent sharing and versioning | 1 | partial |
| 2.9 | Implement Terraform providers (vsphere, vra, vcfa) for infrastructure-as-code within VCF Automation | Terraform with VCF AutomationIaC integrations in AutomationGitOps pipeline with Terraform | 2 | covered |
Section 3 — Extensibility 15%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 3.1 | Design and implement ABX (Action Based Extensibility) actions in Python, Node.js, or PowerShell | ABX runtimes and container lifecycleABX versus Orchestrator workflowsEvent payload and subscription flow | 3 | covered |
| 3.2 | Configure event subscriptions to trigger ABX actions on lifecycle events (Pre-Provision, Post-Provision, Pre-Decommission) | Provisioning event topicsABX action for CMDB enrichmentTesting and promotion pipelineEvent-driven workflow build | 4 | covered |
| 3.3 | Create and manage vRealize Orchestrator (vRO) workflows for complex multi-step automation | Choosing an extensibility mechanismOrchestrator workflow engine | 1 | partial |
| 3.4 | Implement custom resources with full CRUD lifecycle backed by ABX actions or vRO workflows | Extending Automation with custom code | 1 | partial |
| 3.5 | Design resource actions (Day-2 operations) for deployed resources with approval integration | Approval policies and triggersApproval policy designCatalog with approvals and quotas | 1 | partial |
| 3.6 | Configure integration between VCF Automation and external systems (ServiceNow, CMDB, PagerDuty) via ABX | — | 0 | gap |
Section 4 — Multi-Cloud Governance 20%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 4.1 | Configure multi-organization tenancy in both VM-Apps-Org and All-Apps-Org models | — | 0 | gap |
| 4.2 | Design role-based access control using VCF Automation roles (System Admin, Org Admin, Project Admin, Developer, Viewer) | Built-in roles and their scopesRBAC matrix for self-service | 1 | partial |
| 4.3 | Implement approval policies with multi-level sequential and parallel approval chains | Sequential and tiered approvalsApproval escalation configurationApproval and quota lab | 2 | covered |
| 4.4 | Configure lease policies with automated expiry actions and extension workflows | Lease management behaviourGovernance policy setLease and resource reclamation | 2 | covered |
| 4.5 | Design resource quota management at Organization and Project levels | Quota scopes in the org hierarchyQuota management design | 1 | partial |
| 4.6 | Configure content sharing policies between provider and consumer organizations | Catalog content sharing scopesEntitlements and Service Broker policiesProvider content and org management | 2 | covered |
| 4.7 | Implement VPC-based network isolation for All-Apps-Org tenants using NSX VPC integration | — | 0 | gap |
Section 5 — GitOps and Operations 20%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 5.1 | Configure Git integration for version-controlled blueprint management with auto-import | Git-backed templates and pipelinesContent sources in Service BrokerEnd-to-end GitOps pipelineVersion control integration options | 2 | covered |
| 5.2 | Implement GitOps workflows using ArgoCD for Kubernetes workload delivery through VCF Automation | GitOps tooling in the pipelineGitOps pipeline build | 1 | partial |
| 5.3 | Design CI/CD pipelines integrating Harbor image registry, Git repositories, and VCF Automation catalog | Pipeline tooling in the Automation stackCI/CD for cloud templates | 1 | partial |
| 5.4 | Manage Day-2 lifecycle operations including power management, snapshots, resize, and custom actions | Day-2 operations in AutomationDay-2 actions for consumersConfiguring Day-2 actions | 2 | covered |
| 5.5 | Configure and manage the VCF Automation Service Catalog for self-service consumption | Automation component responsibilitiesService Broker catalog design | 2 | covered |
| 5.6 | Troubleshoot deployment failures using VCF Automation event logs, ABX action logs, and vRO workflow runs | Deployment history and audit trailABX error handling and loggingABX structured logging practiceDeploying and validating templates | 2 | covered |
| 5.7 | Monitor VCF Automation platform health using VCF Operations integration and Fleet Management | — | 0 | gap |
3V0-22.25 — Advanced VMware Cloud Foundation 9.0 Operations
Section 1 — Architecture 15%
Section 2 — Capacity Management 20%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 2.1 | Configure capacity analytics dashboards showing current utilization, reclaimable waste, and time-to-full forecasts | Time-remaining forecastingAdmission control for management clustersAutomation and Operations integrationCapacity projection mathsAdmission control policiesCapacity settings and buffers | 5 | covered |
| 2.2 | Execute what-if analysis scenarios to model workload additions, hardware expansions, and migration impacts | What-if capacity modellingCapacity forecasting basicsWhat-if scenario practice | 2 | covered |
| 2.3 | Identify and reclaim wasted resources: oversized VMs, idle VMs, powered-off VMs, and orphaned VMDKs | Reclaimable capacity categoriesReclaimable capacity analysisRightsizing and reclamation | 2 | covered |
| 2.4 | Configure right-sizing recommendations and implement bulk reclamation projects | Rightsizing recommendation inputsRightsizing report practice | 1 | partial |
| 2.5 | Design cost drivers for chargeback/showback models scoped to datacenters, clusters, or custom groups | Costing, rate cards and driversCost allocation scopesCost settings in Operations | 1 | partial |
| 2.6 | Generate capacity planning reports with time-to-full projections and hardware procurement recommendations | — | 0 | gap |
Section 3 — Performance Analysis 20%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 3.1 | Analyze performance metrics across compute, storage, and network layers using VCF Operations dashboards | Health, risk and efficiency badgesMemory pressure metricsNavigating Operations viewsesxtop memory analysisDashboard hierarchy designDashboard widgets for storage | 3 | covered |
| 3.2 | Identify and resolve performance bottlenecks using correlation analysis between CPU ready, memory balloon, disk latency, and network drops | CPU contention metricsSymptom correlation in alertsesxtop CPU analysisvCPU sizing and overcommitCross-component alert correlationPerformance chart metrics | 3 | covered |
| 3.3 | Configure and interpret heat maps for cluster-level performance visualization | Dashboard widget typesBuilding dashboard widgets | 1 | partial |
| 3.4 | Create custom views and reports for executive performance reporting | Views versus reportsReport scheduling and deliveryScheduled report practice | 1 | partial |
| 3.5 | Design workload optimization strategies using DRS recommendations and VCF Operations insights | DRS and HA dashboard widgetsWorkload optimization and DRS | 2 | covered |
| 3.6 | Analyze vSAN performance metrics including latency percentiles, congestion, cache hit rates, and IOPS distribution | Storage latency distribution analysisvSAN performance metrics | 1 | partial |
Section 4 — Automation and Remediation 20%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 4.1 | Configure alert definitions with symptom definitions, alert criticality, and recommended actions | Symptoms, alerts and recommendationsSymptoms and alertsBuilding alert definitions | 2 | covered |
| 4.2 | Design notification rules using email (SMTP), REST webhooks, SNMP traps, and syslog forwarding | Notification channel typesITSM integration patternsAlerting and notificationsServiceNow integration options | 2 | covered |
| 4.3 | Configure automated remediation actions triggered by alerts using VCF Operations workflows | Automated remediation flowRightsizing and reclamation actionsClosed-loop remediation labAutomated actions and workflowsRightsizing workflow practice | 3 | covered |
| 4.4 | Implement maintenance schedules to suppress alerts during planned maintenance windows | Alert suppression optionsMaintenance windows and suppressionPlanned-change alert handling | 1 | partial |
| 4.5 | Configure VCF Operations automation jobs scoped using custom groups or tags | Policy scoping and overridesCustom groups for policy scopePolicy-driven alerting practice | 1 | partial |
| 4.6 | Design proactive monitoring strategies using anomaly detection and predictive analytics | Dynamic thresholds and baselinesDynamic threshold configuration | 1 | partial |
Section 5 — Custom Content and Compliance 25%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 5.1 | Create advanced custom dashboards with widgets, interactions, and context-driven drill-downs | — | 0 | gap |
| 5.2 | Design and implement super metrics using complex formulas across object hierarchies | Super metric formulasSuper metric recipesSuper metric design lab | 2 | covered |
| 5.3 | Install and configure management packs and content packs from VMware Marketplace | Management pack installationThird-party adaptersExtensibility optionsPAK file handling | 2 | covered |
| 5.4 | Configure VCF Operations for Logs: agents, log forwarding, masking, filtering, retention, and archiving (NFS, object storage) | Log privacy and redaction | 1 | partial |
| 5.5 | Implement compliance monitoring using VMware Security Baselines (CIS), custom benchmarks, and regulatory frameworks (PCI-DSS, HIPAA, NIST) | Compliance frameworks in OperationsCompliance baselines and scoringApplying a benchmarkCIS and STIG benchmarkingCompliance monitoring design | 2 | covered |
| 5.6 | Configure configuration drift detection with baseline templates and automated drift alerts | Configuration drift detectionDrift alerts and baselinesDrift detection lab | 1 | partial |
| 5.7 | Implement AI-assisted log correlation for anomaly detection and cross-component root cause analysis | — | 0 | gap |
| 5.8 | Design custom groups and application models for multi-tier dependency-aware monitoring | Custom group membership rulesCustom group design labGrouping objects for analysis | 1 | partial |
3V0-23.25 — Advanced VMware Cloud Foundation 9.0 Storage
Section 1 — vSAN Architecture 20%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 1.1 | Differentiate between vSAN OSA and vSAN ESA architectures including data path, caching model, and RAID implementations | ESA single-tier vs OSA two-tiervSAN ESA and OSA fundamentals | 1 | partial |
| 1.2 | Describe the vSAN object model: objects, components, witnesses, and their placement across fault domains | vSAN objects and components modelObject health and component states | 1 | partial |
| 1.3 | Explain vSAN ESA single-tier NVMe architecture, log-structured storage engine, and adaptive RAID behavior | vSAN ESA architecture and RAID optionsvSAN ESA and OSA fundamentalsESA vs OSA design deep dive | 2 | covered |
| 1.4 | Describe vSAN OSA disk group architecture: cache tier, capacity tier, write path, and destage operations | OSA disk group compositionESA and OSA architecture comparisonvSAN storage core concepts | 1 | partial |
| 1.5 | Design vSAN Storage Clusters (disaggregated storage) for independent compute and storage scaling | Disaggregated vSAN storage optionsCluster topologies and storage disaggregation | 1 | partial |
| 1.6 | Differentiate between principal and supplemental storage in VCF Workload Domain clusters | Principal vs supplemental storage in VCFVCF storage options overviewExternal storage integration in VCF | 2 | covered |
| 1.7 | Describe the role of vSAN within a Supervisor context for Kubernetes persistent volumes | Kubernetes storage classes on vSANvSAN File Services use casesPersistent volume provisioning practice | 2 | covered |
Section 2 — Storage Policies 20%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 2.1 | Design VM storage policies for different workload tiers using FTT, FTM, IOPS limits, and object space reservation | vSAN storage policy parametersPolicy settings in ESA operations | 1 | partial |
| 2.2 | Differentiate between RAID-1 (mirroring) and RAID-5/6 (erasure coding) in both OSA and ESA contexts | FTT and erasure coding capacity mathvSAN storage policy parametersErasure coding policy designSPBM and FTT host requirements | 3 | covered |
| 2.3 | Calculate storage overhead for different RAID configurations: RAID-1 FTT=1/2/3 and RAID-5/6 in OSA vs. ESA | Raw vs usable capacity calculationsESA vs OSA storage overhead ratiosvSAN capacity sizing math | 1 | partial |
| 2.4 | Configure vSAN encryption policies including data-at-rest and data-in-transit encryption with external KMS | vSAN encryption requirementsvSAN data-at-rest key managementEncryption and hardening practice | 2 | covered |
| 2.5 | Implement IOPS limit policies for noisy-neighbor mitigation in shared clusters | Per-object QoS in storage policiesvSAN storage policy parameters | 1 | partial |
| 2.6 | Configure storage policies for vSAN stretched clusters including PFTT and SFTT parameters | Stretched cluster policy and site affinityStretched cluster design requirementsStretched cluster policy specifics | 2 | covered |
Section 3 — Cluster Operations 20%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 3.1 | Deploy and manage vSAN stretched clusters with witness appliance configuration and site affinity rules | Witness placement in stretched clustersStretched cluster witness roleWitness sizing and placementStretched cluster partition scenarios | 3 | covered |
| 3.2 | Configure vSAN File Services for NFS and SMB file shares with access control | vSAN File Services overviewvSAN data services and file shares | 1 | partial |
| 3.3 | Configure vSAN iSCSI target service for block-level storage access by physical servers | vSAN iSCSI Target Service | 1 | partial |
| 3.4 | Manage host maintenance operations with decommission modes: Ensure Accessibility, Full Data Migration, No Action | Host maintenance mode evacuation optionsvSAN data migration modesObject health and rebuild behaviorHost failure impact on objects | 2 | covered |
| 3.5 | Configure vSAN cross-cluster capacity sharing (HCI Mesh) and vSAN Storage Clusters | HCI Mesh and disaggregated storageCluster storage sharing options | 2 | covered |
| 3.6 | Perform vSAN cluster expansion (add hosts) and contraction (remove hosts) with data migration | Adding hosts and vSAN disk claimvSAN disk lifecycle and rebalancevSAN rebalancing behavior | 1 | partial |
| 3.7 | Configure vSAN data-at-rest and data-in-transit encryption with KMS server integration | — | 0 | gap |
Section 4 — Performance and Capacity 20%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 4.1 | Analyze vSAN performance metrics: read/write IOPS, latency (p50/p90/p99), congestion, and cache hit rate | Cache tier sizing and destage behaviorInterpreting vSAN performance metricsvSAN performance service metrics | 2 | covered |
| 4.2 | Use vSAN IOInsight for detailed I/O profiling: I/O size distribution, queue depth, and read/write ratio | vSAN performance service and observer toolingMirroring vs erasure coding performance trade-offsvSAN performance diagnostics toolsPolicy selection by workload tier | 2 | covered |
| 4.3 | Calculate raw vs. usable capacity for OSA and ESA RAID configurations with compression factors | Mirroring vs erasure coding capacityvSAN capacity sizing math | 1 | partial |
| 4.4 | Design capacity plans using slack space requirements (25-30% free) and time-to-full projections | Slack space in capacity waterfallsvSAN raw-to-usable sizing formulavSAN capacity thresholds and alarms | 2 | covered |
| 4.5 | Configure VCF Operations for vSAN-specific capacity dashboards and what-if analysis | What-if capacity modeling in VCF OperationsCapacity what-if scenario practiceCapacity analytics and scenarios | 1 | partial |
| 4.6 | Implement vSAN-to-vSAN snapshot replication for disaster recovery with configurable RPO | Replication choices and RPO targetsValidated DR and replication design | 1 | partial |
Section 5 — Troubleshooting 20%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 5.1 | Diagnose and resolve vSAN health check failures using Skyline Health and CLI tools | — | 0 | gap |
| 5.2 | Troubleshoot vSAN object non-compliance issues including component placement failures and resync operations | Object compliance and resync statusObject-level component inspection | 1 | partial |
| 5.3 | Diagnose disk failures in OSA (cache and capacity) and ESA configurations and understand rebuild behavior | Disk failure handling and rebuildESA disk failure and rebuild behaviorDisk replacement proceduresvSAN disk failure recovery practiceResync rate and rebuild tuning | 2 | covered |
| 5.4 | Troubleshoot vSAN network partitions and split-brain scenarios in standard and stretched clusters | vSAN network partition diagnosisvSAN quorum and votes in partitionsvSAN health check categories | 2 | covered |
| 5.5 | Resolve vSAN performance bottlenecks including congestion, cache saturation (OSA), and latency spikes | Cache destage and ratio sizingInter-site network requirementsvSAN performance metric interpretationvSAN performance and capacity scenarios | 2 | covered |
| 5.6 | Troubleshoot supplemental storage issues (iSCSI, NFS, FC) in VCF Workload Domain clusters | Separating storage from compute metricsExternal NFS storage integration | 1 | partial |
| 5.7 | Use esxcli vsan, RVC (Ruby vSphere Console), and vSAN Observer for advanced diagnostics | ESXi vSAN CLI command referencevSAN diagnostic tooling in vSphereLow-level vSAN diagnostic commandsvSAN health CLI usage | 3 | covered |
3V0-24.25 — Advanced VMware Cloud Foundation 9.0 vSphere Kubernetes Service
Section 1 — Architecture 15%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 1.1 | Describe the three-layer VKS architecture: Supervisor, vSphere Namespace, and VKS Cluster | VKS architecture layersSupervisor and namespace design | 1 | partial |
| 1.2 | Explain Spherelet and CRX (Container Runtime Executive) for vSphere Pods on ESXi | Spherelet and vSphere PodsSupervisor component roles | 1 | partial |
| 1.3 | Describe Supervisor Control Plane VM deployment, sizing (Tiny/Small/Medium/Large), and HA configuration | Supervisor control plane availabilitySupervisor control plane sizingSupervisor cluster topology | 3 | covered |
| 1.4 | Differentiate between NSX-backed and VDS-backed Supervisor networking models | Supervisor networking backingsNSX networking validation labWorkload Management networking setup | 1 | partial |
| 1.5 | Explain Supervisor Services framework: VKS, Contour, Harbor, External-DNS, and LCI | — | 0 | gap |
| 1.6 | Describe Cluster API (CAPI) and CAPV (Cluster API Provider vSphere) for VKS cluster lifecycle management | Cluster API cluster lifecycleProvisioning clusters via ClusterClass | 1 | partial |
Section 2 — Cluster Lifecycle 25%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 2.1 | Provision VKS clusters using declarative YAML with ClusterClass and MachineDeployment specifications | — | 0 | gap |
| 2.2 | Scale VKS clusters horizontally by modifying MachineDeployment replicas and adding node pools | Node pool scaling objectsClusterClass topology manifestVKS cluster lifecycle lab | 2 | covered |
| 2.3 | Configure Kubernetes Cluster Autoscaler with min/max annotations on MachineDeployments | Cluster Autoscaler on node poolsCluster provisioning with autoscaling | 2 | covered |
| 2.4 | Manage Tanzu Kubernetes Releases (TKRs): check availability, upgrade clusters, and handle air-gapped environments | Content library and TKR imagesContent library prerequisites | 2 | covered |
| 2.5 | Implement MachineHealthCheck for automated node health monitoring and remediation | Machine health checks in ClusterClass | 2 | covered |
| 2.6 | Perform VKS cluster upgrades following the Supervisor > TKR > VKS Cluster upgrade order | Kubernetes version lifecycleVCF component upgrade sequenceContent library TKR subscriptionTKR version upgrade lab | 3 | covered |
| 2.7 | Manage VM Operator and VM Service classes for VKS worker node specifications | VM Service and VM ClassesDeploy a VM via VM ServiceNamespace resource classes | 2 | covered |
Section 3 — Networking 20%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 3.1 | Configure Antrea CNI including NetworkPolicies, AntreaNetworkPolicies, and ClusterNetworkPolicies | NetworkPolicy enforcement labAntrea CNI and network policy | 2 | covered |
| 3.2 | Explain NSX integration with VKS: dedicated Tier-1 gateways and segments per namespace | NSX-backed namespace networkingNSX segment and gateway validation | 1 | partial |
| 3.3 | Configure Service types: ClusterIP, NodePort, and LoadBalancer with Avi NSX ALB integration | Kubernetes service types and LBLoadBalancer service with AviNSX LB versus Avi ALBNSX networking validation lab | 2 | covered |
| 3.4 | Implement Ingress resources with Contour and Envoy proxy for HTTP/HTTPS path-based routing | Supervisor Services catalogIngress controller integration lab | 2 | covered |
| 3.5 | Design VKS Supervisor networking with NSX VPC and Centralized Transit Gateway (CTGW) | NSX VPC and Project constructsVPC construct lab | 2 | covered |
| 3.6 | Implement Antrea Traceflow for live packet tracing and network troubleshooting | NSX Traceflow packet walk | 1 | partial |
Section 4 — Storage 15%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 4.1 | Configure the vSphere CSI driver for dynamic persistent volume provisioning from vSAN | vSphere CSI and StorageClassPVC provisioning lab | 1 | partial |
| 4.2 | Design StorageClasses referencing vSAN storage policies with appropriate access modes (RWO, RWX, ROX) | vSAN file services access modesPVC provisioning lab | 1 | partial |
| 4.3 | Implement ReadWriteMany volumes using vSAN File Services for shared workloads | vSAN file services access modesPVC provisioning lab | 1 | partial |
| 4.4 | Configure volume snapshots and volume expansion for stateful applications | Volume snapshot and restore labvSphere CSI storage architecture | 3 | covered |
| 4.5 | Explain Cloud Native Storage (CNS) architecture and the PVC-to-VMDK provisioning workflow | vSphere CSI storage architecturePVC provisioning lab | 1 | partial |
Section 5 — Security and Operations 25%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 5.1 | Configure vSphere SSO integration with VKS clusters including Viewer, Editor, and Owner permission levels | — | 0 | gap |
| 5.2 | Implement external identity providers (LDAP, OIDC) using Pinniped for Kubernetes authentication | VKS identity and SSO integrationNamespace access control design | 2 | covered |
| 5.3 | Configure Pod Security Admission (PSA) with privileged, baseline, and restricted policy levels | Pod security and DFW labMulti-tenant isolation controls | 2 | covered |
| 5.4 | Deploy and manage Harbor as a private container image registry with vulnerability scanning | Supervisor Services catalogRegistry and ingress services | 2 | covered |
| 5.5 | Implement Velero for VKS cluster backup and restore including PV snapshot support | Backup with VeleroSupervisor Services catalogBackup before upgrade labSnapshot and restore lab | 2 | covered |
| 5.6 | Configure Prometheus and Grafana for VKS cluster monitoring and alerting | Kubernetes metrics collection | 1 | partial |
| 5.7 | Troubleshoot common VKS issues: cluster provisioning failures, pending pods, PVC binding, LoadBalancer allocation | Supervisor troubleshooting patternsPVC provisioning labLoadBalancer service with Avi | 2 | covered |
| 5.8 | Implement RBAC with Roles, ClusterRoles, RoleBindings, and ClusterRoleBindings for fine-grained access | Namespace RBAC and SSONamespace permissions design | 2 | covered |
3V0-25.25 — Advanced VMware Cloud Foundation 9.0 Networking
Section 1 — Architecture 15%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 1.1 | Describe NSX architecture across management plane (NSX Manager cluster), control plane (Central Control Plane), and data plane (ESXi TEPs, N-VDS, OVS) | — | 0 | gap |
| 1.2 | Explain transport node architecture including TEP (Tunnel End Points), transport zones (overlay and VLAN), and N-VDS internals | Transport zones and segment typesTEP addressing and connectivityCreate overlay segment | 2 | covered |
| 1.3 | Describe Geneve encapsulation format, BFD tunnel monitoring, and overlay-to-underlay requirements (MTU >= 1600) | Overlay MTU and fabric sizingBFD and tunnel liveness checksTEP and overlay path checksGeneve encapsulation and MTU validationGeneve overlay segmentsTunnel endpoint verification | 3 | covered |
| 1.4 | Differentiate between NSX Manager cluster roles: Manager, Policy, Controller | NSX management and control planesManager cluster diagnostics | 1 | partial |
| 1.5 | Explain DPU-based acceleration for NSX data plane offloading | Dataplane acceleration on NSXDPDK-accelerated Edge cluster | 1 | partial |
Section 2 — Routing Design 25%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 2.1 | Design Tier-0 gateway HA modes: Active-Active (ECMP) vs. Active-Standby and determine appropriate mode for given scenarios | Tier-0 HA modesECMP north-south scalingBuild T0/T1 routing topology | 1 | partial |
| 2.2 | Configure advanced BGP: route maps, prefix lists, community attributes, AS path manipulation, and BFD timers | BGP inbound route filteringBFD timers and BGP convergenceBGP route maps and policiesAdvanced BGP policy engineering | 4 | covered |
| 2.3 | Design ECMP topologies with multiple Edge nodes peering with physical ToR switches | ECMP path loss and throughputEdge failure scenario matrix | 1 | partial |
| 2.4 | Configure OSPF areas, route redistribution, and inter-area routing on Tier-0 gateways | OSPF on Tier-0 gatewaysOSPF areas and redistribution | 2 | covered |
| 2.5 | Design NSX Federation with Global Manager and Local Managers for multi-site network management | NSX Federation componentsFederation Global/Local ManagersFederation across two instancesMulti-site federation design | 2 | covered |
| 2.6 | Implement VRF gateways for multi-tenant routing isolation on shared Tier-0 infrastructure | VRF-Lite on a shared Tier-0VRF isolation and route leaking | 2 | covered |
| 2.7 | Design advanced Tier-0 patterns: single centralized, dedicated management/workload, VPC-based, and multi-tenant with Projects | Projects and VPC multi-tenancyVPC construct in VCF 9.0Tenant routing isolation options | 1 | partial |
Section 3 — Security Services 20%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 3.1 | Design and implement vDefend Distributed Firewall policies for east-west micro-segmentation | Distributed Firewall enforcement pointFederation and consistent DFW policyGlobal versus local security policyKernel-level DFW enforcementLocation-aware DFW across sitesLateral security validated design | 2 | covered |
| 3.2 | Configure Gateway Firewall rules for north-south perimeter security on Tier-0 and Tier-1 gateways | Gateway Firewall scopeDFW versus Gateway Firewall | 1 | partial |
| 3.3 | Implement Distributed IDS/IPS with signature management, alert modes, and block modes | IDS/IPS modes and actionsScoping IDS/IPS profiles and rulesDetection versus prevention mode | 2 | covered |
| 3.4 | Configure URL filtering, Network Detection and Response (NDR), and malware prevention services | URL filtering and gateway featuresMalware prevention on NSXNDR and cloud analysis | 2 | covered |
| 3.5 | Design security group membership using VM tags, OS type, cluster, and dynamic criteria | Dynamic groups and tag criteriaGroup membership and rule realizationDFW policy with tags and groupsPolicy realization and convergence | 2 | covered |
| 3.6 | Implement Global IDS/IPS policy management in NSX Federation environments | Federated security policy scopeIDS/IPS design and deployment | 1 | partial |
Section 4 — Load Balancing and Network Services 15%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 4.1 | Deploy and manage NSX VPC with Centralized and Distributed Transit Gateways | VPC and Transit Gateway constructsVPC connectivity model | 1 | partial |
| 4.2 | Configure VPC subnet types: Public, Private-VPC, and Private-Transit Gateway | VPC subnet types and NATVPC networking constructs | 1 | partial |
| 4.3 | Design NSX Projects for multi-tenant management with isolated Tier-1 gateways and segments | VPC and Project self-service modelCreate Projects, VPCs and subnets | 1 | partial |
| 4.4 | Configure stateful services: NAT (SNAT/DNAT/Reflexive), DHCP, DNS, IPSec VPN, and L2 VPN on NSX gateways | Tier-1 services including NATL2 VPN and segment stretchingNAT on the routing topology | 3 | covered |
| 4.5 | Implement NSX-backed Supervisor networking for VKS with VPC and CTGW integration | NSX networking for SupervisorVPC constructs in VCF 9.0Validate NSX networking for VKS | 1 | partial |
Section 5 — Troubleshooting 25%
| # | Objective | Where it is covered | Quiz | Coverage |
|---|---|---|---|---|
| 5.1 | Use NSX Traceflow to diagnose connectivity issues and identify firewall rule matches | DFW troubleshooting first stepsInterpreting Traceflow observationsDFW rule debugging with Traceflow | 2 | covered |
| 5.2 | Analyze packet walks for east-west (same host, cross-host) and north-south (VM to Internet) traffic flows | — | 0 | gap |
| 5.3 | Troubleshoot overlay tunnel failures using TEP connectivity checks, MTU validation, and BFD status | TEP and tunnel failure causesNSX connectivity troubleshootingMTU validation across the path | 2 | covered |
| 5.4 | Diagnose BGP peering issues: ASN mismatch, wrong neighbor IP, firewall blocking, route advertisement problems | BGP neighbor state diagnosisBGP peering on NSX Edges | 2 | covered |
| 5.5 | Use Edge node CLI commands for routing table inspection, BGP neighbor status, and service health checks | Edge node CLI commands | 1 | partial |
| 5.6 | Troubleshoot NAT, DHCP, VPN, and load balancer configuration issues | Load balancer health monitor checksNAT and gateway rule checksGateway Firewall and NAT orderDNAT on Tier-1 gatewaysLoad balancing validated design | 3 | covered |
| 5.7 | Configure and analyze IPFIX flow data and port mirroring for traffic visibility | IPFIX flow export configurationFlow telemetry and collectors | 3 | covered |