nerdexam
Broadcom-VMware

2V0-13.25 · Question #53

A customer is deploying VMware Cloud Foundation (VCF) in an enterprise environment. During a series of workshops with stakeholders, the following requirements were identified: - The network solution…

The correct answer is D. Deploy a dedicated NSX instance per workload domain. Dedicated NSX instances per workload domain provide the highest level of logical isolation and allow independent upgrade cycles, fulfilling the requirement of tenant-specific customization. Each workload domain with its own NSX instance can be managed separately, updated…

Section 2 – Design VMware Cloud Foundation Solutions

Question

A customer is deploying VMware Cloud Foundation (VCF) in an enterprise environment. During a series of workshops with stakeholders, the following requirements were identified:

  • The network solution must be capable of complete logical isolation.
  • The network solution must be capable of supporting independent

upgrade cycles for network stacks.

  • The network solution must be capable of tenant-specific customization

of NSX configurations. The architect has made the following design decisions:

  • The solution will consist of a single VCF instance.
  • The solution will include a management domain and two workload

domains. Based on the scenario, which additional design decision meets all of the stated requirements?

Options

  • ADeploy NSX only in the management domain and use VLAN-backed segments in the workload
  • BUse a global NSX Federation configuration across workload domains.
  • CUse a shared NSX instance across both workload domains.
  • DDeploy a dedicated NSX instance per workload domain.

How the community answered

(27 responses)
  • A
    22% (6)
  • B
    7% (2)
  • C
    11% (3)
  • D
    59% (16)

Explanation

Dedicated NSX instances per workload domain provide the highest level of logical isolation and allow independent upgrade cycles, fulfilling the requirement of tenant-specific customization. Each workload domain with its own NSX instance can be managed separately, updated independently, and configured with its own security policies, BGP/VRF, segments, and gateways. NSX Federation could achieve some level of centralization but does not support independent upgrade cycles per domain. A shared NSX instance breaks isolation and would tightly couple upgrade cycles, violating two of the key stated requirements.

Topics

#NSX isolation#workload domain#dedicated NSX instance#logical network separation

Community Discussion

No community discussion yet for this question.

Full 2V0-13.25 Practice