nerdexam
Broadcom-VMware

2V0-41.24 · Question #97

A company Is deploying NSX micro-segmentation in their vSphere environment to secure a simple application composed of web. app, and database tiers. The naming convention will be: - WKS-WEB-SRV-XXX…

The correct answer is C. Group all by means of tags membership. Tags are metadata that can be applied to physical servers, virtual machines, logical ports, and logical segments in NSX. Tags can be used for dynamic security group membership, which allows for granular and flexible enforcement of security policies based on various criteria. In…

Section 4 – NSX Services

Question

A company Is deploying NSX micro-segmentation in their vSphere environment to secure a simple application composed of web. app, and database tiers. The naming convention will be:

  • WKS-WEB-SRV-XXX
  • WKY-APP-SRR-XXX
  • WKI-DB-SRR-XXX

What is the optimal way to group them to enforce security policies from NSX?

Options

  • AUse Edge as a firewall between tiers.
  • BDo a service insertion to accomplish the task.
  • CGroup all by means of tags membership.
  • DCreate an Ethernet based security policy.

How the community answered

(40 responses)
  • A
    10% (4)
  • B
    5% (2)
  • C
    83% (33)
  • D
    3% (1)

Explanation

Tags are metadata that can be applied to physical servers, virtual machines, logical ports, and logical segments in NSX. Tags can be used for dynamic security group membership, which allows for granular and flexible enforcement of security policies based on various criteria. In the scenario, the company is deploying NSX micro-segmentation to secure a simple application composed of web, app, and database tiers.

Topics

#micro-segmentation#tag membership#security groups#DFW policy

Community Discussion

No community discussion yet for this question.

Full 2V0-41.24 Practice