Black Friday Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

VMware 5V0-41.21 VMware NSX-T Data Center 3.1 Security Exam Practice Test

Demo: 10 questions
Total 70 questions

VMware NSX-T Data Center 3.1 Security Questions and Answers

Question 1

Which two are used to define dynamic groups for an NSX Distributed Firewall? (Choose two.)

Options:

A.

segment

B.

physical servers

C.

machine name

D.

tags

E.

segment's port

Question 2

A security administrator has configured NSX Intelligence for discovery. They would like to get recommendations based on the changes in the scope of the input entities every hour.

What needs to be configured to achieve the requirement?

Options:

A.

Start a new recommendation.

B.

Publish the recommendations.

C.

Toggle the monitoring option on.

D.

Adjust the time range to 1 hour.

Question 3

Which of the following describes the main concept of Zero-Trust Networks for network connected devices?

Options:

A.

Network connected devices should only be trusted if they are issued by the organization.

B.

Network connected devices should only be trusted if the user can be successfully authenticated.

C.

Network connected devices should only be trusted if their identity and integrity can be verified continually.

D.

Network connected devices should only be trusted if they are within the organizational boundary.

Question 4

An NSX administrator has been tasked with deploying a NSX Edge Virtual machine through an ISO image.

Which virtual network interface card (vNIC) type must be selected while creating the NSX Edge VM allow participation in overlay and VLAN transport zones?

Options:

A.

e1000

B.

VMXNET2

C.

VMXNET3

D.

Flexible

Question 5

An administrator is creating the first distributed firewall rules for a company's salts department. What is the first object that must be created in the distributed firewall'

Options:

A.

firewall policy

B.

firewall file

C.

firewall folder

D.

firewall service

Question 6

Which two are requirements for URL Analysis? (Choose two.)

Options:

A.

The ESXi hosts require access to the Internet to download category and reputation definitions.

B.

A layer 7 gateway firewall rule must be configured on the tier-0 gateway uplink to capture DNS traffic.

C.

A layer 7 gateway firewall rule must be configured on the tier-1 gateway uplink to capture DNS traffic,

D.

The NSX Edge nodes require access to the Internet to download category and reputation definitions.

E.

The NSX Manager requires access to the Internet to download category and reputation definitions.

Question 7

What is the NSX feature that allows a user to block ICMP between 192.168.1.100 and 192.168.1.101?

Options:

A.

NSX Distributed Switch Agent

B.

NSX Distributed IDS/IPS

C.

NSX Distributed Routing

D.

NSX Distributed Firewall

Question 8

Which are two use-cases for the NSX Distributed Firewall' (Choose two.)

Options:

A.

Zero-Trust with segmentation

B.

Security Analytics

C.

Lateral Movement of Attacks prevention

D.

Software defined networking

E.

Network Visualization

Question 9

Refer to the exhibit.

Referencing the exhibit, what is the VMware recommended number of NSX Manager Nodes to additionally deploy to form an NSX-T Manager Cluster?

Options:

A.

4

B.

3

C.

2

D.

5

Question 10

Which are the four use cases for NSX Tags?

Options:

A.

Accountability, Third-party sharing/context sharing. Security, and Logging

B.

Manageability, Third-party sharing/context sharing, Security, and Troubleshooting (Traceability)

C.

Accountability, Third-party sharing/context sharing, Security, and Troubleshooting (Traceability)

D.

Manageability, Third-party sharing/context sharing. Security, and Logging

Demo: 10 questions
Total 70 questions