nerdexam
Broadcom-VMware

3V0-42.20 · Question #15

An architect is helping an organization with the Logical Design of an NSX-T Data Center solution. This information was gathered during the Assessment Phase: Data between two networks connected over…

The correct answer is C. Deploy a Tier-0 gateway in Active/Standby mode. Configure route-based IPSec VPN with. Route-based IPSec VPN provides tunneling on traffic based on the static routes or routes learned Tier-0 gateway in the active-standby state supports the following services: Stateful firewall https://docs.vmware.com/en/VMware-NSX-T-Data-Center/3.0/administration/GUID-C0E5AF10…

Implement Network Security

Question

An architect is helping an organization with the Logical Design of an NSX-T Data Center solution. This information was gathered during the Assessment Phase:

Data between two networks connected over a public network needs to be encrypted. Certificate authentication is required. Dynamic route learning is preferred. Which selection should the architect include in their design? (Choose the best answer.)

Options

  • ADeploy a Tier-0 gateway in Active/Standby mode. Configure policy-based IPSec VPN with
  • BDeploy a Tier-0 gateway in Active/Active mode. Configure route-based IPSec VPN with SHA512
  • CDeploy a Tier-0 gateway in Active/Standby mode. Configure route-based IPSec VPN with
  • DDeploy a Tier-0 gateway in Active/Active mode. Configure policy-based IPSec VPN with SHA512

How the community answered

(53 responses)
  • A
    17% (9)
  • B
    8% (4)
  • C
    72% (38)
  • D
    4% (2)

Explanation

Route-based IPSec VPN provides tunneling on traffic based on the static routes or routes learned Tier-0 gateway in the active-standby state supports the following services: Stateful firewall https://docs.vmware.com/en/VMware-NSX-T-Data-Center/3.0/administration/GUID-C0E5AF10- 576D-493A-A079-C4C95D8F5373.html https://docs.vmware.com/en/VMware-NSX-T-Data-Center/3.0/administration/GUID-7B0CD287- C5EB-493C-A57F-EEA8782A741A.html#GUID-7B0CD287-C5EB-493C-A57F-EEA8782A741A

Topics

#IPSec VPN#route-based VPN#certificate authentication#dynamic routing

Community Discussion

No community discussion yet for this question.

Full 3V0-42.20 Practice