Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

VMware NSX-T Data Center 3.1 Security

Last Update 3 hours ago Total Questions : 70

The VMware NSX-T Data Center 3.1 Security content is now fully updated, with all current exam questions added 3 hours ago. Deciding to include 5V0-41.21 practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our 5V0-41.21 exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these 5V0-41.21 sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any VMware NSX-T Data Center 3.1 Security practice test comfortably within the allotted time.

Question # 1

Which two are the insertion points for North-South service insertion? (Choose two.)

A.

Partner Service VM

B.

Uplink of tier-1 gateway

C.

Transport Node NIC

D.

Guest VM vNIC

E.

Uplink of tier-0 gateway

Question # 2

At which two intervals are NSX-T IDS/IPS updates through VMware ' s cloud based internet service provided for threat signature files? (Choose two.)

A.

weekly periodic updates

B.

off-schedule for 0-day updates

C.

monthly periodic updates

D.

daily periodic updates

E.

bi-weekly periodic updates

Question # 3

Which two statements are true about IDS/IPS signatures? (Choose two.)

A.

Users can upload their own IDS signature definitions from the NSX UI.

B.

IDS Signatures can be High Risk, Suspicious, Low Risk and Trustworthy.

C.

Users can create their own IDS signature definitions from the NSX UI.

D.

An IDS signature contains data used to identify known exploits and vulnerabilities.

E.

An IDS signature contains a set of instructions that determine which traffic is analyzed.

Question # 4

An administrator has enabled the " logging " option on a specific firewall rule. The administrator does not see messages on the Logging Server related to this firewall rule. What could be causing the issue?

A.

The logging on the firewall policy needs to be enabled.

B.

Firewall Rule Logging is only supported in Gateway Firewalls.

C.

NSX Manager must have Firewall Logging enabled.

D.

The logging server on the transport nodes is not configured.

Question # 5

When using URL Analysis In NSX-T, which two services must be set in the URL rule to capture traffic over TCP and UDP? (Choose two.)

A.

DNS

B.

DNS-TSIG

C.

DHCPv6

D.

DHCP

E.

DNS-UDP

Question # 6

To which network operations does a user with the Security Engineer role have full access permission?

A.

Networking IP Address Pools, Networking NAT, Networking DHCP

B.

Networking Forwarding Policies, Networking NAT, Networking VPN

C.

Networking Load Balancing, Networking DNS, Networking Forwarding Policies

D.

Networking DHCP, Networking NAT, Networking Segments

Question # 7

An administrator needs to send FW connections logs to a remote server.

Which sequence of commands does the administrator need to apply on their ESXi Host?

A)

B)

C)

D)

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 8

Which three are required to configure a firewall rule on a getaway to allow traffic from the internal to web servers? (Choose three.)

A.

Create a URL analysis profile for web hosting category.

B.

Create a firewall rule in System category.

C.

Enable Firewall Service for gateway.

D.

Create a firewall policy in Local Gateway category.

E.

Add a firewall rule in Local Gateway category.

F.

Disable the firewall rule in Default category.

Question # 9

An NSX administrator is trying to find the dvfilter name of the sa-web-01 virtual machine to capture the sa-web-01 VM traffic. What could be a reason the sa-web-01 VM dvfilter name is missing from the command output?

A.

sa-web-01 VM has the no firewall rules configured.

B.

ESXi host has 5SH disabled.

C.

sa-web-01 is powered Off on ESXi host.

D.

ESXi host has the firewall turned off.

Question # 10

What needs to be configured on each transport node prior to using NSX-T Data Center Distributed Firewall time-based rule publishing?

A.

DNS

B.

NTP

C.

PAT

D.

NAT

Go to page: