nerdexam
Broadcom-VMware

3V0-21.23 · Question #113

An architect has been tasked with designing a greenfield hosting platform. As part of a workshop, it is identified that the new solution must support the following: - Provide a centralized way to…

The correct answer is D. VMware NSX, Distributed Firewalls and Port Mirroring. VMware NSX: NSX provides a centralized platform for network virtualization and security, which aligns with the requirement for enforcing virtual network security policies. It can manage network segmentation, security policies, and micro-segmentation across the entire…

Design for security

Question

An architect has been tasked with designing a greenfield hosting platform. As part of a workshop, it is identified that the new solution must support the following:

  • Provide a centralized way to enforce virtual network security policy
  • Provide network security for both virtual machines and containerized applications
  • Deny network access between all workloads by default
  • Linked services should be connected to the same virtual port groups by default
  • Support for the security teams network monitoring solution

Which elements should the architect include in the design to meet the identified requirements?

Options

  • AVMware Standard Switches, Access Lists and Promiscuous mode
  • BDistributed Virtual Switches, Access Lists and Promiscuous mode
  • CVMware Carbon Black, Distributed Virtual Switches and Traffic Filtering
  • DVMware NSX, Distributed Firewalls and Port Mirroring

How the community answered

(43 responses)
  • A
    12% (5)
  • B
    5% (2)
  • C
    5% (2)
  • D
    79% (34)

Explanation

VMware NSX: NSX provides a centralized platform for network virtualization and security, which aligns with the requirement for enforcing virtual network security policies. It can manage network segmentation, security policies, and micro-segmentation across the entire environment, including both virtual machines and containerized applications. Distributed Firewalls: NSX's distributed firewall allows for micro-segmentation, meaning that network access is denied between workloads by default, and access controls can be applied based on security policies. This meets the requirement of denying network access by default. Port Mirroring: Port mirroring in NSX can integrate with the security team's network monitoring solutions. It enables the security team to capture traffic for monitoring and analysis, addressing the requirement for network monitoring support.

Topics

#NSX#Distributed Firewall#Port Mirroring#network security policy

Community Discussion

No community discussion yet for this question.

Full 3V0-21.23 Practice