5V0-32.21 · Question #5
What are three capabilities of a data center group that is using NSX-T with VMware Cloud Director? (Choose three.)
The correct answer is B. Provides Distributed Firewall (DFW) management C. Allows a tenant or service provider to establish availability zones E. Provides layer-2 (L2) shared networking. In VMware Cloud Director (VCD), a Data Center Group is a construct that links multiple Organization VDCs together to enable shared networking and security services across them. When backed by NSX-T, a Data Center Group provides Distributed Firewall (DFW) management (B) so that…
Question
What are three capabilities of a data center group that is using NSX-T with VMware Cloud Director? (Choose three.)
Options
- AProvisioning Kubernetes clusters
- BProvides Distributed Firewall (DFW) management
- CAllows a tenant or service provider to establish availability zones
- DProvides edge bridging functionality
- EProvides layer-2 (L2) shared networking
- FConducts Netflow traffic analysis
How the community answered
(32 responses)- A9% (3)
- B81% (26)
- D6% (2)
- F3% (1)
Explanation
In VMware Cloud Director (VCD), a Data Center Group is a construct that links multiple Organization VDCs together to enable shared networking and security services across them. When backed by NSX-T, a Data Center Group provides Distributed Firewall (DFW) management (B) so that firewall policies can be applied consistently across all member VDCs from a single control point; it enables Layer-2 shared networking (E), allowing stretched overlay networks to span multiple VDCs within the group; and it lets tenants or service providers establish availability zones (C) by grouping VDCs from different physical locations under one logical boundary for resiliency planning.
Why the distractors are wrong:
- A (Kubernetes clusters): Provisioning Kubernetes is handled by the Container Service Extension (CSE) plugin, not a Data Center Group feature.
- D (Edge bridging): L2 bridging between overlay and VLAN-backed networks is an NSX-T Edge capability, not a Data Center Group capability.
- F (Netflow analysis): IPFIX/Netflow traffic export is a general NSX-T Data Plane feature configured at the transport node or switch level, not a Data Center Group function.
Memory tip: Think of a Data Center Group as a "security and networking umbrella" stretched across VDCs - it gives you a shared L2 fabric (E), a unified firewall (B), and lets you map VDCs to physical zones (C). If an option sounds like a raw NSX-T infrastructure feature (bridging, Netflow) or a separate plugin (Kubernetes), it's not a Data Center Group capability.
Topics
Community Discussion
No community discussion yet for this question.