VCP-VCF Support · Exam 2V0-15.25 · VMware Cloud Foundation 9.0
Every testable objective in exam 2V0-15.25 is troubleshooting. Read its blueprint and Sections 1 to 4 are marked as having no testable objectives at all. Everything sits in Section 5, from a failed deployment to a stuck HCX migration. The best preparation is breaking things on purpose and finding out why, so that is what these 163 lab tasks ask you to do.
FirstWhat this exam actually is
Facts from the published exam guide, last updated 15 August 2025:
| Item | Detail |
|---|---|
| Exam | 2V0-15.25, VMware Cloud Foundation 9.0 Support, leading to VMware Certified Professional – VMware Cloud Foundation Support (VCP-VCF Support) |
| Questions | 60, in English |
| Time | 135 minutes, including adequate time for non-native English speakers |
| Pass mark | 300, scaled |
| Delivery | Proctored, through Pearson VUE |
| Product version | VCF 9.0 |
| Testable objectives | 11 objectives, 5.1 to 5.11, with 41 sub-objectives, all in Section 5 |
| Recommended course | VMware Cloud Foundation: Troubleshooting |
Source: the official exam guide for 2V0-15.25, published by Broadcom. Read it yourself before you book. Everything below is written against the objectives in that document.
SecondWhere the objectives actually are
| Objective | Sub-objectives | Sections below |
|---|---|---|
| 5.1 Deployment and fleet scaling | 2 | B |
| 5.2 Upgrade from 5.x and vSphere conversion | 2 | C |
| 5.3 Workload domains: create, scale, import | 4 | D |
| 5.4 Fleet management: certificates, passwords, identity | 3, with four more under certificates | E and F |
| 5.5 Licence management | 3 | G |
| 5.6 Compute: ESX, vCenter, VMs, clusters | 4 | H and I |
| 5.7 Storage: vSAN, stretched clusters, supplemental | 3 | J to L |
| 5.8 Networking: VDS, NSX, routing, gateways, services, VPC | 6 | M to O |
| 5.9 VCF Operations, logs, networks, workbench, Log Assist | 7 | P and Q |
| 5.10 Identity Broker, VCF Automation, Supervisor, provider, organizations | 5 | R to T |
| 5.11 HCX workload mobility | 2 | U |
Networking, VCF Operations and the VCF Automation group are the three largest, with six, seven and five sub-objectives. Certificates are the most detailed single topic: objective 5.4 breaks them into four separate items, covering the CA, the CSR, external certificates, and replacement with auto renewal.
ThirdHow it differs from the advanced Support exam
The advanced exam, VCAP-VCF Support 3V0-13.26, also puts everything in Section 5, but goes deeper into fewer layers: vSAN, NSX down to the packet walk, VKS and the Operations stack. The professional exam is broader. It adds the platform-level faults that sit around those layers: deployment, upgrade from 5.x, conversion, workload domain tasks, certificates, passwords, licences, VCF Automation and HCX. If you plan to sit both, this one is the better place to start.
FourthHow to practise a troubleshooting exam
- Create the fault, then diagnose it as if you had not. A fault you built is one where you already know the answer, so you can check your method against it.
- Practise in a lab, never at work. A nested lab covers most of sections H to O. VMware Hands-on Labs cover much of the rest. Search by topic and check each lab runs VCF 9.0.
- Where you cannot break it, write the checklist. Several tasks, such as upgrading from 5.x or a Fibre Channel fault, ask you to write the order you would check things in. That order is what the exam tests.
- Finish with faults somebody else created. Section V is timed, and works best when a colleague breaks things without telling you how.
Workbook163 tasks, in working order
Section A builds a method and a toolkit. Sections B to G cover the platform: deployment, upgrade, workload domains, certificates, passwords, identity and licences. Sections H to O cover compute, storage and networking. Sections P to U cover VCF Operations, VCF Automation, the Supervisor and HCX. Section V is a timed run. Numbers in grey at the right are the objectives.
Before any fault: an order to work in, and the tool for each question.
- 1Write a troubleshooting method in six steps: scope, when it started, what changed, which layer, evidence, fix.5.9›
- 2List the tools VCF 9.0 gives you and the question each answers: VCF Operations, logs, networks, the workbench, Health and Diagnostics, SDDC Manager, vCenter, NSX.5.9›
- 3Find where SDDC Manager keeps its logs, and which log covers domains, operations and lifecycle.5.3›
- 4Find the logs for vCenter, ESX and NSX Manager, and how to reach each.5.6›
- 5Write the support bundle options for each component.5.9›
- 6Write when you would open a case with Broadcom, and what you gather first.5.9›
- 7Set up a lab where you can break things safely, and record what you may not break at work.5.9›
Objective 5.1. Most failed deployments are a prerequisite somebody missed.
- 8Remove a reverse DNS record for one appliance and run installer validation. Read the error.5.1›
- 9Set one host to a different NTP source and run validation. Read the error.5.1›
- 10Set a VLAN or MTU wrongly in the deployment inputs and run validation. Read the error.5.1›
- 11Use a password that breaks the complexity rules and record where the installer stops you.5.1›
- 12Find the installer and bring-up logs, and the first error in a failed run.5.1›
- 13Write how you retry a failed deployment step rather than starting again.5.1›
- 14Write the prerequisites for adding a VCF instance to an existing fleet, and the faults that block it.5.1›
- 15Write what must be cleaned up when an instance is removed from a fleet.5.1›
Objective 5.2. Upgrading from VCF 5.x, and converting vSphere to VCF.
- 16Write the upgrade path from VCF 5.x to 9.0 and the order components are upgraded in.5.2›
- 17Run an upgrade precheck and work through every failure it reports.5.2›
- 18Write the faults that block an upgrade: incompatible versions, a missing bundle, failed hosts, expired passwords or certificates.5.2›
- 19Find the lifecycle logs for a failed upgrade and the first error.5.2›
- 20Write how to retry a failed upgrade task and when not to.5.2›
- 21Write the prerequisites for converting an existing vSphere environment to VCF 9.0.5.2›
- 22Run a conversion precheck in a lab against an environment that fails one prerequisite, and fix it.5.2›
- 23Write what to check after a conversion to prove it worked.5.2›
Objective 5.3. Create, add clusters, add and remove hosts, import.
- 24Commission a host with a wrong password and read the validation error.5.3›
- 25Commission a host whose NTP or DNS is wrong and read the error.5.3›
- 26Exhaust a network pool so a host cannot be added, read the error, and extend the pool.5.3›
- 27Start a workload domain creation with a missing DNS record and find where it fails.5.3›
- 28Find a failed task in SDDC Manager, read its subtasks, and retry it.5.3›
- 29Add a cluster whose hosts do not match the image, and fix it.5.3›
- 30Remove a host from a cluster, and record what blocks it when vSAN cannot evacuate the data.5.3›
- 31Remove a cluster from a workload domain and record what must be empty first.5.3›
- 32Run an import precheck against a vCenter that fails it, and fix each finding.5.3›
- 33Write the most common reasons a vSphere import fails.5.3›
Objective 5.4. The four certificate sub-objectives, each broken and fixed.
- 34Configure a certificate authority with a wrong credential, read the error, and correct it.5.4›
- 35Configure a CA whose own certificate is not trusted, and fix the trust.5.4›
- 36Generate a CSR and check its subject alternative names before it is signed.5.4›
- 37Sign a certificate with a wrong or missing name and see what fails when it is installed.5.4›
- 38Import an external certificate with the full chain, then again without the intermediate. Record the difference.5.4›
- 39Let a lab certificate get close to expiry and confirm auto renewal acts.5.4›
- 40Write what breaks when a vCenter or NSX certificate expires.5.4›
- 41Find the certificate management task history and read a failed replacement.5.4›
Objective 5.4. Password management and the Identity Broker.
- 42Change a managed password directly on the component and find the account out of sync.5.4›
- 43Remediate the out-of-sync account.5.4›
- 44Lock an account with failed sign-ins and unlock it.5.4›
- 45Let a lab password expire and record what stops working.5.4›
- 46Break the Identity Broker connection to the identity provider and diagnose it.5.4›
- 47Remove a user from a mapped group and confirm the access change, then explain a user who still has access.5.4›
- 48Create clock skew on an identity component and record the sign-in error.5.4›
Objective 5.5. Assignment, entitlements and expiry.
- 49Assign a licence to the wrong component and read the result.5.5›
- 50Try to assign more capacity than the licence entitles, and read the error.5.5›
- 51Read the entitlement view and explain a component shown as unlicensed.5.5›
- 52Write what the 9.0 documentation says happens when a VCF licence expires.5.5›
- 53Write how you find which licence is about to expire and who is told.5.5›
- 54Write the steps to replace an expired licence.5.5›
Objective 5.6, part one. The layers everything else sits on.
- 55Disconnect a host from vCenter and reconnect it, recording the cause you created.5.6›
- 56Make a host not responding by stopping its management agents, then restart them.5.6›
- 57Fill a host scratch or log location and read the symptoms.5.6›
- 58Break a host time setting and read what fails.5.6›
- 59Stop a vCenter service and find which feature stopped working.5.6›
- 60Read vCenter service health from its management interface and restart a failed service.5.6›
- 61Write what to check when no one can sign in to vCenter.5.6›
- 62Write how to tell a vCenter database or disk full problem from a service problem.5.6›
Objective 5.6, part two.
- 63Make a virtual machine fail to power on through lack of reserved capacity, and fix it.5.6›
- 64Make a virtual machine lose its network by disconnecting the adapter or port group, and fix it.5.6›
- 65Create a slow virtual machine through a CPU limit, find it, and remove the limit.5.6›
- 66Fail a vMotion on purpose, for example with a missing port group on the target, and read the error.5.6›
- 67Make HA admission control block a power-on and explain it.5.6›
- 68Make DRS fail to balance through an affinity rule, and find the rule.5.6›
- 69Create an EVC mismatch when adding a host, and fix it.5.6›
- 70Write how you find what changed on a cluster in the last day.5.6›
Objective 5.7, part one. Create each fault, then diagnose it.
- 71Break the vSAN network on one host and read the health result and partition.5.7›
- 72Fail a device and watch the rebuild, recording the delay before it starts.5.7›
- 73Fill vSAN close to full and read what stops working first.5.7›
- 74Apply a policy the cluster cannot satisfy and read the compliance error.5.7›
- 75Find an inaccessible object and explain why.5.7›
- 76Read the resyncing objects view and explain why data is moving.5.7›
- 77Run vSAN health checks and work through every failure.5.7›
- 78Write the order you check a vSAN problem in: network, devices, capacity, policy.5.7›
Objective 5.7, part two. VCF availability zones on vSAN.
- 79Cut the witness off in a lab and read what still works.5.7›
- 80Write the latency and bandwidth limits between sites and to the witness, from the documentation.5.7›
- 81Fail one site in a lab and record what restarts and where.5.7›
- 82Apply a policy without site mirroring to a VM in a stretched cluster and record the risk.5.7›
- 83Write what breaks when the networks are not present in both zones.5.7›
- 84Write the checks before adding hosts to a stretched cluster.5.7›
Objective 5.7, part three. iSCSI, NFS and Fibre Channel.
- 85Break iSCSI port binding or a target address, read the error, and fix it.5.7›
- 86Remove a host from an NFS export permission and read the mount error.5.7›
- 87Write how an FC zoning or masking error shows up on the host.5.7›
- 88Write the difference between all paths down and permanent device loss.5.7›
- 89Read the storage paths for a device and find a dead path.5.7›
- 90Write what to collect for the storage team when a datastore disappears.5.7›
Objective 5.8, part one.
- 91Mismatch the MTU on one host and prove it with vmkping.5.8›
- 92Put an uplink on the wrong VLAN and find it.5.8›
- 93Read the distributed switch health check and fix a finding.5.8›
- 94Find a host transport node with a failed status and read why.5.8›
- 95Break tunnel endpoint reachability and read the tunnel status.5.8›
- 96Find the NSX Manager cluster status and a node that is down.5.8›
- 97Write the order you check NSX in: manager, transport nodes, tunnels, edges.5.8›
Objective 5.8, part two.
- 98Take a BGP neighbour down and diagnose it from the Tier-0.5.8›
- 99Remove route advertisement on a Tier-1 and find why a segment is unreachable from outside.5.8›
- 100Use Traceflow to find where a packet is dropped.5.8›
- 101Fail an edge node and record what moves and how long it takes.5.8›
- 102Read the routing table on an edge from the CLI.5.8›
- 103Write the checks when two virtual machines on different segments cannot reach each other.5.8›
- 104Write how a stateful service affects a Tier-0 failover.5.8›
Objective 5.8, part three.
- 105Break DHCP on a segment and find why a virtual machine gets no address.5.8›
- 106Break a NAT rule and find it with Traceflow.5.8›
- 107Write the checks when a VPN tunnel will not come up.5.8›
- 108Block traffic with a distributed firewall rule, then find the rule from the symptom.5.8›
- 109Exhaust a VPC external IP block and read the error a consumer sees.5.8›
- 110Make a VPC public subnet unreachable from outside and trace why.5.8›
- 111Write how transit gateway connectivity affects what a VPC can reach.5.8›
Objective 5.9, part one: when the monitoring itself is broken.
- 112Stop a collector and find the objects with no data.5.9›
- 113Break an adapter credential and read the collection error.5.9›
- 114Read VCF Operations cluster status and a node that is down.5.9›
- 115Break log forwarding from a host and find the gap in VCF Operations for logs.5.9›
- 116Break flow collection for VCF Operations for networks and find the gap.5.9›
- 117Use VCF Operations for networks to find why two virtual machines cannot talk.5.9›
- 118Use VCF Operations for logs to find the first error before an incident.5.9›
- 119Use VCF Operations to find a VCF component in a bad state.5.9›
Objective 5.9, part two: the workbench, log bundles, and building your own views.
- 120Open the troubleshooting workbench for a slow virtual machine and read its findings.5.9›
- 121Use the workbench to find a change that happened just before an incident.5.9›
- 122Generate a log bundle for a component from VCF Operations.5.9›
- 123Upload a log bundle to a support case with Log Assist, or record each step if you have no case.5.9›
- 124Create a dashboard that shows the health of one problem area.5.9›
- 125Create a report that proves an issue is fixed.5.9›
- 126Create an alert that would have caught an issue earlier.5.9›
- 127Write which of the three you would build first in a live incident.5.9›
Objective 5.10, part one. The heading names the Identity Broker; most sub-objectives are VCF Automation.
- 128Break the Identity Broker certificate trust or redirect and diagnose the sign-in failure.5.10›
- 129Map a group to the wrong role and explain the access a user reports.5.10›
- 130Read VCF Automation health and find a service that is down.5.10›
- 131Break VCF Automation connectivity to vCenter or NSX and read the error.5.10›
- 132Write where VCF Automation logs are and how to collect them.5.10›
- 133Write the checks when the provider portal will not load.5.10›
Objective 5.10, part two.
- 134Enable a Supervisor with a wrong network setting and read where it stops.5.10›
- 135Read Supervisor configuration status and its conditions.5.10›
- 136Break the load balancer path and record what a consumer sees.5.10›
- 137Fill a namespace quota and read the error when a VKS cluster is requested.5.10›
- 138Remove a VM class or storage policy from a namespace and request a cluster that needs it.5.10›
- 139Write the checks when a VKS cluster stays in provisioning.5.10›
Objective 5.10, part three. VPC, regions, content libraries, regional networks, storage classes, VM classes, organizations.
- 140Create a region missing a Supervisor and read the error.5.10›
- 141Break a regional network and find why tenants cannot deploy.5.10›
- 142Remove a content library item a catalog item depends on and read the failure.5.10›
- 143Remove a storage class from an organization and request a workload that needs it.5.10›
- 144Remove a VM class and request a workload that needs it.5.10›
- 145Give a VM Apps organization a request only All Apps can serve, and explain the error.5.10›
- 146Exhaust an organization quota and read what the tenant sees.5.10›
- 147Write the checks when a tenant says nothing in the catalog deploys.5.10›
Objective 5.11. Configuration first, then migrations.
- 148Write the HCX components: manager, interconnect, WAN optimisation, network extension.5.11›
- 149Break site pairing, for example with a certificate or DNS error, and fix it.5.11›
- 150Write the ports and network profiles a service mesh needs.5.11›
- 151Read service mesh and tunnel status and explain a tunnel that is down.5.11›
- 152Write the migration types and when each fails: bulk, vMotion, replication-assisted vMotion, cold.5.11›
- 153Fail a migration on purpose, for example with too little target capacity, and read the error.5.11›
- 154Find a migration stuck in progress and read its events.5.11›
- 155Write the checks when an extended network stops passing traffic.5.11›
Do this section twice in the last week, with faults somebody else created.
- 156A host shows not responding. Find the cause. 10 minutes.5.6›
- 157A virtual machine will not power on. Find the cause. 10 minutes.5.6›
- 158A vSAN object is inaccessible. Find the cause. 15 minutes.5.7›
- 159Two virtual machines cannot reach each other. Find where the packet stops. 15 minutes.5.8›
- 160A certificate replacement failed. Find why. 10 minutes.5.4›
- 161A workload domain task failed. Find the subtask and the log line. 15 minutes.5.3›
- 162A tenant cannot deploy. Find the missing piece. 15 minutes.5.10›
- 163An HCX migration is stuck. Find the cause. 15 minutes.5.11›
How to use itFive weeks, if that is what you have
| Week | Sections | Focus |
|---|---|---|
| 1 | A to D | Method, then deployment, upgrade and workload domain faults |
| 2 | E to I | Certificates, passwords, identity, licences, compute |
| 3 | J to O | Storage and networking, the largest share of hands-on faults |
| 4 | P to U | VCF Operations, VCF Automation, the Supervisor and HCX |
| 5 | V | Section V twice, with faults somebody else created |
Work through it online: the interactive workbook. All 163 tasks with what they need first, the steps, and a diagram for each one, searchable and filterable by section or objective, and it keeps your ticks.
Or take it with you: download the PDF (163 tasks). Print it, tick tasks off on paper, and bring the gaps back to the online version.
Preparing for another VCF exam? Pick it from the full list of VCF exam labs.
Exam details are from the published Broadcom exam guide for 2V0-15.25, last updated 15 August 2025, and were checked on 5 October 2026. Broadcom revises blueprints regularly, so confirm the current version before you book. Tasks here are my own, written from the published objectives; they are not exam content.








DrJha