nerdexam
Broadcom-VMware

2V0-621 · Question #218

Refer to the Exhibit. An administrator has configured a firewall rule as shown in the Exhibit. Which statement best describes the ESXi 6.x firewall rule?

The correct answer is B. Connections coming from IP addresses from the 192.168.1.0 network and 192.168.2.220 on port. This question tests the ability to correctly interpret ESXi 6.x host firewall rules, specifically distinguishing traffic direction (inbound vs. outbound) and protocol specification.

Section 1 – Configure and Administer vSphere 6.x Security

Question

Refer to the Exhibit. An administrator has configured a firewall rule as shown in the Exhibit. Which statement best describes the ESXi 6.x firewall rule?

Exhibit

2V0-621 question #218 exhibit

Options

  • AConnections from the ESXi host to all devices on the 192.168.1.0 network and 192.168.2.220 on
  • BConnections coming from IP addresses from the 192.168.1.0 network and 192.168.2.220 on port
  • CTCP Connections coming from IP addresses from the 192.168.1.0 network and 192.168.2.220 on
  • DTCP Connections from the ESXi host to all devices on the 192.168.1.0 network and

How the community answered

(40 responses)
  • A
    3% (1)
  • B
    78% (31)
  • C
    13% (5)
  • D
    8% (3)

Why each option

This question tests the ability to correctly interpret ESXi 6.x host firewall rules, specifically distinguishing traffic direction (inbound vs. outbound) and protocol specification.

AConnections from the ESXi host to all devices on the 192.168.1.0 network and 192.168.2.220 on

Option A incorrectly describes the traffic direction as outbound (connections FROM the ESXi host to external devices), whereas the rule controls inbound connections arriving at the ESXi host.

BConnections coming from IP addresses from the 192.168.1.0 network and 192.168.2.220 on portCorrect

The firewall rule is configured to allow inbound connections coming from specific source IP addresses - the 192.168.1.0 network and the individual host 192.168.2.220 - on a specified port. ESXi host firewall rules with source IP filtering control which external systems can initiate connections to ESXi host services, and this rule does not restrict the traffic to TCP only, applying to connections generally.

CTCP Connections coming from IP addresses from the 192.168.1.0 network and 192.168.2.220 on

Option C incorrectly adds a TCP-only protocol restriction that is not specified in the firewall rule as shown - the rule applies to connections without limiting them to TCP exclusively.

DTCP Connections from the ESXi host to all devices on the 192.168.1.0 network and

Option D is incorrect on two counts: it describes the direction as outbound (from the ESXi host) and incorrectly adds TCP as the protocol, neither of which matches the configured rule.

Concept tested: ESXi 6.x host firewall inbound rule direction and IP allowlist

Source: https://docs.vmware.com/en/VMware-vSphere/6.7/com.vmware.vsphere.security.doc/GUID-7A8BEFC8-BF86-49B5-AE2D-E400AAD81BA3.html

Topics

#ESXi firewall#IP filtering#inbound rules#host security

Community Discussion

No community discussion yet for this question.

Full 2V0-621 Practice