Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

VMware vDefend Security for VCF 5.x Administrator

Last Update 3 hours ago Total Questions : 75

The VMware vDefend Security for VCF 5.x Administrator content is now fully updated, with all current exam questions added 3 hours ago. Deciding to include 6V0-21.25 practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our 6V0-21.25 exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these 6V0-21.25 sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any VMware vDefend Security for VCF 5.x Administrator practice test comfortably within the allotted time.

Question # 11

Which vDefend Gateway Firewall feature is ONLY supported on T1 Gateways?

A.

Gateway IDRS

B.

Stateful Services on A/A Gateways

C.

Gateway IDFW

D.

L3/L4 Gateway Firewall

Question # 12

vDefend firewall provides support to VMs connected to which of the following?

A.

VMs connected to Overlay Networks

B.

VMs connected to VLAN Networks

C.

VMs connected to DvPG Networks

D.

All of the above

Question # 13

Which of the following are true regarding vDefend Intelligence? (Select all that apply)

A.

Flow data is collected from selected clusters or standalone hosts

B.

Flow data retention is 1-year

C.

Recommendations can generate L7 security rules

D.

Recommended security policies can include a default allow/deny rule

Question # 14

Which statements are true for DFW and Rule processing order based on the information shown in the image? (Select all that apply)

[root@vesxi-nsxt-10:~] vsipioctl getconfig -f nic-2292571-ethO-vmware-sfw.2

ruleset mains {

# generation number: 0

# realization time : 2020-05-21T13:01:48

# FILTER rules

rule 1596 at 1 inout protocol tcp from addrset e70a9a79-c346-48c4-8b9d- 402e97e38a7c to addrset be665396-14d9-4ee4-98b9- 9c21ebfl27a port 464 accept;

rule 1596 at 2 inout protocol udp from addrset e70a9a79-c346-48c4-8b9d- 402e97e38a7c to addrset be665396-14d9-4ee4-98b9- 9c21ebfl27a port 464 accept;

rule 1595 at 3 inout protocol udp from addrset e70a9a79-c346-48c4-8b9d- 402e97e38a7c to addrset 9edl2e5f-36f4-42a9-a79b- 87efc243alef port 53 accept;

rule 1594 at 4 inout protocol udp from addrset e70a9a79-c346-48c4-8b9d- 402e97e38a7c to addrset 59e6aa90-e360-4341-9fb3- b312772b79fb port 123 accept;

rule 2 at 5 inout protocol any from any to any accept;

}

A.

Rule 1595 will be processed before rule 1596

B.

Rule 1594 will be processed after 1595 and 1596

C.

Rule 1596 will be the first one to be processed

D.

Rule 2 will only be processed if the conditions for the above rules are not met

Question # 15

Which of the following is a benefit of combining Distributed IDS/IPS with Gateway IDS/IPS?

A.

Enhancing detection coverage for North/South and East/West traffic

B.

Eliminating the need for intrusion detection on virtual machines

C.

Reducing the reliance on NSX for security enforcement

D.

Allowing NSX-T to function without Service Routers

Question # 16

Which following roles are pre-configured in roles and cannot be modified? (Select all that apply)

A.

Principal Identity Users

B.

External Users

C.

Local Users

D.

Admin

E.

Guest Users

F.

Audit

G.

Analyst

Question # 17

Which of the following are true regarding Antrea? (Select all that apply)

A.

Antrea Agent runs on every Worker Node

B.

Antrea integration allows support of mixed rules of Virtual Machines and Kubernetes objects

C.

Antrea Agent computes NetworkPolicies from K8s and publishes the results to the Antrea Controller

D.

Antrea Agent runs on every node of the management cluster

Question # 18

Which of the following is true regarding private IP ranges in NTA?

A.

Private IP ranges are added manually

B.

Private IP ranges are automatically in scope based on RFC1918

C.

Private IP ranges are automatically in scope based on RFC1918 and manually added

D.

Private IP ranges are based on user-defined IP pools

Question # 19

Which of the following is NOT true regarding the Gateway IDS/IPS?

A.

Can be combined with Decryption policies

B.

Distributed IDS/IPS must be configured to utilize Gateway IDS/IPS

C.

Distributed IDS/IPS and Gateway IDS/IPS have same set of signatures

D.

Can be used to Detect/Prevent intrusions at network or Zone perimeter

Question # 20

VMware vDefend Security Services Platform (SSP) is required for which of the following security features? (Select all that apply)

A.

Security Intelligence

B.

Network Detection and Response

C.

Network Traffic Analysis

D.

Malware Protection

E.

Distributed Firewall Security Policy

F.

Gateway Firewall Security Policy

Go to page: