
Prepare Top Veeam VMCA2022 Exam Study Guide Practice Questions Edition
Go to VMCA2022 Questions - Try VMCA2022 dumps pdf
Veeam Certified Architect (VMCA) certification is a highly respected designation in the field of computer systems and data management. VMCA 2022 certification confirms mastery of the Veeam product line and the ability to utilize Veeam software in complex enterprise environments. The VMCA 2022 exam is the updated version of the certification exam, tailored to meet current best practices and technological trends. VMCA2022 exam focuses on in-depth understanding of Veeam architecture, optimization, design, and troubleshooting techniques. It is designed to test candidates' abilities in leveraging Veeam software in real-world scenarios.
The VMCA2022 exam is a timed exam that consists of 40 multiple-choice questions. VMCA2022 exam is designed to be challenging and requires a deep understanding of Veeam Backup and Replication. To pass the exam, you must score at least 70%. VMCA2022 exam is administered online and can be taken from anywhere in the world. It is also available in multiple languages, including English, German, French, Spanish, Italian, and Russian.
NEW QUESTION # 24
Which of the following could cause failures to meet the requirement to test gold tier backups?
- A. You cannot firewall traffic between vLANs in the SureBackup job configuration.
- B. Backup jobs run every hour.
- C. The LAN bandwidth is not sufficient for vPower NFS datastores.
- D. There may be too many networks.
Answer: A
Explanation:
Explanation
A possible cause of failures to meet the requirement to test gold tier backups is that you cannot firewall traffic between vLANs in the SureBackup job configuration. This could prevent the gold tier virtual machines from communicating with each other or with other required services in the isolated virtual lab. For example, if a gold tier virtual machine needs to access a database server or a domain controller in another vLAN, it might fail to start or function properly in the SureBackup job. Therefore, it is important to ensure that all necessary vLANs and network settings are configured correctly in the SureBackup job.
NEW QUESTION # 25
What components can help meet the following requirement: "Alternative decryption capabilities on encrypted backups must be possible in the event of lost passwords"?
- A. Veeam Backup & Replication's Extract Utility
- B. Veeam Backup Enterprise Manager
- C. Veeam Backup & Replication's Configuration Backups
- D. Veeam Backup & Replication's Extraction Explorer
Answer: B
Explanation:
Explanation
The component that can help meet the requirement of alternative decryption capabilities on encrypted backups in the event of lost passwords is Veeam Backup Enterprise Manager. Veeam Backup Enterprise Manager is a web-based interface that allows centralized management of multiple Veeam backup servers. It also provides a password loss protection feature that enables authorized users to restore encrypted backups without entering passwords if they forget or lose them. This feature requires enabling password loss protection in Veeam Backup Enterprise Manager settings and assigning a security officer role to a user who can approve password recovery requests.
References: [Veeam Backup Enterprise Manager], [Password Loss Protection]
NEW QUESTION # 26
The decision has been made to separate out proxies for gold tier and silver/bronze tier. Which reason below justifies the decision?
- A. Gold tier virtual machines require their own backup server
- B. Gold tier virtual machines are in their own VMware cluster
- C. Gold tier virtual machines run frequently and should not share resources with lower priority virtual machines
- D. Gold tier virtual machines are on their own VMware Datastores.
Answer: C
Explanation:
Explanation
The reason that justifies the decision to separate out proxies for gold tier and silver/bronze tier is that gold tier virtual machines run frequently and should not share resources with lower priority virtual machines. This is because gold tier virtual machines have a high RPO of one hour or less, which means that they need to run backup jobs more often than silver/bronze tier virtual machines. Therefore, they should have dedicated proxies that can process their data without competing with other backup jobs for proxy resources. This can improve backup performance, reliability, and scalability for gold tier virtual machines.
NEW QUESTION # 27
Based on the customer Windows and Linux file server backup requirements, which component will help them meet their stated objectives?
- A. Add Windows and Linux server, enable indexing of backups and ensure authenticated users are configured to appropriate RBAC policy.
- B. Use Backup Enterprise Manager with indexing enabled on virtual machine and Agent backups with RBAC policies.
- C. Add a Windows Server, enable indexing of backups and ensure authenticated users are configured to appropriate AD Groups policies.
- D. Deploy Veeam Backup & Replication console and set RBAC policies to Administrator Role.
Answer: B
Explanation:
Explanation
Based on the customer Windows and Linux file server backup requirements, the best component to help them meet their stated objectives is Backup Enterprise Manager with indexing enabled on virtual machine and Agent backups with RBAC policies. This is because:
*Backup Enterprise Manager allows the customer to manage and monitor backup jobs across multiple backup servers from a single web-based interface1.
*Indexing enables the customer to perform file-level recovery from the backups of Windows and Linux servers, as well as search for files across all backups2.
*RBAC policies allow the customer to delegate permissions to different users and groups for performing file-level recovery, based on their roles and restore scopes3.
References: 1: Veeam Backup Enterprise Manager Guide 2: Veeam Backup & Replication User Guide 3:
Veeam Backup Enterprise Manager Guide > Configuring Accounts and Roles
NEW QUESTION # 28
Based on Customer requirements, how should virtual machine backups be scoped? (Choose 2)
- A. Scope each backup based the software running in each workload
- B. Create backups based on protection groups create with a CSV file.
- C. Create backups based on resource pools
- D. Create backups jobs with same retention requirements.
- E. Create backups based on tags.
Answer: D,E
Explanation:
Explanation
The methods that should be used to scope virtual machine backups based on customer requirements are to create backups based on tags and to create backup jobs with same retention requirements. Creating backups based on tags allows dynamic scoping of backups based on VMware tags assignedto virtual machines. This can simplify backup management, as new or modified virtual machines will be automatically included or excluded from backup jobs based on their tags. Creating backup jobs with same retention requirements allows consistent application of backup policies based on the backup tiers defined by the customer. This can ensure compliance with regulatory and business needs, as different tiers of virtual machines will have different retention periods and restore points.
NEW QUESTION # 29
Which of the following is risk for this project?
- A. The backup solution must support VMware encrypted datastores.
- B. Linux and Windows files server backups must be searchable during a self-service restore.
- C. Data must be replicate with one-hour recovery point objective.
- D. End-user laptop backups must have a recovery time objective of 30 minutes.
Answer: C
Explanation:
Explanation
To design a solution that meets the needs and requirements of Veeam University Hospital, you need to consider some of the risks and challenges that may affect the success and quality of the project. This will help you to identify and mitigate any potential issues or errors that may arise during the implementation or operation of the solution.
According to the Veeam Backup & Replication Best Practice Guide, a risk is a factor that may negatively impact the performance, reliability, security, or functionality of the backup and replication solution. A risk may be caused by internal or external factors, such as technical limitations, environmental constraints, human errors, etc.
Based on this definition, one of the possible risks for this project is C. Data must be replicated with one-hour recovery point objective.
This risk means that:
*The recovery point objective (RPO) is a business requirement that defines the maximum acceptable amount of data loss in case of a disaster or failure. It is measured in time units, such as minutes, hours, or days.
*The data replication is a technical solution that allows you to create replicas of your running workloads on another host or site. It is used for disaster recovery purposes, as it enables you to quickly fail over and fail back in case of a disaster.
*The one-hour RPO is a challenging and demanding requirement that may be difficult toachieve or maintain, depending on various factors, such as the data change rate, the available bandwidth, the replication frequency, etc.
*The one-hour RPO may also conflict or contradict with other requirements or expectations, such as the backup window, the backup retention, the backup storage capacity, etc.
This risk has some implications for designing a solution with Veeam products and features, such as:
*The customer or a third-party vendor must monitor and measure the data change rate of the workloads that need to be replicated, as well as the available bandwidth between sites. This will help to plan and optimize the replication infrastructure, such as the proxy servers, repository servers, WAN accelerators, and failover plans, based on the data change rate.
*The customer or a third-party vendor must configure and adjust the replication settings and policies, such as the replication method, schedule, frequency, retention, compression, deduplication, etc., based on the one-hour RPO. This will help to improve the replication performance and efficiency, as well as to meet the RPO requirement.
*The customer or a third-party vendor must test and verify the replication results and processes, as well as perform regular failover and failback drills. This will help to ensure the reliability and consistency of the replicas, as well as to validate and improve the RPO achievement.
NEW QUESTION # 30
Why is it recommended to have a Veeam backup server at each of the three sites?
- A. VMware cluster isolation.
- B. Each site has production data.
- C. Replication requires a backup server at each site.
- D. VPN connections sites.
Answer: B
Explanation:
Explanation
According to the Veeam Backup & Replication Best Practice Guide1, some of the reasons why it is recommended to have a Veeam backup server at each of the three sites are:
*Each site has production data. This reason is based on the principle of locality, which states that backup data should be stored as close as possible to the source data, to reduce network traffic and latency, and to improve backup and restore speed and efficiency. Having a Veeam backup server at each site allows you to perform local backups of the production data at each site, without having tocross the WAN or VPN connections between sites.
Topic 1, Veeam University Hospital
Executive Overview:
Veeam University Hospital is a healthcare network with located is Boston, Salt Lake City and Columbus.
They are considered a pioneer in breakthrough treatments to many illnesses and recognized worldwide as a leader in their field. They have decided to modernize their data protection strategy due to new regulatory requirements as well as ever evolving malware issues. They suffereda ransomware attack recently as well, which affected several systems with patient treatment.
Furthermore, they have expressed interest in replication of virtual workloads between sites in case of a disaster to allow for timely failover between sites with would ensure continuity in the level of patient care offered.
Their board of directors is concerned that all virtual workloads at this point can be considered a single point of failure.
Veeam University Hospital has also been experiencing issues with the time required to back up NAS systems.
Not only are they taking too long, the amount of space required is considered excessive, and a reduction of storage space for these backups is desired.
Veeam University Hospital had issues with the time required to restore Exchange items. The current solution will only restore entire mailboxes, and no granularity is possible.
For this implementation to be successful, backups must complete in the allotted backup window, and the recovery of data should be faster than the current solution, which can amount to 24 to 48 hours for a full system restore.
Solution Concept:
Veeam University Hospital is replacing their current backup solution Veeam. They plan to protect data at all three sites, with backups copied off-site for disaster recovery purposes. They have also expressed an interest in taking action to prevent another data lost due to ransomware. The offenders were also able to encrypt the existing backups as part of the attack, so data recovery is impossible. Veeam University Hospital is also interested in any posible public cloud technologies that might help mitigate this risk.
In addition, replication of running workloads to secondary sites will also be implemented to allow for site failover in the event of a disaster for reduced down time.
Existing Technical Environment:
Veeam University Hospital has VMware cluster in all locations. For security purposes, each cluster is dedicated to the department that it servers. No communication between cluster is possible. These cluster are broken into two categories, one hosting database workloads and the other hosting general use virtual machines.
Confidential patient data exists on several NAS systems as unstructured data. These NAS systems are only presenting backups to ensure consistency of the database.
Veeam University Hospital has an in-house patient database required a custom script to be execute before backups to ensure consistency of the database.
MSSQL and Oracle are used by most of the departments, with a mix of virtual and physical deployments.
Each site as a 10 GbE link to the public internet, and all traffic between sites is routed through these connections via VPN.
Each site has 20 vLANs in use, with 16 being used for VMware workloads.
For security and regulatory purposes, all vLANs are firewalled off from each other.
The current backups write to NFS storage.
All doctor and lab staff are assigned their laptops, which will also need to be protected. The location of data on these devices is enforced through group policy, and consistent throughout the organization.
No current disaster recovery solution, apart from restoring from backup files, exists at this time.
Business Requirements:
Any new solution must take advantage of automation and self-service functionality. Both features are needed to cut down on administrative costs. Role based access (RBAC) is mandatory. Forexample, only Oracle administrators can have the ability to perform self-service restore of Oracle Data.
Mission critical applications must not be impacted during business hours. All backups must complete between
6 p.m. and 8 a.m. local time.
To meet regulatory requirements all data must be retained for three years.
For archival purposes, 12 monthly backups and three yearly backups must be stored offsite.
Veeam University Hospital will only purchase on-premises storage to accommodate growth for three years of backup retention.
For any replicated virtual workloads, the data must not more than one hour old.
Due regulatory requirements, all protected data must be encrypted in flight and rest.
To meet customer service-level agreements, a commercially available helpdesk ticketing system is in use. All alerts generated must be integrated with this system to create support tickets.
Technical requirements:
Backups must take advantage of public cloud storage for long term archival purposes.
The solution must keep a local backup and be able to create an additional copy of production data. Both backups should reside on site with production systems being protected.
For quick restores and recovery, at least copy of protected data must reside on-premises.
Due to the threat of ransomware, at least one immutable or air gapped copy of protected data must reside off-side.
To ensure data integrity, backups must be verified and scanned for malware before any restore Is performed.
In addition to Self-service Oracle restores, native Oracle tools must be available and PowerShell script ready to perform ad-hoc backups and restores.
The backup solution must support VMware encrypted datastores.
Backups must be stored in logical scalable storage systems that can be expanded non-disruptively.
For end user laptop backups, only user data should be backed up. Operating system files should be excluded.
Personal files such as music, photos, and videos must be excluded for backup.
NEW QUESTION # 31
To demonstrate SLA compliance during audits and protection against exposure to personally identifiable information, which configuration would verify this is possible in the event of exposure?
- A. Implement Veeam Backup & Replication servers at one location and leverage hardened repositories as a primary target with a backup copy to a second site.
- B. Create a virtual lab environment and periodically perform staged restores with custom scripts.
- C. Scan backups with Veeam ONE to remove personally identifiable information.
- D. Create secure restore to ensure malware-free backups.
Answer: B
Explanation:
Explanation
The configuration that would verify the SLA compliance during audits and protection against exposure to personally identifiable information in the event of exposure is to create a virtual lab environment and periodically perform staged restores with custom scripts. A virtual lab is an isolated environment where you can run your backups or replicas without affecting the production environment. A staged restore is a process that allows you to run custom scripts on the restored data before publishing it to the production environment.
By using these features, you can demonstrate that your backups are recoverable and compliant with legal regulations, as well as remove or mask any sensitive data before restoring it.
NEW QUESTION # 32
While deciding which transport mode to use for the proxies, you notice that one of the requirements is support the encrypted datastore in VMware. Which processing modes can you leverage for the backup proxies?
(Choose 3)
- A. Virtual Appliance (HotAdd) mode.
- B. Network mode with Encryption (NBDSSL).
- C. Direct SMB.
- D. Direct NFS.
- E. Direct SAN.
- F. Network (NBD) mode.
Answer: A,B,C
Explanation:
Explanation
To access encrypted datastores in VMware, you need to use a transport mode that supports encryption. The following transport modes support encryption:
*Network mode with Encryption (NBDSSL): This mode uses an encrypted network connection between the backup proxy and the ESXi host to read and write data from the encrypted datastore. This mode does not require direct access to the datastore, but it can be slower than other modes due to network traffic and encryption overhead2
*Virtual Appliance (HotAdd) mode: This mode uses a virtual backup proxy that runs on an ESXi host and attaches virtual disks of the encrypted VMs to itself using the VMware vSphere API. This mode requires that the backup proxy and the source VMs reside on the same datastore or on datastores that are accessible by the same ESXi host. This mode can offer better performance than network mode, but it can also cause SCSI reservation conflicts if multiple backup proxies access the same datastore simultaneously3
*Direct SMB: This mode uses a physical backup proxy that accesses the encrypted datastore over the SMB protocol. This mode requires that the datastore is configured as an SMB share and that the backup proxy has read and write permissions on it. This mode can offer high performance and scalability, but it also requires additional configuration steps and security considerations4 The following transport modes do not support encryption:
*Network (NBD) mode: This mode uses an unencrypted network connection between the backup proxy and the ESXi host, which cannot access encrypted datastores2
*Direct SAN: This mode uses a physical backup proxy that accesses the encrypted datastore over the SAN fabric, which cannot decrypt encrypted data5
*Direct NFS: This mode uses a physical backup proxy that accesses the encrypted datastore over the NFS protocol, which does not support encryption6 References:
1: Hardened Repository - User Guide for VMware vSphere 2: Network Mode - User Guide for VMware vSphere 3: Virtual Appliance Mode - User Guide for VMware vSphere 4: Direct SMB Access Mode - User Guide for VMware vSphere 5: Direct SAN Access Mode - User Guide forVMware vSphere 6: Direct NFS Access Mode - User Guide for VMware vSphere
NEW QUESTION # 33
Consider the requirements regarding immutable or air gapped and different types of workloads. Which types of jobs do not support using immutability from S3 Object Lock or Hardened Repository and will need a different solution?
- A. Backup copy jobs with GFS enable.
- B. NAS backups.
- C. Backup Jobs.
- D. Scale-out Backup Repository offloads to Archive Tier to Amazon Glacier.
Answer: A
Explanation:
Explanation
*Backup copy jobs with GFS enabled. This type of job does not support using immutability from S3 Object Lock because it uses synthetic full backups, which require modifying existing backup files. Synthetic full backups are not compatible with immutability settings, as they violate the principle of not changing the backup files.
NEW QUESTION # 34
You are trying to determine which feature would work the reliably for excluding the H: drive on MSSQL server virtual machines. The MSSQL servers are built on demand, not from virtual machine templates. Which is the preferred method to achieve this requirement?
- A. Set up VMDK exclusion for the disk on which the H: resides in the Virtual Machines > Exclusions page for each virtual machine.
- B. Use Veeam Agent Backups and use the Exclusions tab under Gest Processing > Application for MSSQL jobs.
- C. Use Veeam Agent Backups and set up Volume Backups and include everything but H:
- D. Use the Exclusion tab under Guest Processing > Applications for VM backups to exclude the H: volume in MSSQL jobs.
Answer: A
Explanation:
Explanation
The preferred method to achieve the requirement of excluding the H: drive on MSSQL server virtual machines is to set up VMDK exclusion for the disk on which the H: resides in the Virtual Machines > Exclusions page for each virtual machine. This method allows you to exclude specific virtual disks from being processed by backup jobs based on their SCSI IDs or disk labels. This can save backup time and storage space by skipping unnecessary data. This method also works reliably regardless of whether the MSSQL servers are built on demand or from virtual machine templates.
NEW QUESTION # 35
What information is missing form discovery?
- A. What the current LAN bandwidth is at Fresno.
- B. What backup transport mode is currently used.
- C. What the available bandwidth is between Fresno and Carson City.
- D. What type of backup storage is currently used.
Answer: C
Explanation:
Explanation
The information that is missing from discovery is what the available bandwidth is between Fresno and Carson City. This information is important for designing and sizing the backup copy jobs that need to run daily between the two sites. The available bandwidth can affect the backup copy performance, duration, and size.
For example, you can use the available bandwidth to estimate how much data can be transferred between the sites within the backup copy window. You can also use theavailable bandwidth to determine whether you need to use compression, deduplication, or WAN acceleration to optimize the backup copy traffic.
NEW QUESTION # 36
To ensure SLA compliance and protection against ransomware, which of the following configurations would accomplish this goal?
- A. Implement Veeam Backup & Replication servers at two locations and leverage ReFS repository as a primary target with a backup copy to a second site.
- B. Provide a Veeam Backup & Replication servers at two locations and leverage object storage.
- C. Implement Veeam backup & Replication servers at one location and leverage Hardened Repositories as a primary target with a backup copy to a second site.
- D. Provide a Veeam Backup & Replication server with Veeam replication and enable XFS with immutability on NFS targets.
Answer: C
Explanation:
Explanation
*Use Hardened Repositories as the primary target, which are Linux-based repositories that support immutability and prevent ransomware from accessing or deleting backup files12.
*Use backup copy jobs to create a second copy of the backups to a different site, which will provide additional protection and redundancy in case of a disaster or data loss34.
*Use Veeam Backup & Replication servers at one location, which will simplify the management and monitoring of the backup infrastructure and reduce the operational costs.
The other configurations are not as effective or secure, as they either do not use immutability, do not create a second copy of the backups, or do not leverage the benefits of Veeam Backup & Replication servers.
References: 1: Protect against Ransomware with Immutable Backups - Veeam 2: Hardened Repository - User Guide for VMware vSphere 3: Backup Copy Modes - User Guide for VMware vSphere 4: Backup copy jobs - Veeam Backup & Replication Best Practice Guide : Veeam Backup & Replication Architecture Overview
NEW QUESTION # 37
Veeam University Hospital is considering using Veeam ONE to collect alarms from the virtual and backup infrastructure. What option is available for integrating the solution with ticketing systems?
- A. Configure Veeam ONE to send SNMP traps to the ticketing system.
- B. Configure Veeam Backup & Replication to send email notification to the helpdesk email account and have someone generate the ticket manually.
- C. Integrate Veeam ONE with the ticketing software using plug-in in the supplemental folder on the Veeam ISO.
- D. Veeam Backup & Replication integrates directly with Service Now and Remedy ticketing software natively.
Answer: A
Explanation:
Explanation
Veeam University Hospital is considering using Veeam ONE to collect alarms from the virtual and backup infrastructure. Veeam ONE is a powerful monitoring and reporting tool that provides visibility and insight into the performance, configuration, and utilization of your backup and virtual infrastructure. Veeam ONE can also alert you about any issues or problems that may affect the availability or reliability of your data protection and recovery processes.
One of the options that is available for integrating Veeam ONE with ticketing systems is A. Configure Veeam ONE to send SNMP traps to the ticketing system.
This option means that:
*SNMP (Simple Network Management Protocol) is a protocol that allows network devices to communicate and exchange information with each other.
*SNMP traps are messages that are sent by network devices to notify a management system about events or conditions that require attention or action.
*Veeam ONE can be configured to send SNMP traps to a ticketing system when an alarm is triggered or resolved. This allows you to automate the creation and update of tickets based on the alarm data, such as the alarm name, severity, status, description, etc.
*To configure Veeam ONE to send SNMP traps to a ticketing system, you need to enable SNMP notifications in the Veeam ONE settings, as well as specify the SNMP server address, port, community string, and trap format. You also need to configure the ticketing system to receive and process the SNMP traps from Veeam ONE.
This option is a good choice for integrating Veeam ONE with ticketing systems, as it allows you to leverage the benefits and features of both solutions, such as:
*You can use Veeam ONE to monitor and analyze your backup and virtual infrastructure, as well as to detect and alert you about any issues or problems that may affect your data protection and recovery processes.
*You can use the ticketing system to manage and track the resolution of the issues or problems that are reported by Veeam ONE, as well as to assign and prioritize tickets to the appropriate staff or team members.
NEW QUESTION # 38
What information is necessary to design the disaster recovery solution and must be identified during discovery? (Choose 3)
- A. The number of virtual machines to be replicated.
- B. The number of vLANs per site.
- C. Which sites will be the source of replication and which sites will be the targets for recovery.
- D. The required amount of backups to be storage off site.
- E. The available bandwidth between locations.
Answer: A,C,E
Explanation:
Explanation
To design a disaster recovery solution that meets the needs and requirements of Veeam University Hospital, you need to identify some information during the discovery phase. This information will help you to understand the scope and scale of the replication and failover processes, the network andstorage resources and limitations, and the recovery time objectives and recovery point objectives.
According to the Veeam Backup & Replication Best Practice Guide, some of the information that is necessary to design the disaster recovery solution and must be identified during discovery are:
*The number of virtual machines to be replicated. This information will help you to determine the number and size of the replication jobs, as well as the replication performance and scalability, based on the number and type of virtual machines.
*The available bandwidth between locations. This information will help you to estimate the network bandwidth and throughput that are available for replication traffic, as well as the impact of replication activities on the network performance and latency.
*Which sites will be the source of replication and which sites will be the targets for recovery. This information will help you to plan and configure the replication infrastructure, such as the proxy servers, repository servers, WAN accelerators, and failover plans, based on the source and target locations.
NEW QUESTION # 39
In order to improve the likelihood that a ransomware attack on the Veeam infrastructure will not be successful, which of the following should Veeam University Hospital do?
- A. Protect the Veeam components on the production Active Directory Forest with multi-factor authentication.
- B. Ensure that none of the Veeam components are on the production Active Directory domain.
- C. Remove all remote access from Veeam administrators.
- D. Implement a strong password security policy on shared administrative accounts.
Answer: A
Explanation:
Explanation
*MFA is a security method that requires users to provide two or more pieces of evidence to verify their identity, such as a password, a code, a token, or a biometric factor3.
*MFA adds an extra layer of protection against ransomware attacks, as it prevents attackers from accessing the Veeam components even if they manage to steal or guess the passwords of the administrative accounts12.
*MFA also helps to prevent unauthorized changes or deletions of backup data, as well as unauthorized restores or failovers of VMs or applications12.
The other options are not as effective or feasible, as they either do not provide enough security, limit the functionality, or disrupt the integration of the Veeam infrastructure.
References: 1: 6 Best Practices For Ransomware Protection | Veeam 2: Ransomware Prevention Best Practices
- Veeam 3: Multi-factor authentication - Wikipedia
NEW QUESTION # 40
According to the specified requirements, it is necessary to have backups encrypted. If using Veeam's native encryption, which repository type will be impacted the most?
- A. Deduplicating storage appliance.
- B. SMB share.
- C. Hardened Repository with XFS reflink cloning.
- D. Windows ReFS with block cloning.
Answer: A
Explanation:
Explanation
If using Veeam's native encryption, the repository type that will be impacted the most is the deduplicating storage appliance. This is because Veeam Backup & Replication uses different encryption keys for every job session, which makes the encrypted data blocks appear as different even if they contain duplicate data. This reduces the deduplication ratio and increases the storage consumption on the deduplicating appliance. If you want to achieve a higher deduplication ratio, youcan disable data encryption or use the encryption feature on the deduplicating appliance itself1
NEW QUESTION # 41
During deeper technical discovery it was uncovered that that the customer also has a Fibre Channel SAN that needs protection. Veeam University Hospital asks about the option of performing backup from storage snapshots. What component(s) will this require?
- A. Veeam backup proxies running the Windows servers.
- B. Veeam backup proxies and repositories running on the servers.
- C. Veeam backup proxies running on physical servers.
- D. Veeam backup proxies running on Linux serves.
Answer: C
Explanation:
Explanation
To perform backup from storage snapshots for a Fibre Channel SAN, you need to deploy one or more physical servers that will act as backup proxies and connect them to the SAN fabric. This is because Veeam Backup & Replication needs to access the storage system over the Fibre Channel protocol, which is not supported by virtual machines. The backup proxies will read data from the storage snapshots and transfer it to the backup repositories1
NEW QUESTION # 42
Based on additional discovery, it was determined that a few critical workloads need to maintain a less than five-minute recovery point objective. Which of the following would be the recommended method to replicate VMware virtual machines?
- A. Veeam Backup Copy with immediate mode.
- B. Veeam image-based replication.
- C. Veeam Continuous Data Protection.
- D. Custom PowerShell scripting.
Answer: C
Explanation:
Explanation
*Veeam CDP is a technology that helps you protect mission-critical VMware virtual machines when data loss for seconds or minutes is unacceptable12.
*Veeam CDP leverages vSphere APIs for I/O filtering (VAIO) to constantly replicate I/O operations performed on VMs without creating snapshots12.
*Veeam CDP allows you to configure the RPO per second and achieve near-zero RPO, which means almost no data loss12.
*Veeam CDP also provides minimum recovery time objective (RTO) in case of a disaster, as CDP replicas are in a ready-to-start state1.
Veeam image-based replication is not the best option, as it relies on snapshots and has a higher RPO than CDP3. Custom PowerShell scripting is not a reliable or scalable solution, as it requires manual coding and maintenance. Veeam Backup Copy with immediate mode is not suitable for replication, as it is designed for copying backup files, not VM replicas4.
References: 1: Continuous Data Protection (CDP) - User Guide for VMware vSphere 2: Veeam v11:
Continuous Data Protection (CDP) configuration 3: Replication - User Guide for VMware vSphere 4: Backup Copy Modes - User Guide for VMware vSphere
NEW QUESTION # 43
When deciding on the design of the primary backup repository, which option best fits the requirements in the case study?
- A. Linux Repository using XFS integration, single-use credentials, and immutability
- B. Dedupe appliance leveraging vendor API for access
- C. Public cloud storage with S3 object-lock for immutability
- D. Windows repository using ReFS integration, single-use credential and persistent VSS snapshot
Answer: A
Explanation:
Explanation
The best option for the primary backup repository design that fits the requirements in the case study is a Linux Repository using XFS integration, single-use credentials, and immutability. A Linux Repository is a type of backup repository that uses a Linux server as a backup target. A LinuxRepository can leverage XFS integration to enable fast creation and transformation of synthetic full backups by using XFS file system features such as reflink and copy-on-write. A Linux Repository can also use single-use credentials to enhance security by generating unique credentials for each backup job session. A Linux Repository can also provide immutability and ransomware protection for backup files by using Linux access control mechanisms such as immutable flag or chattr command.
NEW QUESTION # 44
What information related to the virtual infrastructure is missing and must be collected during the discovery phase? (Choose 2)
- A. Recovery point objective.
- B. Backup window.
- C. Size of the source data set.
- D. Local area network speed.
- E. number of Microsoft Exchange mailboxes.
Answer: C,D
Explanation:
Explanation
To design a solution that meets the virtual infrastructure requirements for Veeam University Hospital, you need to collect some information during the discovery phase. This information will help you to understand the configuration and performance of the VMware clusters, the size and type of the data, and the backup and recovery objectives.
According to the Veeam Backup & Replication Best Practice Guide, some of the information related to the virtual infrastructure that is missing and must be collected during the discovery phase are:
*Local area network speed. This information will help you to determine the network bandwidth and throughput that are available for backup and replication traffic, as well as the impact of backup and replication activities on the network performance and latency.
*Size of the source data set. This information will help you to estimate the backup storage requirements, as well as the backup compression and deduplication ratios, based on the size and type of the data.
Therefore, the correct answer is A and D.
NEW QUESTION # 45
Based on the requirements, what should be factored into the physical design when implementing the virtual machine replication between sites?
- A. Use virtual servers on separate ESXi hosts for the Veeam backup proxies.
- B. Use physical servers for Veeam backup proxies at each site.
- C. Configure Veeam Backup Enterprise Manager on the same virtual machine as your Veeam Backup & Replication server.
- D. Ensure the proper firewall ports are open between the proxies at each site.
Answer: D
Explanation:
Explanation
Based on the requirements, one of the factors that should be considered in the physical design when implementing the virtual machine replication between sites is to ensure that the proper firewall ports are open between the proxies at each site. This is because Veeam Backup & Replication uses network ports to communicate with backup infrastructure components and transfer data during replication. You need to make sure that the required ports are not blocked by firewalls or other network devices. For a list of ports used by Veeam Backup & Replication, see this article2
NEW QUESTION # 46
The customer has stated that synthetic operations and backups copy jobs must be completed in the desired window. Which components should be sized correctly to ensure that this will be successful?
- A. Veeam Backup & Replication and gateway servers.
- B. Proxy and gateway servers.
- C. Repository and gateway servers.
- D. Proxy and repository servers.
Answer: D
Explanation:
Explanation
According to the Veeam Backup & Replication Best Practice Guide1, the proxy and repository servers are the components that should be sized correctly to ensure that synthetic operations and backup copy jobs can be completed in the desired window. This is because:
*The proxy server is responsible for retrieving data from the source and sending it to the target. The proxy server performance depends on the CPU, memory, network, and storage resources available. The proxy server should have enough CPU cores and memory to handle concurrent tasks, as well as sufficient network bandwidth and storage throughput to transfer data efficiently.
*The repository server is responsible for storing backup files on the target storage. The repository server performance depends on the CPU, memory, network, and storage resources available. The repository server should have enough CPU cores and memory to handle concurrent tasks, as well as sufficient network bandwidth and storage throughput to write data efficiently. The repository server should also support the backup format and retention policy chosen for the backup copy job.
References: 1: Backup copy jobs - Veeam Backup & Replication Best Practice Guide
NEW QUESTION # 47
Which of the following areas would benefit from additional analysis on areas mentioned in the casa study?
(Choose 3)
- A. OneDrive
- B. Hyper-V
- C. MSSQL
- D. NAS
- E. VMware
- F. PostgreSQL
Answer: A,D,F
Explanation:
Explanation
To design a solution that meets the needs and requirements of Veeam University Hospital, you need to conduct a thorough analysis on the areas mentioned in the case study. This will help you to understand the current state of the environment, the goals and expectations of the stakeholders, and the constraints and challenges of the project.
According to the case study, some of the areas that would benefit from additional analysis are:
*NAS. This area would benefit from additional analysis because NAS systems are used to store confidential patient data as unstructured data, which need to be backed up consistently and securely. You need to collect more information about the characteristics and performance of the NAS systems, such as the size and type of data, the number and distribution of files, the largest file size, the version of SMB protocol, the deduplication and compression ratios, etc. This will help you to design a solution that can meet the backup and recovery objectives, as well as the regulatory and security requirements, for the NAS data.
*PostgreSQL. This area would benefit from additional analysis because PostgreSQL databases are used by some of the departments, with a mix of virtual and physical deployments. You need to collect more information about the configuration and performance of the PostgreSQL databases, such as the version and edition, the operating system and platform, the backup and restore methods and tools, the consistency and integrity requirements, etc. This will help you to design a solution that can support and integrate with PostgreSQL databases, as well as provide consistent and reliable backups and restores.
*OneDrive. This area would benefit from additional analysis because OneDrive is used by all doctor and lab staff to store their user data on their laptops, which also need to be backed up. You need to collect more information about the usage and performance of OneDrive, such as the number and size of files, the synchronization frequency and settings, the authentication and authorization methods, etc. This will help you to design a solution that can protect and recover OneDrive data, as well as exclude any operating system or personal files from backup.
Topic 2, Veeam Life and Indemnity
Executive Summary:
Veeam Life and Indemnity is expanding its existing Veeam backup infrastructure to protect additional virtual machines, physical server and NAS workloads at their Fresno, CA and Carson City, NY data centers.
The original installation and configuration of Veeam software occurred two years ago. Since the installation, the organization has grown, and as a result, the Veeam Infrastructure needs to be resized to accommodate the existing and new workloads.
For the past three months, Veeam Life and Indemnity has noticed that they are having issues with backups completing within the allotted backup window. Only 40% of backup jobs complete successfully, so they have broken the backups into two sets, and they run them on alternating days. They have also stopped all backups for their development environment.
In addition, the original configuration required a daily backup copy job, but to the issue with backups completing, this has been modified to run only on Sundays.
They have also noticed a degradation in storage performance and are having to purchase new storage on a quarterly basis to accommodate data growth.
Solution Concept:
Veeam Life and Indemnity is upgrading Veeam Backup & Replication to the last version. They are also replacing all legacy physical hardware and storage with current generation equipment. Veeam Life and Indemnity wants to be able to ensure that all backups, including production and dev test workloads, can run every night and that all backups complete within the required backup window. In addition, Veeam Life and Indemnity would like to run daily copy jobs to ensure that a copy of all backed up data resides at both physical sites.
Veeam Life and Indemnity has also expressed concern about the threat of ransomware. They have not experienced a data breach of any kind but would like to ensure the ability of recover should one occur.
Existing Technical Environment:
Veeam Life and Indemnity has VMware clusters in all locations. These clusters are broken into two categories:
general use virtual workloads, and application specific workloads, such as MSSQL and Oracle.
All customer data is subject to government regulation and must be kept secure at all times.
Veeam Life and Indemnity has a proprietary CRM system that must be quiesced prior to backup.
All email is hosted in Office 365.
All database servers are virtualized.
All virtual machines are categorized as either gold, silver, or bronze, with different service-level agreements based on tier.
All backups currently encrypted in flight and at rest.
Internet connectivity at both sites is current 1 Gbps, with plans to increase to 2 Gbps soon.
All field sales reps are assigned a company laptop that runs a CRM client.
The LAN at each location supports up to 40 Gbps bandwidth.
All backups are currently written to Scaled-out Backup Repositories with each extent residing on a CIFS share.
Each department has its own vLAN, with a total of 30 vLANs for production traffic.
A single management vLAN is stretched between sites.
All unstructured data resides either on 10 NFS shares on the company's incumbent NAS devices, or Windows file servers as file shares.
VMware uses vSAN for VM datastores.
All vLAN must traverse a firewall to communicate, and the backup network itself is no routable.
All network traffic between clusters is required to traverse a firewall.
The firewall devices can support up to 20 Gbps.
Business Requirements:
Due to limited manpower, all backups should be dynamically scope.
All backups must be copied across site outside of the current backup window to avoid any backup performance issues.
Due to the sensitivity of customer data, tier 1 helpdesk personnel must not be able to access these backups.
They should have access to restore non-customer data.
Backup administrators are subject toa rigorous background check and should be the only staff able to perform restores of confidential customer data.
For any legal issues, fast and timely discovery from backup data should be supported.
For security purposes, all storage should be hardened to prevent data breaches.
Remote sales staff should have the ability to start a backup oh their devices.
Due to regulatory requirements, audits must be performed periodically to ensure successful and consistent backups, as well adherence to security policies.
Technical Requirements:
All backups must complete within the hours of 5 p.m. to 8 a.m. local time Backup copy jobs must successfully complete daily outside of the backup window.
Gold tier virtual machines have a recovery point objective of the one hour for image backup, and 15 minutes for traction log backup, with a recovery time objective of four hours.
Silver tier virtual machines have a recovery point objective of 24 hours, with a recovery time objective of eight hours.
Bronze tier virtual machines have a recovery point objective of seven days, with no defined recovery time objective.
NAS devices and file servers have a recovery point objective of four hours, with no specified recovery time objective.
Eight weekly backup, three monthly backups, and seven yearly backups should be retained for regulatory requirements.
All data must be encrypted in flight and rest.
Alternative decryption capabilities on encrypted backups must be possible in the event of lost passwords.
Role Based Access Control must be used to prevent unauthorized access to backup data.
New storage must be hardened to prevent intrusion, and if possible, the data written must be unchangeable to prevent ransomware attacks.
All backups must be scanned prior to any restore operations for malware.
All gold level systems must have a custom script run before restore to ensure compliance to specific legal statutes.
Gold tier backups must be tested to verify recoverability.
Only silver tier systems should be indexed during backups, with the exception of laptops belonging to the sales field.
All personal files on laptops should be excluded from backup
All MSSQL server backups should exclude the H: drive.
NEW QUESTION # 48
Veeam University Hospital perform a proof of concept of the design outline in the architecture. Backups completed successfully, but it is determined that backup copy jobs between sites are not completing in the required timeframe. During the result analysis, it was discovered that the bandwidth between sites was heavily saturated. What adjustments within the Veeam infrastructure would best address this issue?
- A. Add WAN accelerators to each site.
- B. Increase the proxy computer resources at each site.
- C. Increase the computer resources on the repository servers at each site.
- D. Have the customer implement Quality of Service on their WAN connections.
Answer: A
Explanation:
Explanation
WAN accelerators are dedicated components that Veeam Backup & Replication uses for WAN acceleration.
WAN accelerators are responsible for global data caching and data deduplication, which reduce the amount of data that needs to be transferred over the network. By adding WAN accelerators to each site, you can improve the performance of backup copy jobs between sites, and reduce the bandwidth consumption and network traffic3 References:
1: Gateway Server - User Guide for VMware vSphere 2: Gateway Server - User Guide for VMware vSphere
3: WAN Accelerators - User Guide for VMware vSphere
NEW QUESTION # 49
......
The VMCA2022 certification is recognized globally and is highly valued in the IT industry. VMCA 2022 certification provides IT professionals with the skills and knowledge required to deploy and manage Veeam Availability Suite v11 in enterprise environments. VMCA 2022 certification also demonstrates the candidate’s commitment to professional development and their dedication to staying up-to-date with the latest technologies.
Free Veeam Certified Architect VMCA2022 Exam Question: https://pass4sure.practicedump.com/VMCA2022-exam-questions.html