A company needs to segment its development environment without adding hardware. Which NSX feature should be used?
AVirtual Routing
BMicro-Segmentation
CLoad Balancer
DVPN Service
Explanation
Micro-segmentation provides internal security without hardware.
Q102
You are configuring the NSX Edge. What happens when you incorrectly set the HA mode to 'disabled'?
AHigh Availability is active
BRedundant Edge instances deploy
CFailover will not occur
DPerformance will improve
Explanation
Disabling HA prevents automatic failover to redundancy.
Q103
Which service in NSX provides load balancing?
ANSX Load Balancer
BNSX Edge Services
CNSX Firewall
DNSX Route Reflector
Explanation
NSX Load Balancer is specifically designed for load balancing, while the others serve different functions.
Q104
A company needs to ensure that traffic between virtual machines on different segments has strict security policies. What feature should they use?
ANSX Distributed Firewall
BNSX Edge Firewall
CNSX Security Groups
DNSX VPN
Explanation
The NSX Distributed Firewall enforces security policies at the VM level across segments, while the others do not provide that granularity.
Q105
You are configuring a multi-site NSX environment. What happens when a site goes offline?
AAll traffic is rerouted instantly
BTraffic is stalled until restored
CActive/Active load balancing fails
DTraffic can still reach local resources
Explanation
Local resources remain accessible due to local forwarding, while other options misrepresent the expected behavior.
Q106
Which service provides Layer 2 VPN capabilities in NSX?
ANSX-T Edge
BNSX Cloud
CNSX Load Balancer
DNSX Firewall
Explanation
NSX-T Edge provides Layer 2 VPN, while others serve different purposes.
Q107
A company needs to isolate different tenant networks on the same physical infrastructure. What technology should they implement?
AVLANs
BVRFs
CNSX Segments
DStatic Routing
Explanation
NSX Segments allow for logical isolation, unlike traditional methods listed.
Q108
What happens when an NSX-D logical switch receives an ARP packet for an IP not in its subnet?
AIt drops the packet.
BIt replies with an ARP response.
CIt forwards to the default gateway.
DIt floods within the logical switch.
Explanation
The logical switch drops packets for unknown IP addresses.
Q109
Which NSX service handles east-west traffic segmentation?
ANSX Distributed Firewall
BNSX Edge Services Gateway
CNSX Load Balancer
DNSX VPN Service
Explanation
The NSX Distributed Firewall is specifically designed to segment and control east-west traffic within the data center, while the other options serve different functions.
Q110
A company needs to connect its on-premises data center with a cloud provider securely. What is the best solution?
ANSX VPN
BNSX Load Balancing
CNSX Data Security
DNSX Distributed Router
Explanation
NSX VPN provides secure connections for hybrid deployments, while the other options do not offer a direct method for secure connectivity.