New Year Special Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

VMware 2V0-41.24 VMware NSX 4.X Professional V2 Exam Practice Test

Page: 1 / 12
Total 115 questions

VMware NSX 4.X Professional V2 Questions and Answers

Question 1

Which two tools are used for centralized logging in VMware NSX? (Choose two.)

Options:

A.

Sysloq Server

B.

VMware Aria Automation

C.

VMware Aria Operations for Logs

D.

VMware Aria Operations for Networks

E.

VMware Aria Operations

Question 2

An administrator needs to download the support bundle for NSX Manager.

Where does the administrator download the log bundle from?

Options:

A.

System > Support Bundle

B.

System > Settings

C.

System > Utilities > Tools

D.

System > Settings > Support Bundle

Question 3

Which three of the following describe the Border Gateway Routing Protocol (BGP) configuration on a Tier-0 Gateway? (Choose three.)

Options:

A.

It supports a 4-byte autonomous system number.

B.

Can be used as an Exterior Gateway Protocol.

C.

The network is divided into areas that are logical groups.

D.

EIGRP is disabled by default.

E.

BGP is enabled by default.

Question 4

Which two commands does an NSX administrator use to check the IP address of the VMkernel port for the Geneve protocol on the ESXi transport node? (Choose two.)

Options:

A.

net-dvs

B.

esxcfg-nics -l

C.

esxcli network ip interface ipv4 get

D.

esxcfg-vmknic -l

E.

esxcli network nic list

Question 5

What can the administrator use to identify overlay segments in an NSX environment if troubleshooting is required?

Options:

A.

Geneve ID

B.

VMI ID

C.

Segment ID

D.

VLANID

Question 6

What are two functions of the Service Engines in NSX Advanced Load Balancer? (Choose two.)

Options:

A.

It collects real-time analytics from application traffic flows.

B.

It stores the configuration and policies related to load-balancing services.

C.

It performs application load-balancing operations.

D.

It deploys web servers to perform load-balancing operations.

E.

It provides a user interface to perform configuration and management tasks.

Question 7

Refer to the exhibit.

An administrator configured NSX Advanced Load Balancer to load balance the production web server traffic, but the end users are unable to access the production website by using the VIP address.

Which of the following Tier-1 gateway route advertisement settings needs to be enabled to resolve the problem? Mark the correct answer by clicking on the image.

Question # 7

Options:

Question 8

A customer is preparing to deploy a VMware Kubernetes solution in an NSX environment.

What is the minimum MTU size for the UPLINK profile?

Options:

A.

1700

B.

1500

C.

1550

D.

1650

Question 9

Which three protocols could an NSX administrator use to transfer log messages to a remote log server? (Choose three.)

Options:

A.

HTTPS

B.

SSH

C.

TCP

D.

UDP

E.

SSL

F.

TLS

Question 10

What is the VMware recommended way to deploy a virtual NSX Edge Node?

Options:

A.

Through the NSX Ul

B.

Through automated or interactive mode using an ISO

C.

Through the vSphere Web Client

D.

Through the OVF command line tool

Question 11

A security administrator needs to configure a firewall rule based on the domain name of a specific application.

Which field in a distributed firewall rule does the administrator configure?

Options:

A.

Profile

B.

Service

C.

Policy

D.

Source

Question 12

Where is the insertion point for East-West network introspection?

Options:

A.

Tier-0 router

B.

Guest VM vNIC

C.

Partner SVM

D.

Host Physical NIC

Question 13

Which statement is true about an alarm in a Suppressed state?

Options:

A.

An alarm can be suppressed for a specific duration in hours.

B.

An alarm can be suppressed for a specific duration in seconds.

C.

An alarm can be suppressed for a specific duration in days.

D.

An alarm can be suppressed for a specific duration in minutes

Question 14

Where in the NSX UI would an administrator set the time attribute for a time-based Gateway Firewall rule?

Options:

A.

The option to set time-based rule is a clock Icon in the rule.

B.

The option to set time based rule is a field in the rule Itself.

C.

There Is no option in the NSX UI. It must be done via command line interface.

D.

The option to set time-based rule is a clock Icon in the policy.

Question 15

Which of the two following characteristics about NAT64 are true? (Choose two.)

Options:

A.

NAT64 is stateless and requires gateways to be deployed in active-standby mode.

B.

NAT64 is supported on Tier-1 gateways only.

C.

NAT64 is supported on Tier-0 and Tier-1 gateways.

D.

NAT64 requires the Tier-1 gateway to be configured in active-standby mode.

E.

NAT64 requires the Tier-1 gateway to be configured in active-active mode.

Question 16

An administrator is configuring service insertion for Network Introspection.

Which two places can the Network Introspection be configured? (Choose two.)

Options:

A.

Edge Node

B.

Host pNIC

C.

Tier-0 gateway

D.

Tier-1 gateway

E.

Partner SVM

Question 17

Which choice is a valid insertion point for North-South network introspection?

Options:

A.

Host Physical NIC

B.

Tier-0 gateway

C.

Guest VM vNIC

D.

Partner SVM

Question 18

Which two statements are true for IPSec VPN? (Choose two.)

Options:

A.

IPSec VPN services can be configured at Tier-0 and Tier-1 gateways.

B.

Dynamic routing is supported for any IPSec mode in NSX.

C.

IPSec VPNs use the DPDK accelerated performance library.

D.

VPNs can be configured on the command line interface on the NSX manager.

Question 19

A company Is deploying NSX micro-segmentation in their vSphere environment to secure a simple application composed of web. app, and database tiers.

The naming convention will be:

• WKS-WEB-SRV-XXX

• WKY-APP-SRR-XXX

• WKI-DB-SRR-XXX

What is the optimal way to group them to enforce security policies from NSX?

Options:

A.

Use Edge as a firewall between tiers.

B.

Do a service insertion to accomplish the task.

C.

Group all by means of tags membership.

D.

Create an Ethernet based security policy.

Question 20

A customer has a network where BGP has been enabled and the BGP neighbor is configured on the Tier-0 Gateway. An NSX administrator used the get gateways command to retrieve this information:

Question # 20

Which two commands must be executed to check BGP neighbor status? (Choose two.)

Options:

A.

vrf 3

B.

sa-nsxedge-01(tier0_dr)> get bgp neighbor

C.

vrf 1

D.

sa-nsxedge-01(tier1_sr)> get bgp neighbor

E.

sa-nsxedge-01(tier0_sr)> get bgp neighbor

F.

vrf 4

Question 21

What are two valid BGP Attributes that can be used to influence the route path traffic will take? (Choose two.)

Options:

A.

AS-Path Prepend

B.

BFD

C.

Cost

D.

MED

Question 22

Refer to the exhibit.

An administrator configured NSX Advanced Load Balancer to redistribute the traffic between the web servers. However, requests are sent to only one server

Which of the following pool configuration settings needs to be adjusted to resolve the problem? Mark the correct answer by clicking on the image.

Question # 22

Options:

Question 23

Which two steps must an NSX administrator take to integrate VMware Identity Manager in NSX to support role-based access control? (Choose two.)

Options:

A.

Create a SAML authentication in VMware Identity Manager using the NSX Manager FQDN.

B.

Add NSX Manager as a Service Provider (SP) in VMware Identity Manager.

C.

Enter the Identity Provider (IdP) metadata URL in NSX Manager.

D.

Enter the service URL, Client Secret, and SSL thumbprint in NSX Manager.

E.

Create an OAuth 2.0 client in VMware Identity Manager.

Question 24

An NSX administrator wants to create a Tier-0 Gateway to support equal cost multi-path (ECMP) routing.

Which failover detection protocol must be used to meet this requirement?

Options:

A.

Host Standby Router Protocol (HSRP)

B.

Beacon Probing (BP)

C.

Virtual Router Redundancy Protocol (VRRP)

D.

Bidirectional Forwarding Detection (BFD)

Question 25

Which of the two following characteristics about NAT64 are true? (Choose two.)

Options:

A.

NAT64 requires the Tier-1 gateway to be configured in active-active mode.

B.

NAT64 is stateless and requires gateways to be deployed in active-standby mode.

C.

NAT64 is supported on Tier-0 and Tier-1 gateways.

D.

NAT64 is supported on Tier-1 gateways only.

E.

NAT64 requires the Tier-1 gateway to be configured in active-standby mode.

Question 26

Which table on an ESXi host is used to determine the location of a particular workload for a frame-forwarding decision?

Options:

A.

Routing Table

B.

ARP Table

C.

TEP Table

D.

MAC Table

Question 27

An administrator has a requirement to have consistent policy configuration and enforcement across NSX instances.

What feature of NSX fulfills this requirement?

Options:

A.

Multi-hvpervisor support

B.

Federation

C.

Load balancer

D.

Policy-driven configuration

Question 28

Which three DHCP Services are supported by NSX? (Choose three.)

Options:

A.

Gateway DHCP

B.

Segment DHCP

C.

DHCP Relay

D.

Port DHCP per VNF

E.

VRF DHCP Server

Question 29

What must be configured on Transport Nodes for encapsulation and decapsulation of Geneve protocol?

Options:

A.

TEP

B.

STT

C.

VXLAN

D.

UDP

Question 30

Which two statements are correct about East-West Malware Prevention? (Choose two.)

Options:

A.

A SVM is deployed on every ESXi host.

B.

NSX Application Platform must have Internet access.

C.

An agent must be installed on every ESXi host.

D.

An agent must be installed on every NSX Edge node.

E.

NSX Edge nodes must have Internet access.

Question 31

Which two built-in VMware tools will help identify the cause of packet loss on VLAN Segments? (Choose two.)

Which two built-in VMware tools will help identify the cause of packet loss on VLAN Segments? (Choose two.)

Options:

A.

Flow Monitoring

B.

Traceflow

C.

Live Flow

D.

Packet Capture

E.

Activity Monitoring

Question 32

An NSX administrator is using ping to check connectivity between VM1 running on ESXi1 to VM2 running on ESXi2. The ping tests fail. The administrator knows the maximum transmission unit size on the physical switch is 1600.

Which command does the administrator use to check the VMware kernel ports for tunnel end point communication?

Options:

A.

vmkping ++netstack=geneve -d -s 1572

B.

vmkping ++netstack=vxlan -d -s 1572

C.

esxcli network diag ping –H

D.

esxcli network diag ping -I vmk0 -H

Question 33

What are two valid options when configuring the scope of a distributed firewall rule? (Choose two.)

Options:

A.

DFW

B.

Tier-1 Gateway

C.

Segment

D.

Segment Port

E.

Group

Question 34

An NSX administrator is troubleshooting a connectivity issue with virtual machines running on an ESXi transport node.

Which feature in the NSX UI shows the mapping between the virtual NIC and the host’s physical adapter?

Options:

A.

Port Mirroring

B.

Activity Monitoring

C.

IPF1X

D.

Switch Visualization

Page: 1 / 12
Total 115 questions