A company needs to enforce security policies on VM traffic without changing its architecture. What should they implement?
APhysical Layer Security
BMicro-Segmentation
CVLAN Tagging
DLayer 2 Tunneling
Explanation
Micro-segmentation can enforce security policies efficiently without altering the existing architecture, unlike the other options.
Q132
What happens when you disconnect a distributed port group from a vSwitch?
AVMs lose all network connectivity
BVMs retain connectivity to other networks
CConnection to vCenter is lost
DOnly VLAN configuration is removed
Explanation
Disconnecting the distributed port group removes network connectivity for the VMs associated with it, while the other options don't accurately reflect the disconnect outcome.
Q133
Which service provides logical load balancing in NSX?
ANSX Load Balancer
BNSX Distributed Firewall
CNSX Edge Services
DNSX VPN Services
Explanation
NSX Load Balancer offers load balancing, while the others serve different functions.
Q134
A company needs to enforce security policies per application. What should they utilize?
ASecurity Groups
BNetwork Segmentation
CEdge Services
DService Insertion
Explanation
Security Groups allow application-level policy enforcement, while the others focus on broader network functions.
Q135
You are configuring a Virtual Tunnel for a secure connection. What happens when the VTEP fails?
ATraffic is rerouted automatically
BAll traffic is dropped
CVTEP appears as down only
DNew VTEP is auto-configured
Explanation
If the VTEP fails, traffic is dropped until a new route is established, unlike other options.
Q136
Which service provides Layer 2 VPN in NSX?
ANSX Segmentation
BNSX VLAN
CNSX VPN Service
DNSX Overlay Transport
Explanation
NSX VPN Service specifically provides Layer 2 VPN capabilities, while the others do not serve this purpose.
Q137
A company needs to segment traffic based on application types. Which NSX feature should they use?
ADistributed Firewall
BLoad Balancer
CEdge Services Gateway
DNSX-T Manager
Explanation
The Distributed Firewall allows for micro-segmentation and application-based traffic policies, unlike other options.
Q138
What happens when an NSX logical switch is deleted?
AVMs lose connectivity immediately
BAll VLAN mappings get removed
CRouting policies are reset
DTraffic flows through amended paths
Explanation
When a logical switch is deleted, associated VMs lose connectivity as they are dependent on that network.
Q139
Which service is used to provide network segmentation in VMware NSX?
ADistributed Firewall
BEdge Services Gateway
CvSphere Networking
DvCloud Director
Explanation
The Distributed Firewall enables effective micro-segmentation, while others don't focus on segmentation.
Q140
A company needs to route traffic between different NSX-T segments. What should they use?
ATier-1 Gateway
BLogical Switch
CFirewall Rules
DLoad Balancer
Explanation
A Tier-1 Gateway routes traffic between segments, whereas others serve different purposes.