Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free VMware Avi Load Balancer 30.x Administrator 6V0-22.25 Exam Questions

Page: 1 / 7 Total 65 questions

Want more questions? Get Premium Access.

Question 1

A Virtual Service is configured with both RSA and EC certificates. What action could be taken to increase SSL performance without compromising security?

Correct Answer: B. Arrange the order of the RSA and EC certificates so EC is preferred
Explanation:

Avi Load Balancer supports presenting both RSA and EC certificates on the same SSL/TLS Virtual Service. When both are available, certificate selection can influence SSL performance. EC certificates generally provide strong security with lower computational overhead than RSA, especially compared with larger RSA keys. VMware Avi documentation includes guidance for EC versus RSA Certificate Priority, which exists specifically because certificate ordering and preference matter when both certificate types are configured. Disabling SSL session reuse would usually hurt performance, not improve it. Scaling out to another Service Engine can improve capacity, but it does not specifically optimize SSL cryptographic efficiency. Disabling PFS would reduce security, so it violates the question's requirement. Therefore, preferring EC before RSA is the correct performance improvement without compromising security.


Question 2

Doing HTTP to HTTPS redirect in an HTTP Policy is:

Correct Answer: C. More flexible than the HTTP profile
Explanation:

VMware Avi Load Balancer supports HTTP-to-HTTPS redirection in more than one way. The HTTP application profile can perform a general HTTP-to-HTTPS redirect, but an HTTP Policy provides more granular control because policies can match on specific conditions and then apply actions. Avi documentation states that Virtual Service policies are more specific than general-purpose profiles and that policy rules take precedence over profile behavior. This makes HTTP Policy redirection more flexible than using only the HTTP profile, because administrators can build conditional redirect logic based on host, path, headers, or other HTTP match criteria. It is not incompatible with WAF, and it is not described as less efficient than DataScript for this purpose.


Question 3

Which statement is true for Avi to compress an HTTP response?

Correct Answer: D. The client's Accept-Encoding header must be in the request
Explanation:

HTTP compression depends on whether the client indicates support for compressed content. In Avi Load Balancer compression configuration, the Accept-Encoding request header is relevant because it tells the system what compression encodings the client can accept. Therefore, for Avi to compress an HTTP response, the client request must include an appropriate Accept-Encoding header.


Question 4

Which High Availability mode should be used for an application that cannot be SNATed?

Correct Answer: A. Legacy Active-Standby
Explanation:

Applications that cannot be SNATed require preservation of the original client IP address. In Avi Load Balancer, preserving client IP is mutually exclusive with SNAT, because the Service Engine must forward traffic without replacing the source address. VMware Avi documentation for Preserve Client IP describes specific requirements and caveats for non-SNAT traffic handling. For this model, the Service Engine Group must use Legacy Active-Standby behavior, where the Virtual Service is active on one Service Engine and failover behavior is predictable. Elastic Active-Active mode generally relies on distributed placement and typically uses SNAT for symmetric return traffic handling. Therefore, when an application cannot use SNAT and must preserve the client IP address, the correct HA mode is Legacy Active-Standby.


Question 5

Which task is performed by the Avi Controller?

Correct Answer: B. Renew SSL/TLS Certificates
Explanation:

The Avi Controller performs centralized control-plane and management tasks, while Service Engines perform data-plane traffic processing. SSL/TLS termination, HTTP header manipulation, and other live traffic-processing functions occur on Service Engines, not the Controller. Client DNS resolution for GSLB is handled by Avi DNS/GSLB services through Virtual Services and Service Engines. Certificate lifecycle management, however, is a Controller-side administrative function. Avi documentation describes automatic certificate renewal, where the Controller scans configured certificates for expiry, generates events before expiration, and attempts renewal when a certificate management profile is configured. This is a management-plane workflow rather than a packet-processing task. Therefore, among the listed options, the task performed by the Avi Controller is Renew SSL/TLS Certificates.


Question 6

When the logs are viewed, the operator finds that cookies are not captured. Which configuration option should be enabled to fix this?

Correct Answer: A. Log all headers
Explanation:

Cookies are carried in HTTP headers, specifically the client request Cookie header and the server response Set-Cookie header. Avi application logs can show many useful request and response details, but not every header is captured in the standard visible log fields. Broadcom documentation for client log levels explains that full client logs include many data points and that All Headers logging can be enabled to capture HTTP headers. Broadcom's logging-all-headers guidance also recommends using this feature carefully, preferably with log filters or temporary troubleshooting scope, because collecting all headers can increase log volume and may expose sensitive data. A client IP filter narrows log capture but does not by itself capture cookies. Real-time metrics and non-significant logs also do not specifically enable cookie/header capture.


Question 7

Which issue or scenario requires elastic scale-out?

Correct Answer: C. Managing heavy increases in traffic volume without disruption
Explanation:

Elastic scale-out is used to increase data-plane capacity by placing a Virtual Service on additional Service Engines or by increasing Service Engine capacity in response to demand. Avi Elastic HA combines scale-out performance and high availability, and Avi autoscale features are designed to add Service Engine capacity when traffic growth requires more resources. This directly addresses situations where a Virtual Service must handle heavy increases in traffic volume without application disruption. Controller failure protection is handled by Controller clustering, not elastic data-plane scale-out. Processing multiple protocols is a Virtual Service design and profile configuration concern. Enabling WAF is an application security feature and can increase resource needs, but it does not itself define the scenario requiring elastic scale-out. Therefore, the correct answer is C.


Question 8

Which two mechanisms for alerting an operator that an SSL/TLS certificate is about to expire are enabled by default? Choose two.

Correct Answer: C. The Health Score of the Virtual Service will be lowered by a security penalty; D. In Templates > Security > SSL Certificates, the certificates about to expire will appear in yellow, orange, or red
Explanation:

The default Avi Load Balancer behavior for impending SSL/TLS certificate expiration includes visible operational indicators in the UI and health score impact. VMware Avi documentation explains that certificates approaching expiration affect the Virtual Service by applying a security penalty. At 30 days before expiration, the Virtual Service incurs a 20-point security penalty and the maximum health score is capped at 80. The certificates page also provides visual indication of certificate status using color changes as certificates approach expiration. Email and SNMP alerting require notification or external integration configuration, so they are not the default mechanisms. A top red UI banner is not the standard default certificate-expiry alerting mechanism described for this case. Therefore, the correct default mechanisms are health score security penalty and SSL certificate color status indicators.


Question 9

To disable SNAT, configure Preserve Client IP Address in which section?

Correct Answer: D. Network Service
Explanation:

In Avi Load Balancer, disabling SNAT for a Virtual Service is handled through Preserve Client IP configuration. VMware Avi documentation states that preserving the client IP address is mutually exclusive with SNATing the Virtual Service. The related configuration is not part of the Application Profile or TCP Profile, because those profiles control application-layer or TCP proxy behavior rather than the forwarding model for source address preservation. It is also not simply a Service Engine Group property. For the supported configuration flow, Preserve Client IP is configured using a Network Service, including floating IP and related network service settings associated with the Service Engine Group, VRF, and cloud. Therefore, the correct section for configuring Preserve Client IP Address to disable SNAT is Network Service.


Question 10

Which method must be used to create a new Virtual Service for multiple ports and network protocols?

Correct Answer: B. Create the Virtual Service using Advanced Mode
Explanation:

Avi Virtual Services can listen on multiple ports, and some deployments require different port and protocol mappings for the same Virtual Service configuration. The simplified Basic Mode wizard is intended for common application deployment and does not expose the full set of Virtual Service options. Broadcom's Avi documentation states that creating a Virtual Service in Advanced Setup allows administrators to configure all options through the available tabs. Documentation for mapping multiple Virtual Service ports also describes using the Virtual Service editor settings to define multiple service ports. Therefore, when a new Virtual Service must support multiple ports and network protocols, the correct method is to use Advanced Mode, where the full port, profile, and protocol configuration is available.