nerdexam
Broadcom-VMware

2V0-13.24 · Question #35

A customer is designing a new VMware Cloud Foundation stretched cluster using L2 non-uniform connectivity, where due to a past incident an attacker was able to inject some false routes into their…

The correct answer is D. BGP peer password. The scenario involves designing a VMware Cloud Foundation (VCF) stretched cluster with L2 non- uniform connectivity, leveraging NSX (a core component of VCF) for networking. The customer's past incident, where an attacker injected false routes into their dynamic global routing…

Section 4 – Secure VMware Cloud Foundation Solutions

Question

A customer is designing a new VMware Cloud Foundation stretched cluster using L2 non-uniform connectivity, where due to a past incident an attacker was able to inject some false routes into their dynamic global routing table. What design decision can be taken to prevent this when configuring the Tier-0 gateway?

Options

  • AOSPF MD5 authentication
  • BGateway Firewall with ECMP
  • CImplicit deny for any traffic
  • DBGP peer password

How the community answered

(34 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    9% (3)
  • D
    82% (28)

Explanation

The scenario involves designing a VMware Cloud Foundation (VCF) stretched cluster with L2 non- uniform connectivity, leveraging NSX (a core component of VCF) for networking. The customer's past incident, where an attacker injected false routes into their dynamic global routing table, indicates a security vulnerability in the routing protocol. The Tier-0 gateway in NSX handles external connectivity and routing, typically using dynamic routing protocols like BGP (Border Gateway Protocol) or OSPF (Open Shortest Path First) to exchange routes with external routers. The design decision must prevent unauthorized route injection, ensuring the integrity of the Context Analysis: Stretched Cluster with L2 Non-Uniform Connectivity: In VCF 5.2, a stretched cluster spans multiple availability zones (AZs) with L2 connectivity for workload VMs, but the Tier-0 gateway uplinks may use L3 routing to external networks. "Non-uniform" suggests varying latency or bandwidth between sites, but this does not directly impact the routing security concern. False Routes Injection: This implies the attacker exploited a lack of authentication or filtering in the routing protocol, allowing unauthorized route advertisements to be accepted into the Tier-0 gateway's routing table. Tier-0 Gateway: In NSX, the Tier-0 gateway is the edge component that peers with external routers (e.g., top-of-rack switches or upstream routers) and supports dynamic routing protocols like BGP and OSPF. Routing Security in NSX: NSX Tier-0 gateways commonly use BGP for external connectivity due to its scalability and flexibility in multi-site deployments like stretched clusters. OSPF is also supported but is less common for external peering in VCF designs. Route injection attacks occur when an unauthorized device advertises routes without validation, often due to missing authentication mechanisms.

Topics

#BGP authentication#Tier-0 gateway#routing security#route injection prevention

Community Discussion

No community discussion yet for this question.

Full 2V0-13.24 Practice