New Year Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

VMware 2V0-41.24 VMware NSX 4.X Professional V2 Exam Practice Test

Demo: 34 questions
Total 115 questions

VMware NSX 4.X Professional V2 Questions and Answers

Question 1

Refer to the exhibit.

An administrator configured NSX Advanced Load Balancer to redistribute the traffic between the web servers. However, requests are sent to only one server

Which of the following pool configuration settings needs to be adjusted to resolve the problem? Mark the correct answer by clicking on the image.

Options:

Question 2

Which two commands does an NSX administrator use to check the IP address of the VMkernel port for the Geneve protocol on the ESXi transport node? (Choose two.)

Options:

A.

net-dvs

B.

esxcfg-nics -l

C.

esxcli network ip interface ipv4 get

D.

esxcfg-vmknic -l

E.

esxcli network nic list

Question 3

What are two valid options when configuring the scope of a distributed firewall rule? (Choose two.)

Options:

A.

DFW

B.

Tier-1 Gateway

C.

Segment

D.

Segment Port

E.

Group

Question 4

Which VPN type must be configured before enabling an L2VPN?

Options:

A.

Policy-based IPSec VPN

B.

Port-based IPSec VPN

C.

SSL-based IPSec VPN

D.

Route-based IPSec VPN

Question 5

An NSX administrator has deployed a single NSX Manager node and will be adding two additional nodes to form a 3-node NSX Management Cluster for a production environment. The administrator will deploy these two additional nodes and Cluster VIP using the NSX UI.

What two are the prerequisites for this configuration? (Choose two.)

Options:

A.

The cluster configuration must be completed using API.

B.

All nodes must be in the same subnet.

C.

All nodes must be in separate subnets.

D.

A compute manager must be configured.

E.

NSX Manager must reside on a Windows Server.

Question 6

Which steps are required to activate Malware Prevention on the NSX Application Platform?

Options:

A.

Select Cloud Region and Deploy Network Detection and Response.

B.

Activate NSX Network Detection and Response and run Pre-checks.

C.

Activate NSX Network Detection and Response and Deploy Malware Prevention.

D.

Select Cloud Region and run Pre-checks.

Question 7

Which field in a Tier-1 Gateway Firewall would be used to allow access for a collection of trustworthy web sites?

Options:

A.

Source

B.

Profiles -> Context Profiles

C.

Destination

D.

Profiles -> L7 Access Profile

Question 8

Which is an advantage of an L2 VPN in an NSX 4.x environment?

Options:

A.

Achieve better performance

B.

Use the same broadcast domain

C.

Enables Multi-Cloud solutions

D.

Enables VM mobility with re-IP

Question 9

An administrator wants to validate the BGP connection status between the Tier-0 Gateway and the upstream physical router.

What sequence of commands could be used to check this status on NSX Edge node?

Options:

A.

- enable

- get vrf

- show bgp neighbor

B.

- get gateways

- vrf

- get bgp neighbor

C.

- set vrf

- show logical-routers

- show bgp

D.

- show logical-routers

- get vrf

- show ip route bgp

Question 10

When running nsxcli on an ESXi host, which command will show the Replication mode?

Options:

A.

get logical-switch status

B.

get logical-switch

C.

get logical-switches

D.

get logical-switch status

Question 11

Match the NSX Intelligence recommendations with their correct purpose.

Options:

Question 12

An NSX administrator noticed that the nsxcli command times out after 600 secs of idle time.

Which CLI command disables the nsxcli time out value on NSX Manager?

Options:

A.

set cli-timeout 1

B.

set cli-timeout enabled

C.

set cli-timeout disabled

D.

set cli-timeout 0

Question 13

A company security policy requires all users to log into applications using a centralized authentication system.

Which two authentication, authorization, and accounting (AAA) systems are available when integrating NSX with VMware Identity Manager? (Choose two.)

Options:

A.

RSA SecureID

B.

SecureDAP

C.

RADII 2.0

D.

LDAP and OpenLDAP based on Active Directory (AD)

E.

Keygen Enterprise

Question 14

Which two BGP configuration parameters can be configured in the VRF Lite gateways? (Choose two.)

Options:

A.

Route Aggregation

B.

Route Distribution

C.

BGP Neighbors

D.

Graceful Restart

E.

Local AS

Question 15

An architect receives a request to apply distributed firewall in a customer environment without making changes to the network and vSphere environment. The architect decides to use Distributed Firewall on VDS.

Which two of the following requirements must be met in the environment? (Choose two.)

Options:

A.

vCenter 8.0 and later

B.

NSX version must be 3.2 and later

C.

NSX version must be 3.0 and later

D.

VDS version 6.6.0 and later

Question 16

Which three data collection sources are used by NSX Network Detection and Response to create correlations/Intrusion campaigns? (Choose three.)

Options:

A.

Files and anti-malware (lie events from the NSX Edge nodes and the Security Analyzer

B.

East-West anti-malware events from the ESXi hosts

C.

Distributed Firewall flow data from the ESXi hosts

D.

IDS/IPS events from the ESXi hosts and NSX Edge nodes

E.

Suspicious Traffic Detection events from NSX Intelligence

Question 17

Which of the following exist only on Tler-1 Gateway firewall configurations and not on Tier-0?

Options:

A.

Applied To

B.

Actions

C.

Profiles

D.

Sources

Question 18

Which CLI command does an NSX administrator run on the NSX Manager to generate support bundle logs if the NSX UI is inaccessible?

Options:

A.

esxcli system syslog config logger set --id=nsxmanager

B.

get support-bundle file vcpnv.tgz

C.

vm-support

D.

set support-bundle file vcpnv.tgz

Question 19

Which NSX CLI command is used to change the authentication policy for local users?

Options:

A.

set hardening-policy

B.

get auth-policy minimum-password-length

C.

set cli-timeout

D.

set auth-policy

Question 20

A company Is deploying NSX micro-segmentation in their vSphere environment to secure a simple application composed of web. app, and database tiers.

The naming convention will be:

• WKS-WEB-SRV-XXX

• WKY-APP-SRR-XXX

• WKI-DB-SRR-XXX

What is the optimal way to group them to enforce security policies from NSX?

Options:

A.

Use Edge as a firewall between tiers.

B.

Do a service insertion to accomplish the task.

C.

Group all by means of tags membership.

D.

Create an Ethernet based security policy.

Question 21

Which two of the following parameters are required for deploying the NSX Application Platform? (Choose two.)

Options:

A.

Interface Name

B.

Upload XML File

C.

Cluster Format Type

D.

Interface Service Name

E.

Upload Kubernetes Configuration File

Question 22

When deploying an NSX Edge Transport Node, what two valid IP address assignment options should be specified for the TEP IP addresses? (Choose two.)

Options:

A.

Use an IP Pool

B.

Use RADIUS

C.

Use a Static IP List

D.

Use BootP

E.

Use a DHCP Server

Question 23

Which two are supported by L2 VPN clients? (Choose two.)

Options:

A.

NSX Autonomous Edge

B.

NSX Edge

C.

NSX for vSphere Edge

D.

3rd party Hardware VPN Device

Question 24

What must be configured on Transport Nodes for encapsulation and decapsulation of Geneve protocol?

Options:

A.

TEP

B.

STT

C.

VXLAN

D.

UDP

Question 25

Which three DHCP Services are supported by NSX? (Choose three.)

Options:

A.

Gateway DHCP

B.

Segment DHCP

C.

DHCP Relay

D.

Port DHCP per VNF

E.

VRF DHCP Server

Question 26

An administrator has deployed 10 Edge Transport Nodes in their NSX Environment, but has forgotten to specify an NTP server during the deployment.

What is the efficient way to add an NTP server to all 10 Edge Transport Nodes?

Options:

A.

Use a Node Profile

B.

Use Transport Node Profile

C.

Use the CLI on each Edge Node

D.

Use a PowerCLI script

Question 27

Which statement is true about an alarm in a Suppressed state?

Options:

A.

An alarm can be suppressed for a specific duration in hours.

B.

An alarm can be suppressed for a specific duration in seconds.

C.

An alarm can be suppressed for a specific duration in days.

D.

An alarm can be suppressed for a specific duration in minutes

Question 28

In which VPN type are the Virtual Tunnel interfaces (VTI) used?

Options:

A.

SSL-based VPN

B.

Route & SSL based VPNs

C.

Policy & Route based VPNs

D.

Route-based VPN

Question 29

Which two logical router components span across all transport nodes? (Choose two.)

Options:

A.

SERVICE_ROUTER_TIER0

B.

TIER0_DISTRIBUTED_ROUTER

C.

DISTRIBUTED_ROUTER_TIER0

D.

DISTRIBUTED_ROUTER_TIER1

E.

SERVICE_ROUTER_TIER1

Question 30

Refer to the exhibits.

Drag and drop the NSX graphic element icons on the left found in an NSX Intelligence visualization graph to Its correct description on the right.

Options:

Question 31

Which two are requirements for FQDN Analysis? (Choose two.)

Options:

A.

The NSX Edge nodes require access to the Internet to download category and reputation definitions.

B.

ESXi control panel requires access to the Internet to download category and reputation definitions.

C.

The NSX Manager requires access to the Internet to download category and reputation definitions.

D.

A layer 7 gateway firewall rule must be configured on the Tier-1 gateway uplink.

E.

A layer 7 gateway firewall rule must be configured on the Tier-0 gateway uplink.

Question 32

The security administrator turns on logging for a firewall rule.

Where is the log stored on an ESXi transport node?

Options:

A.

/var/log/messages.log

B.

/var/log/vmware/nsx/firewall.log

C.

/var/log/fw.log

D.

/var/log/dfwpktlogs.log

Question 33

What can the administrator use to identify overlay segments in an NSX environment if troubleshooting is required?

Options:

A.

Geneve ID

B.

VMI ID

C.

Segment ID

D.

VLANID

Question 34

Which NSX feature can be leveraged to achieve consistent policy configuration and simplicity across sites?

Options:

A.

VRF Lite

B.

Ethernet VPN

C.

NSX MTML5 UI

D.

NSX Federation

Demo: 34 questions
Total 115 questions