nerdexam
Cisco

300-460 · Question #93

A cloud architect is creating a solution to allow virtual machines to be provisioned into a DMZ. Security requirements specify that all traffic between DMZ and internal networks must pass through…

The correct answer is A. Ensure that DMZ virtual machines reside on a dedicated DMZ compute cluster that is separate. See the full explanation below for the reasoning.

Question

A cloud architect is creating a solution to allow virtual machines to be provisioned into a DMZ. Security requirements specify that all traffic between DMZ and internal networks must pass through the firewall. As long as this requirement is met, DMZ zone and internal zone resources must be pooled to reduce costs. Which action is the most likely to meet these requirements?

Options

  • AEnsure that DMZ virtual machines reside on a dedicated DMZ compute cluster that is separate
  • BEnsure that DMZ virtual port groups are separate from non-DMZ virtual port groups.
  • CEnsure that any Fibre Channel traffic for DMZ virtual machines utilizes a dedicated VSAN that is
  • DEnsure that iSCSI traffic for DMZ virtual machines is on separate networks from iSCSI traffic for
  • EEnsure that DMZ virtual machine traffic uses dedicated physical NICs.

How the community answered

(31 responses)
  • A
    74% (23)
  • B
    3% (1)
  • C
    13% (4)
  • D
    3% (1)
  • E
    6% (2)

Community Discussion

No community discussion yet for this question.

Full 300-460 Practice