nerdexam
Broadcom-VMware

5V0-32.21 · Question #5

What are three capabilities of a data center group that is using NSX-T with VMware Cloud Director? (Choose three.)

The correct answer is B. Provides Distributed Firewall (DFW) management C. Allows a tenant or service provider to establish availability zones E. Provides layer-2 (L2) shared networking. In VMware Cloud Director (VCD), a Data Center Group is a construct that links multiple Organization VDCs together to enable shared networking and security services across them. When backed by NSX-T, a Data Center Group provides Distributed Firewall (DFW) management (B) so that…

Cloud Provider Services

Question

What are three capabilities of a data center group that is using NSX-T with VMware Cloud Director? (Choose three.)

Options

  • AProvisioning Kubernetes clusters
  • BProvides Distributed Firewall (DFW) management
  • CAllows a tenant or service provider to establish availability zones
  • DProvides edge bridging functionality
  • EProvides layer-2 (L2) shared networking
  • FConducts Netflow traffic analysis

How the community answered

(32 responses)
  • A
    9% (3)
  • B
    81% (26)
  • D
    6% (2)
  • F
    3% (1)

Explanation

In VMware Cloud Director (VCD), a Data Center Group is a construct that links multiple Organization VDCs together to enable shared networking and security services across them. When backed by NSX-T, a Data Center Group provides Distributed Firewall (DFW) management (B) so that firewall policies can be applied consistently across all member VDCs from a single control point; it enables Layer-2 shared networking (E), allowing stretched overlay networks to span multiple VDCs within the group; and it lets tenants or service providers establish availability zones (C) by grouping VDCs from different physical locations under one logical boundary for resiliency planning.

Why the distractors are wrong:

  • A (Kubernetes clusters): Provisioning Kubernetes is handled by the Container Service Extension (CSE) plugin, not a Data Center Group feature.
  • D (Edge bridging): L2 bridging between overlay and VLAN-backed networks is an NSX-T Edge capability, not a Data Center Group capability.
  • F (Netflow analysis): IPFIX/Netflow traffic export is a general NSX-T Data Plane feature configured at the transport node or switch level, not a Data Center Group function.

Memory tip: Think of a Data Center Group as a "security and networking umbrella" stretched across VDCs - it gives you a shared L2 fabric (E), a unified firewall (B), and lets you map VDCs to physical zones (C). If an option sounds like a raw NSX-T infrastructure feature (bridging, Netflow) or a separate plugin (Kubernetes), it's not a Data Center Group capability.

Topics

#NSX-T DFW#Availability Zones#L2 Networking#Network Virtualization

Community Discussion

No community discussion yet for this question.

Full 5V0-32.21 Practice