Academy/VVS/Intelligent Ops Management
This solution targets VCF 5.2

Intelligent Operations Management for VMware Cloud Foundation

VCF 5.2architectvcdxadminautomationcloud-opsPages 338-435

VMware Cloud Foundation Operations (formerly vRealize Operations / Aria Operations) provides a centralized monitoring and alerting platform that delivers proactive management of system failures. The solution consists of an analytics cluster (primary + primary replica + data node, scale-out up to 8 nodes) for data analysis and storage, and VMware Cloud Proxy appliances that perform local metric collection per VMware Cloud Foundation instance and forward data to the analytics cluster. Data source integrations include VMware Cloud Foundation, NSX, vCenter Server, vSAN, Workspace ONE Access, and Ping. The design supports single-instance, multi-AZ, and multi-instance topologies.

Key Components: NSX, Aria Operations, Aria Automation, SDDC Manager, vCenter, ESXi, VCF Operations, Workspace ONE

Multi AZ: Analytics nodes run in first AZ. DRS VM/Host rule binds them to AZ1 host group. VMware Cloud Proxies also pinned to AZ1.

Design Decisions
Implementation
Operations
VCDX Defense
Quiz (15)
Flashcards (15)

48 design decisions

DD-IDDecisionQuality
IOM-VAOPS-SEC-005), custom vCenter role with minimum privileges for cloud account, NSX Principal Identity using clienManageabilitySecurity

Decision: ), custom vCenter role with minimum privileges for cloud account, NSX Principal Identity using client certificate (Enterprise Admin role) for each NSX Local Manager — removes need to manage password.

Rationale: Password ManagementRoot and admin passwords rotated via SDDC Manager UI or API (not through Aria Suite Lifecycle) since the product is in VCF mode.

Implication: CertificatesCA-signed certificate with analytics and Cloud Proxy FQDNs in SAN; SHA-2 or higher; must be replaced when new nodes are add

Component: VAOPS

IOM-VAOPS-CFG-001Deploy VCF Operations as a 3-node cluster (primary + primary replica + data node) in the default manManageability

Decision: Deploy VCF Operations as a 3-node cluster (primary + primary replica + data node) in the default management vSphere cluster.

Rationale: Scale capacity for up to 12,000 VMs/objects; supports scale-out.

Implication: All nodes must be sized identically, increasing resource requirements.

Component: VAOPS

IOM-VAOPS-CFG-002Deploy two VMware Cloud Proxy appliances in the default management vSphere cluster.Manageability

Decision: Deploy two VMware Cloud Proxy appliances in the default management vSphere cluster.

Rationale: Removes metric collection load from analytics cluster.

Implication: You must assign a collector group when configuring monitoring.

Component: VAOPS

IOM-VAOPS-CFG-003Use the VMware Aria Suite Lifecycle instance in the corresponding VCF instance to deploy Operations.Manageability

Decision: Use the VMware Aria Suite Lifecycle instance in the corresponding VCF instance to deploy Operations.

Rationale: Aria Suite Lifecycle manages product binaries; SDDC Manager auto-configures load balancer when in VCF mode.

Implication: Must deploy Aria Suite Lifecycle via SDDC Manager.

Component: VAOPS

IOM-VAOPS-CFG-004Protect all VCF Operations nodes with vSphere HA.AvailabilityManageability

Decision: Protect all VCF Operations nodes with vSphere HA.

Rationale: Supports availability objective without manual intervention.

Implication: No significant trade-offs identified for this decision.

Component: VAOPS

IOM-VAOPS-CFG-005Apply DRS anti-affinity rule to analytics cluster VMs.Manageability

Decision: Apply DRS anti-affinity rule to analytics cluster VMs.

Rationale: Prevents co-location on same ESXi host.

Implication: Must be updated when data nodes are added; in a 4-host cluster only one host can be in maintenance at a time.

Component: VAOPS

IOM-VAOPS-CFG-009Enable data persistence on all Cloud Proxy appliances.AvailabilityManageability

Decision: Enable data persistence on all Cloud Proxy appliances.

Rationale: Provides buffering during connectivity issues.

Implication: Monitor storage availability on each Cloud Proxy.

Component: VAOPS

IOM-VAOPS-CFG-010In multi-AZ, add Operations VMs to first AZ VM group.Manageability

Decision: In multi-AZ, add Operations VMs to first AZ VM group.

Rationale: Ensures VMs power on within AZ1 host group.

Implication: If Operations deployed after stretched cluster creation, VM group must be updated.

Component: VAOPS

IOM-VAOPS-CFG-011In multi-instance, deploy two Cloud Proxies per instance using first instance's Aria Suite LifecycleManageability

Decision: In multi-instance, deploy two Cloud Proxies per instance using first instance's Aria Suite Lifecycle.

Rationale: Localizes collection; consistent deployment.

Implication: Must assign collector groups.

Component: VAOPS

IOM-VAOPS-CFG-014Deploy analytics nodes as medium-size appliances.AvailabilityManageability

Decision: Deploy analytics nodes as medium-size appliances.

Rationale: Capacity for 12,000 objects with HA active; metrics from vCenter, ESXi, NSX, Aria Automation, Aria Operations for Logs.

Implication: Requires 24 vCPU / 96 GB total; ESXi hosts need 8+ cores per socket; scale up via Aria Suite Lifecycle when > 12,000 objects.

Component: VAOPS

IOM-VAOPS-CFG-016Increase initial storage per analytics node by 700 GB.Manageability

Decision: Increase initial storage per analytics node by 700 GB.

Rationale: Supports 12,000 objects, 20% growth, 6-month retention.

Implication: No significant trade-offs identified for this decision.

Component: VAOPS

IOM-VAOPS-CFG-017Deploy each Cloud Proxy as small-size.Manageability

Decision: Deploy each Cloud Proxy as small-size.

Rationale: Supports up to 8,000 objects per proxy; proxies don't store data.

Implication: 2 vCPUs/8 GB RAM reserved per proxy.

Component: VAOPS

IOM-VAOPS-CFG-018Configure outbound SMTP mail server for notifications.Manageability

Decision: Configure outbound SMTP mail server for notifications.

Rationale: Email delivery of system events.

Implication: Must maintain an SMTP server.

Component: VAOPS

IOM-VAOPS-CFG-019Set the currency in Operations global options based on organization requirements.Manageability

Decision: Set the currency in Operations global options based on organization requirements.

Rationale: Ensures accurate costing; Aria Automation integration uses this currency.

Implication: Currency cannot be changed after initial configuration.

Component: VAOPS

IOM-VAOPS-NET-001Place analytics nodes on cross-instance NSX segment.Manageability

Decision: Place analytics nodes on cross-instance NSX segment.

Rationale: Supports multi-instance DR growth.

Implication: Requires NSX overlay implementation.

Component: VAOPS

IOM-VAOPS-NET-002Place Cloud Proxies on local-instance NSX segment.Manageability

Decision: Place Cloud Proxies on local-instance NSX segment.

Rationale: Collect metrics locally per VCF instance.

Implication: Requires NSX overlay implementation.

Component: VAOPS

IOM-VAOPS-NET-008Use small-size NSX load balancer on dedicated Tier-1 gateway (shared with Workspace ONE Access).Manageability

Decision: Use small-size NSX load balancer on dedicated Tier-1 gateway (shared with Workspace ONE Access).

Rationale: Deploys Operations analytics cluster with distributed UI access.

Implication: Must use the NSX LB configured by SDDC Manager.

Component: VAOPS

IOM-VAOPS-NET-009Do NOT use a load balancer for Cloud Proxies.Manageability

Decision: Do NOT use a load balancer for Cloud Proxies.

Rationale: Proxies must directly access monitored systems; don't require public access.

Implication: No significant trade-offs identified for this decision.

Component: VAOPS

IOM-VAOPS-LCM-001Use VMware Aria Suite Lifecycle for all LCM of Operations.Manageability

Decision: Use VMware Aria Suite Lifecycle for all LCM of Operations.

Rationale: Manages product binaries and upgrades.

Implication: Must deploy Aria Suite Lifecycle via SDDC Manager; includes patches, updates, hotfixes.

Component: VAOPS

IOM-VAOPS-CFG-020Activate VMware Cloud Foundation integration in Operations.Manageability

Decision: Activate VMware Cloud Foundation integration in Operations.

Rationale: Enables cloud accounts for SDDC Manager, vCenter, vSAN, NSX.

Implication: Manual activation.

Component: VAOPS

IOM-VAOPS-CFG-021Activate VMware Identity Manager integration.Manageability

Decision: Activate VMware Identity Manager integration.

Rationale: Operations communicates with Workspace ONE Access.

Implication: Installed/activated by SDDC Manager.

Component: VAOPS

IOM-VAOPS-CFG-022Activate VMware Infrastructure Health integration.Manageability

Decision: Activate VMware Infrastructure Health integration.

Rationale: Unified operations view and health of management components.

Implication: Must configure a VCF cloud account first; manual activation.

Component: VAOPS

IOM-VAOPS-CFG-023Activate Ping integration.Availability

Decision: Activate Ping integration.

Rationale: Endpoint availability metrics.

Implication: Manual activation.

Component: VAOPS

IOM-VAOPS-CFG-024Remove the existing vCenter Server cloud account created by SDDC Manager.Manageability

Decision: Remove the existing vCenter Server cloud account created by SDDC Manager.

Rationale: Not used when using the VCF integration.

Implication: Must manually remove.

Component: VAOPS

IOM-VAOPS-CFG-025Remove existing Principal Credential for vCenter created by SDDC Manager.Manageability

Decision: Remove existing Principal Credential for vCenter created by SDDC Manager.

Rationale: Replaced by service-account-based credential.

Implication: Must manually remove.

Component: VAOPS

IOM-VAOPS-CFG-026Configure SDDC Manager credential per VCF instance using least-privilege AD service account.Manageability

Decision: Configure SDDC Manager credential per VCF instance using least-privilege AD service account.

Rationale: Required to collect SDDC Manager domain and metric data.

Implication: Maintain lifecycle of service account.

Component: VAOPS

IOM-VAOPS-CFG-027Configure a VCF cloud account per VCF instance assigned to local-instance collector group.Manageability

Decision: Configure a VCF cloud account per VCF instance assigned to local-instance collector group.

Rationale: Metric collection for SDDC Manager and workload domains.

Implication: Manual creation.

Component: VAOPS

IOM-VAOPS-CFG-028Configure Principal Credential for each workload domain vCenter using least-privilege AD service accManageability

Decision: Configure Principal Credential for each workload domain vCenter using least-privilege AD service account.

Rationale: Required to collect vCenter metric data.

Implication: Maintain service account lifecycle.

Component: VAOPS

IOM-VAOPS-CFG-029Configure vCenter cloud account per workload domain assigned to local-instance collector group.Manageability

Decision: Configure vCenter cloud account per workload domain assigned to local-instance collector group.

Rationale: Metric collection for vCenter.

Implication: Manual creation.

Component: VAOPS

IOM-VAOPS-CFG-030Enable vSAN cloud account per workload domain.Manageability

Decision: Enable vSAN cloud account per workload domain.

Rationale: Metric collection from vSAN clusters.

Implication: Shared service account increases connectivity fault risk.

Component: VAOPS

IOM-VAOPS-CFG-031Configure NSX Client Certificate credential per NSX Manager with least privilege.ManageabilitySecurity

Decision: Configure NSX Client Certificate credential per NSX Manager with least privilege.

Rationale: Required to collect NSX metrics.

Implication: Manage certificates and private keys.

Component: VAOPS

IOM-VAOPS-CFG-032Configure NSX cloud account per workload domain NSX Manager assigned to local-instance collector groManageability

Decision: Configure NSX cloud account per workload domain NSX Manager assigned to local-instance collector group.

Rationale: Metric collection for NSX Manager.

Implication: Manual credential addition.

Component: VAOPS

IOM-VAOPS-CFG-033Configure VMware Identity Manager cloud account for clustered Workspace ONE Access using default colManageability

Decision: Configure VMware Identity Manager cloud account for clustered Workspace ONE Access using default collector group.

Rationale: Metric collection from WS1 Access.

Implication: Configured by SDDC Manager.

Component: VAOPS

IOM-VAOPS-CFG-034Configure Ping cloud account for analytics cluster nodes (default collector group).Availability

Decision: Configure Ping cloud account for analytics cluster nodes (default collector group).

Rationale: Availability metrics for analytics cluster.

Implication: Manual addition.

Component: VAOPS

IOM-VAOPS-CFG-035Configure Ping cloud account for Cloud Proxy appliances (local-instance collector group).Availability

Decision: Configure Ping cloud account for Cloud Proxy appliances (local-instance collector group).

Rationale: Availability metrics for proxies.

Implication: Manual addition.

Component: VAOPS

IOM-VAOPS-CFG-037Define alerts for application/VM/container, VI/ESXi host, SDN, and storage.Manageability

Decision: Define alerts for application/VM/container, VI/ESXi host, SDN, and storage.

Rationale: Detect conditions endangering workloads, infrastructure, NSX, vSAN/disk storage.

Implication: Individual alerts may need manual creation/maintenance.

Component: VAOPS

IOM-VAOPS-SEC-001Activate Operations integration with corporate identity via clustered Workspace ONE Access.ManageabilityRecoverabilitySecurity

Decision: Activate Operations integration with corporate identity via clustered Workspace ONE Access.

Rationale: Enables AD authentication (incl. MFA) and authorization via roles.

Implication: Must deploy clustered WS1 Access.

Component: VAOPS

IOM-VAOPS-SEC-002Assign Administrator, ContentAdmin, ReadOnly roles to Active Directory security groups.ManageabilitySecurity

Decision: Assign Administrator, ContentAdmin, ReadOnly roles to Active Directory security groups.

Rationale: Managed access, auditability.

Implication: Maintain AD security groups outside SDDC stack.

Component: VAOPS

IOM-VAOPS-SEC-006Define custom vCenter role with minimum privileges for vCenter cloud account.Manageability

Decision: Define custom vCenter role with minimum privileges for vCenter cloud account.

Rationale: Least privilege.

Implication: Maintain role; apply to each SSO domain if multiple.

Component: VAOPS

IOM-VAOPS-SEC-007Assign custom vCenter role to AD service account per workload domain vCenter.Manageability

Decision: Assign custom vCenter role to AD service account per workload domain vCenter.

Rationale: Integration and data collection with minimal privileges.

Implication: Maintain service account.

Component: VAOPS

IOM-VAOPS-SEC-008Use vCenter service account also for vSAN data collection (no separate credentials).Manageability

Decision: Use vCenter service account also for vSAN data collection (no separate credentials).

Rationale: vSAN uses vCenter credentials.

Implication: No significant trade-offs identified for this decision.

Component: VAOPS

IOM-VAOPS-SEC-009Create NSX Principal Identity with Enterprise Admin role per NSX Local Manager.ManageabilitySecurity

Decision: Create NSX Principal Identity with Enterprise Admin role per NSX Local Manager.

Rationale: Certificate-based auth removes password management.

Implication: Manage certificates and private keys.

Component: VAOPS

IOM-VAOPS-SEC-010Configure password expiration, complexity, and account lockout policies on Operations and Cloud ProxManageability

Decision: Configure password expiration, complexity, and account lockout policies on Operations and Cloud Proxy appliances.

Rationale: Align with organizational/compliance standards; applies only to local users.

Implication: Manage via appliance console or SSH.

Component: VAOPS

IOM-VAOPS-SEC-013Change Operations and Cloud Proxy root password on schedule via SDDC Manager UI/API.Manageability

Decision: Change Operations and Cloud Proxy root password on schedule via SDDC Manager UI/API.

Rationale: In VCF mode, root password is managed by SDDC Manager, not Aria Suite Lifecycle.

Implication: Use SDDC Manager for rotation.

Component: VAOPS

IOM-VAOPS-SEC-014Change Operations admin account password via SDDC Manager UI/API.Manageability

Decision: Change Operations admin account password via SDDC Manager UI/API.

Rationale: Admin password managed by SDDC Manager in VCF mode.

Implication: Routine rotation via SDDC Manager.

Component: VAOPS

IOM-VAOPS-SEC-015Use CA-signed certificate with analytics and Cloud Proxy FQDNs in SAN when deploying Operations.ManageabilitySecurity

Decision: Use CA-signed certificate with analytics and Cloud Proxy FQDNs in SAN when deploying Operations.

Rationale: Encrypts external UI/API traffic.

Implication: Must replace when adding nodes.

Component: VAOPS

IOM-VAOPS-SEC-016Use SHA-2 or higher.Manageability

Decision: Use SHA-2 or higher.

Rationale: SHA-1 deprecated.

Implication: Not all CAs support SHA-2.

Component: VAOPS

IOM-VAOPS-LOG-001Use Aria Operations for Logs content pack; forward logs to VAOL VIP using ingestion API port 9000 wiManageabilitySecurity

Decision: Use Aria Operations for Logs content pack; forward logs to VAOL VIP using ingestion API port 9000 with ssl=no; dedicated Photon OS agent group.

Rationale: Enables cross-instance log forwarding during DR without certificate mismatch issues.

Implication: Log transmission is unencrypted.

Component: VAOPS

Prerequisites

  • VCF version listed in Support Matrix (5.2.1, 5.2.0, 5.1.1, 5.1.0).

Implementation Procedure

Implementation

Captured parameters in Intelligent Operations Management tab of the VCF Planning & Preparation Workbook.

Downloaded Workspace ONE Access OVA, VMware Cloud Foundation Operations OVA, and Cloud Proxy OVA from Broadcom Support Portal.

Aria Suite Lifecycle or VCF Operations license with sufficient quantity.

Required forward/reverse DNS records created.

Active Directory Domain Controllers, service accounts, and security groups created.

Microsoft Certificate Authority available; OpenSSL 3.0+ installed for PowerShell module execution.

PowerShell 7.2+ for automated implementation.

Implementation Methods

Powershell

Install-Module PowerValidatedSolutions (+ PowerCLI, SsoAdmin, PowerVCF, ImportExcel). Run Start-ValidatedSolutionMenu; choose '07. (IOM) Intelligent Operations Management'. Submenu options: 01 Generate JSON Spec, 02 Verify Prerequisites, 03 Generate Certificate from Microsoft CA, 05 End-to-End Deployment, 07 Configuration (interoperability).

UI

Per VCF version-specific table (VCF 5.2.1 shown): 1) Download Aria Suite Lifecycle 8.18.0 install bundle via SDDC Manager (or Bundle Transfer Utility for disconnected). 2) Deploy Aria Suite Lifecycle via SDDC Manager. 3) Replace Aria Suite Lifecycle certificate with CA-signed. 4) Apply PSPACK3 to Aria Suite Lifecycle. 5) Create vSphere Content Library to host Operations OVA. 6) Configure cross-instance datacenter + management vCenter in Aria Suite Lifecycle. 7) Import Workspace ONE Access certificate. 8) Add Workspace ONE Access passwords. 9) Deploy clustered Workspace ONE Access via Aria Suite Lifecycle (3-node global environment). 10) Configure anti-affinity rule and VM group for WS1 Access. 11-12) Configure NTP, domain, domain search. 13) Configure AD identity source. 14) Add WS1 Access nodes as identity provider connectors. 15-16) Assign AD groups to WS1 Access and Aria Suite Lifecycle roles.

Then create Content Library for Operations, import Operations OVA/OVF, deploy Operations cluster from Aria Suite Lifecycle (which triggers SDDC Manager to configure the NSX LB). Deploy Cloud Proxies, configure cloud accounts (SDDC Manager, vCenter, NSX using Principal Identity cert, vSAN, WS1 Access, Ping), activate integrations (VCF, VMware Identity Manager, VMware Infrastructure Health, Ping), configure notifications, costing, alerts.

External Services / Integration Points

Active Directory (AD)

DNS

NTP

Microsoft Certificate Authority (CA)

SMTP

LLDP or CDP on network devices

Configuration Values

Load Balancer Monitor URL/suite-api/api/deployment/node/status?services=api&services=adminui&services=ui
Session Persistence Timeout1800 seconds (30 minutes)

Notification FlowAlert Definitions → Notifications → Standard Email Plug-In (outbound SMTP) → payload template

vSphere Content LibraryUsed to synchronize the Operations OVA across VI workload domains for image mapping by Aria Automation (cross-solution)
Power Shell Menu ID07

Additional Instance

For additional VCF instance, extend the Operations implementation by deploying two additional Cloud Proxy appliances in each additional instance. Steps: (1) Prepare NSX Principal Identity in each NSX Manager. (2) Configure credentials for SDDC components. (3) Create cloud accounts assigned to the instance's local collector group. (4) Configure integrations. (5) Add Ping adapters for the new nodes.

Day-2 Operations Tasks

Operations

As needed

Personas

As needed

NameRole

As needed

Cloud AdminVCF Operations Administrator

As needed

AdministratorVCF Operations Administrator

As needed

Content AdministratorVCF Operations Content Admin — dashboards/views/reports/groups

As needed

Read-only UserVCF Operations Read Only

As needed

Operational Verification

As needed

Certificate Management

As needed

Generate CA-signed cert via PowerValidatedSolutions; add to Aria Suite Lifecycle locker; replace on Operations; if Aria Automation is integrated, re-t

As needed

Monitoring Points

  • Authenticate with local admin — verify Cluster Status = Online, HA = Activated.
  • Authenticate via AD user through vIDMAuthSource — verify access matches role.
  • Verify Authentication Sources → clustered WS1 Access shows successful Test connection.
  • Verify each adapter Status = OK: VCF cloud account, vCenter, vSAN, NSX, WS1 Access, Ping.
  • Verify Capacity → Assess shows 'All clusters have sufficient capacity'.

Troubleshooting

DRDeployed on cross-instance segment; supports failover between VCF instances via SRM/vSphere Replication (covered in Site Protection and DR VVS).
Cause:
Fix:

Likely Panelist Questions

Q: Why did you choose this architecture?

See design decisions for rationale

Failure Scenarios

Place analytics cluster on cross-instance NSX segment to allow future multi-instance DR failover without IP renumbering.
Impact:
Mitigation:
Pinning analytics/proxies to AZ1 via DRS VM/Host rules keeps data path short but means AZ2 failure doesn't automatically rebalance workload.
Impact:
Mitigation:
Site Protection and DR VVS failovers analytics cluster via SRM + vSphere Replication.
Impact:
Mitigation:

Trade-off Analysis

Trade-Offs Analysis

Chosen:

Justification:

Managing root password via Aria Suite Lifecycle UI instead of SDDC Manager when in VCF mode.

Chosen:

Justification:

Quiz — Intelligent Ops Management

0/15
Q1
In IOM-VAOPS-CFG-001, how many nodes form the analytics cluster and what roles do they have?
  • Two nodes: one primary, one data
  • Three nodes: one primary, one primary replica, one data
  • Four nodes: two primary, two data
  • One monolithic node with HA
The validated solution deploys a 3-node cluster: primary, primary replica, and data node. This supports HA and scale-out up to 8 nodes.
Q2
Which port and setting does VCF Operations use to forward logs to Aria Operations for Logs?
  • 9543 with ssl=yes
  • 9000 with ssl=no (cfapi)
  • 514 with ssl=yes
  • 443 with ssl=auto
IOM-VAOPS-LOG-004 uses the cfapi port 9000 with ssl=no to support DR scenarios where certificates may mismatch after failover.
Q3
Why must Operations timezone be set to UTC?
  • It's the only timezone that Aria Suite Lifecycle supports
  • VMware Aria Automation supports only UTC
  • NSX requires UTC for logging
  • vSAN requires UTC
IOM-VAOPS-NET-011 states UTC is required for Aria Automation integration.
Q4
Which appliance size is chosen for the analytics cluster by default and what are its resources?
  • Small — 4 vCPU / 16 GB
  • Medium — 8 vCPU / 32 GB
  • Large — 16 vCPU / 48 GB
  • Extra Large — 24 vCPU / 128 GB
Medium is the default: 8 vCPU, 32 GB RAM, 274 GB initial + 700 GB added storage.
Q5
How is the NSX load balancer for VCF Operations configured?
  • Manually via NSX UI
  • Automatically by SDDC Manager when deployed via Aria Suite Lifecycle in VCF mode
  • Via a PowerCLI script
  • Via a Terraform module
SDDC Manager automates the LB configuration on a dedicated NSX Tier-1 gateway; shared with Workspace ONE Access (IOM-VAOPS-NET-008).
Q6
What integration method is recommended for NSX Manager in VCF Operations?
  • Local admin password
  • NSX Principal Identity with client certificate
  • Active Directory account
  • API token
IOM-VAOPS-SEC-009 recommends NSX Principal Identity with Enterprise Admin role and client certificate, which removes password management.
Q7
What is the scale-out threshold at which you move from 3-node medium cluster to larger nodes or more nodes?
  • 5,000 objects
  • 8,000 objects
  • 12,000 objects
  • 20,000 objects
IOM-VAOPS-CFG-015 specifies scaling when >12,000 SDDC objects.
Q8
Where are Cloud Proxies placed relative to analytics cluster?
  • Same cross-instance NSX segment
  • Local-instance NSX segment in each VCF instance
  • Management VLAN
  • DMZ VLAN
IOM-VAOPS-NET-002: Cloud Proxies on local-instance NSX segment to collect metrics close to monitored systems.
Q9
What is the maximum number of objects a small Cloud Proxy supports?
  • 4,000
  • 8,000
  • 15,000
  • 40,000
Small Cloud Proxy supports 8,000 objects / 500 agents. Large supports 40,000 / 3,000.
Q10
Who manages root and admin password rotation for VCF Operations?
  • Aria Suite Lifecycle
  • SDDC Manager UI/API
  • vCenter Server
  • Directly on the appliance
IOM-VAOPS-SEC-013/014: In VCF mode, SDDC Manager owns password lifecycle, not Aria Suite Lifecycle.
Q11
Which load balancer monitor URL is used?
  • /health
  • /api/status
  • /suite-api/api/deployment/node/status?services=api&services=adminui&services=ui
  • /admin/status
The vrops-https-monitor uses that URL expecting HTTP 200/204/301 with body ONLINE.
Q12
Which role is assigned to the NSX Principal Identity for Operations data collection?
  • Auditor
  • Network Admin
  • Enterprise Admin
  • Security Admin
IOM-VAOPS-SEC-009 uses Enterprise Admin to allow full data collection.
Q13
Which action must you take after replacing the WS1 Access certificate with respect to Operations?
  • Redeploy Operations
  • Re-Trust With Identity Manager in Aria Suite Lifecycle (Environments → cross-instance → Operations tab)
  • Reissue NSX cert
  • Nothing
Use Aria Suite Lifecycle's Re-Trust with VMware Identity Manager action against the Operations product in the cross-instance environment.
Q14
Which design decision ensures vSAN metrics collection does not require a separate credential?
  • IOM-VAOPS-SEC-009
  • IOM-VAOPS-SEC-008
  • IOM-VAOPS-CFG-027
  • IOM-VAOPS-CFG-030
IOM-VAOPS-SEC-008 reuses the vCenter service account for vSAN data collection since vSAN is a service managed by vCenter.
Q15
What storage increment is added to each analytics node beyond initial?
  • 500 GB
  • 700 GB
  • 1 TB
  • 2 TB
IOM-VAOPS-CFG-016 adds 700 GB per analytics node (supports 12,000 objects, 20% growth, 6-month retention).

Flashcards — Intelligent Ops Management

Card 1 of 15
What components make up the analytics cluster?
Primary, Primary Replica, and one Data node (scalable up to 8/12).

Labs

Deploy and verify VCF Operations cluster with NSX load balancer

Deploy a 3-node Medium analytics cluster + 2 Cloud Proxies via Aria Suite Lifecycle and validate SDDC Manager-automated NSX LB.

Starting State: Healthy VCF 5.2 instance with Aria Suite Lifecycle and clustered WS1 Access deployed; PSPACK3 applied; DNS/NTP in place.

Configure NSX Principal Identity and rotate certificate

Create an NSX Principal Identity with client certificate for Operations, then rotate the certificate before expiry.

Starting State: Operations deployed; NSX Local Manager accessible; SDDC Manager SSH available.

Add a second VCF instance and extend Operations monitoring

Deploy two local-instance Cloud Proxies in a second VCF instance and integrate with the existing analytics cluster.

Starting State: Primary VCF instance with analytics cluster operational; second VCF instance bring-up complete; Aria Suite Lifecycle already managing first instance.

Was this page useful?
Type to search. ↑ ↓ to move, Enter to open, Esc to close.