Weekend Special Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Question # 4

An administrator is configuring service insertion for Network Introspection.

Which two places can the Network Introspection be configured? (Choose two.)

A.

Edge Node

B.

Host pNIC

C.

Tier-0 gateway

D.

Tier-1 gateway

E.

Partner SVM

Full Access
Question # 5

Which command is used to display the network configuration of the Tunnel Endpoint (TEP) IP on a bare metal transport node?

A.

debug

B.

tcpdump

C.

tcpconfig

D.

ifconfig

Full Access
Question # 6

What are two valid BGP Attributes that can be used to influence the route path traffic will take? (Choose two.)

A.

AS-Path Prepend

B.

BFD

C.

Cost

D.

MED

Full Access
Question # 7

NSX improves the security of today's modern workloads by preventing lateral movement, which feature of NSX can be used to achieve this?

A.

Network Segmentation

B.

Virtual Security Zones

C.

Edge Firewalling

D.

Dynamic Routing

Full Access
Question # 8

Which two statements are true for IPSec VPN? (Choose two.)

A.

IPSec VPN services can be configured at Tier-0 and Tier-1 gateways.

B.

Dynamic routing is supported for any IPSec mode in NSX.

C.

IPSec VPNs use the DPDK accelerated performance library.

D.

VPNs can be configured on the command line interface on the NSX manager.

Full Access
Question # 9

Where in the NSX UI would an administrator set the time attribute for a time-based Gateway Firewall rule?

A.

The option to set time-based rule is a clock Icon in the rule.

B.

The option to set time based rule is a field in the rule Itself.

C.

There Is no option in the NSX UI. It must be done via command line interface.

D.

The option to set time-based rule is a clock Icon in the policy.

Full Access
Question # 10

An administrator wants to validate the BGP connection status between the Tier-0 Gateway and the upstream physical router.

What sequence of commands could be used to check this status on NSX Edge node?

A.

- enable

- get vrf

- show bgp neighbor

B.

- get gateways

- vrf

- get bgp neighbor

C.

- set vrf

- show logical-routers

- show bgp

D.

- show logical-routers

- get vrf

- show ip route bgp

Full Access
Question # 11

Which three protocols could an NSX administrator use to transfer log messages to a remote log server? (Choose three.)

A.

HTTPS

B.

SSH

C.

TCP

D.

UDP

E.

SSL

F.

TLS

Full Access
Question # 12

When deploying an NSX Edge Transport Node, what two valid IP address assignment options should be specified for the TEP IP addresses? (Choose two.)

A.

Use an IP Pool

B.

Use RADIUS

C.

Use a Static IP List

D.

Use BootP

E.

Use a DHCP Server

Full Access
Question # 13

Which two BGP configuration parameters can be configured in the VRF Lite gateways? (Choose two.)

A.

Route Aggregation

B.

Route Distribution

C.

BGP Neighbors

D.

Graceful Restart

E.

Local AS

Full Access
Question # 14

What must be configured on Transport Nodes for encapsulation and decapsulation of Geneve protocol?

A.

TEP

B.

STT

C.

VXLAN

D.

UDP

Full Access
Question # 15

Which is the only supported mode in NSX Global Manager when using Federation?

A.

Proxy

B.

Policy

C.

Controller

D.

Proton

Full Access
Question # 16

An NSX administrator has deployed a single NSX Manager node and will be adding two additional nodes to form a 3-node NSX Management Cluster for a production environment. The administrator will deploy these two additional nodes and Cluster VIP using the NSX UI.

What two are the prerequisites for this configuration? (Choose two.)

A.

The cluster configuration must be completed using API.

B.

All nodes must be in the same subnet.

C.

All nodes must be in separate subnets.

D.

A compute manager must be configured.

E.

NSX Manager must reside on a Windows Server.

Full Access
Question # 17

What are two supported host switch modes? (Choose two.)

A.

Overlay Datapath

B.

Secure Datapath

C.

Standard Datapath

D.

Enhanced Datapath

E.

DPDK Datapath

Full Access
Question # 18

Which tool could be used to configure BGP on a Tier-0 Gateway?

A.

ESX CLI

B.

NSX CLI

C.

API

D.

iPerf3

Full Access
Question # 19

An administrator has been tasked with implementing the SSL certificates for the NSX Manager Cluster VIP.

Which is the correct way to implement this change?

A.

Send an API call to https:// /api/vl/cluster/api-certificate?action=set_cluster_certificate&certificate_id=

B.

Send an API call to https:// /api/vl/node/services/http?action=apply_certificate&certificate_id=

C.

SSH as admin into the NSX manager with the cluster VIP IP and run nsxcli cluster certificate node install

D.

SSH as admin into the NSX manager with the cluster VIP IP and run nsxcli cluster certificate vip install

Full Access
Question # 20

What is VMware’s recommendation for the minimum MTU requirements when planning an NSX deployment?

A.

MTU should be set to 1700 or greater across the data center network including inter-data center connections.

B.

MTU should be set to 1500 or less only on inter-data center connections.

C.

Configure Path MTU Discovery and rely on fragmentation.

D.

MTU should be set to 1550 or less across the data center network including inter-data center connections.

Full Access
Question # 21

Which three security features are dependent on the NSX Application Platform? (Choose three.)

A.

NSX Intelligence

B.

NSX Firewall

C.

NSX Network Detection and Response

D.

NSX TLS Inspection

E.

NSX Distributed IDS/IPS

F.

NSX Malware Prevention

Full Access
Question # 22

Which two of the following parameters are required for deploying the NSX Application Platform? (Choose two.)

A.

Interface Name

B.

Upload XML File

C.

Cluster Format Type

D.

Interface Service Name

E.

Upload Kubernetes Configuration File

Full Access
Question # 23

An NSX administrator is using ping to check connectivity between VM1 running on ESXi1 to VM2 running on ESXi2. The ping tests fail. The administrator knows the maximum transmission unit size on the physical switch is 1600.

Which command does the administrator use to check the VMware kernel ports for tunnel end point communication?

A.

vmkping ++netstack=geneve -d -s 1572

B.

vmkping ++netstack=vxlan -d -s 1572

C.

esxcli network diag ping –H

D.

esxcli network diag ping -I vmk0 -H

Full Access
Question # 24

Which two of the following features are supported for the Standard NSX Application Platform Deployment? (Choose two.)

A.

NSX Intrusion Detection and Prevention

B.

NSX Intelligence

C.

NSX Network Detection and Response

D.

NSX Malware Prevention Metrics

E.

NSX Intrinsic Security

Full Access
Question # 25

What are two valid options when configuring the scope of a distributed firewall rule? (Choose two.)

A.

DFW

B.

Tier-1 Gateway

C.

Segment

D.

Segment Port

E.

Group

Full Access
Question # 26

Refer to the exhibit.

An administrator would like to change the private IP address of the NAT VM 172.16.101.11 to a public address of 80.80.80.1 as the packets leave the NAT-Segment network.

Which type of NAT solution should be implemented to achieve this?

A.

NAT64

B.

Reflexive NAT

C.

DNAT

D.

SNAT

Full Access
Question # 27

An NSX administrator would like to create an L2 segment with the following requirements:

• L2 domain should not exist on the physical switches.

• East/West communication must be maximized as much as possible.

Which type of segment must the administrator choose?

A.

VLAN

B.

Overlay

C.

Bridge

D.

Hybrid

Full Access
Question # 28

An NSX administrator is creating a Tier-1 Gateway configured in Active-Standby High Availability Mode. In the event of node failure, the failover policy should not allow the original failed node to become the Active node upon recovery.

Which failover policy meets this requirement?

A.

Enable Preemptive

B.

Non-Preemptive

C.

Preemptive

D.

Disable Preemptive

Full Access
Question # 29

Which of the two following characteristics about NAT64 are true? (Choose two.)

A.

NAT64 is stateless and requires gateways to be deployed in active-standby mode.

B.

NAT64 is supported on Tier-1 gateways only.

C.

NAT64 is supported on Tier-0 and Tier-1 gateways.

D.

NAT64 requires the Tier-1 gateway to be configured in active-standby mode.

E.

NAT64 requires the Tier-1 gateway to be configured in active-active mode.

Full Access
Question # 30

When configuring OSPF on Tier-0 Gateway, which three of the following must match in order to establish a neighbor relationship with an upstream router? (Choose three.)

A.

Area ID

B.

MTU of the Uplink

C Naming convention

C.

Address of the neighbor

D.

Subnet mask

E.

Protocol and Port

Full Access
Question # 31

Which two statements are correct about East-West Malware Prevention? (Choose two.)

A.

A SVM is deployed on every ESXi host.

B.

NSX Application Platform must have Internet access.

C.

An agent must be installed on every ESXi host.

D.

An agent must be installed on every NSX Edge node.

E.

NSX Edge nodes must have Internet access.

Full Access
Question # 32

What should an NSX administrator check to verify that VMware Identity Manager integration is successful?

A.

From the NSX Ul the status of the VMv/are Identity Manager Integration must be Enabled'

B.

From the NSX CLI the status of the VMware Identity Manager Integration must be Configured'

C.

From VMware Identity Manager the status of the remote access application must be green

D.

From the NSX Ul the URI in the address bar must have locaMalstf part of it.

Full Access
Question # 33

Which two of the following will be used for ingress traffic on the Edge node supporting a Single Tier topology? (Choose two.)

A.

Tier-1 SR Router Port

B.

Tier-0 Uplink interface

C.

Downlink Interface for the Tier-0 DR

D.

Downlink Interface for the Tier-1 DR

E.

Inter-Tier interface on the Tier-0 gateway

Full Access
Question # 34

When running nsxcli on an ESXi host, which command will show the Replication mode?

A.

get logical-switch status

B.

get logical-switch

C.

get logical-switches

D.

get logical-switch status

Full Access