5V0-41.21 Exam Questions
69 real 5V0-41.21 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1
Which of the following describes the main concept of Zero-Trust Networks for network connected devices?
- Question #2
Which vCenter component is used by the NSX Manager to deploy the Partner Service VM on every host of a cluster configured for guest introspection?
- Question #3
To which object can time based rules be applied?
- Question #4
An organization wants to add security controls for contractor virtual desktops. Which statement Is true when configuring an NSX Identity firewall rule?
- Question #5
Refer to the exhibit. An administrator needs to configure a security policy with a firewall rule allowing a group of applications to retrieve the correct time from an NTP server. W...
- Question #6
Which two statements are true about IDS/IPS signatures? (Choose two.)
- Question #7
What is the NSX feature that allows a user to block ICMP between 192.168.1.100 and 192.168.1.101?
- Question #8
Which three criteria help to determine the severity for a Distributed IDS/IPS? (Choose three.)
- Question #9
Which is the port number used by transport nodes to export firewall statistics to NSX Manager?
- Question #10
Where is a partner security virtual machine (Partner SVM) deployed to process the redirected North-South traffic in an efficient manner?
- Question #11
To which network operations does a user with the Security Engineer role have full access permission?
- Question #12
Which two Guest OS drivers are required for the Identity Firewall to operate? (Choose two.)
- Question #13
An administrator has enabled the "logging" option on a specific firewall rule. The administrator does not see messages on the Logging Server related to this firewall rule. What cou...
- Question #14
How does N5X Distributed IDS/IPS keep up to date with signatures?
- Question #15
Which two statements are true about NSX Intelligence? (Choose two.)
- Question #16
An administrator wants to use Distributed Intrusion Detection. How is this implemented in an NSX-T Data Center?
- Question #17
Information Security Management (ISM) describes a set of controls that organizations employ to protect which properties?
- Question #18
An NSX administrator is trying to find the dvfilter name of the sa-web-01 virtual machine to capture the sa-web-01 VM traffic. What could be a reason the sa-web-01 VM dvfilter name...
- Question #19
What is an unprotected traffic flow in NSX Intelligence?
- Question #20
Refer to the exhibit. A security administrator is configuring a time window to create a time-based distributed firewall rule. While configuring the time window, an error displayed...
- Question #21
When using URL Analysis In NSX-T, which two services must be set in the URL rule to capture traffic over TCP and UDP? (Choose two.)
- Question #22
Which 3 CU commands ant required to configure remote logging on an ESXI host? (Choose three.)
- Question #23
An administrator needs to configure their NSX-T logging to audit changes on firewall security policy. The administrator Is using the following command from NSX-T3.1 documentation :...
- Question #24
A customer has deployed NSX Intelligence appliance with an incorrect IP address. What should the customer do to correct the IP address?
- Question #25
A security administrator recently enabled Guest Introspection on NSX-T Data Center. Which would be a reason none of the Microsoft Windows based VMs are reporting any information?
- Question #26
What is the default action of the Default Layer 3 distributed firewall rule?
- Question #27
What is one of the main use-cases of NSX-T Endpoint Protection?
- Question #28
A security administrator is required to protect East-West virtual machine traffic with the NSX Distributed Firewall. What must be completed with the virtual machine's vNIC before a...
- Question #29
Which two criteria would an administrator use to filter firewall connection logs on NSX?
- Question #30
A security administrator is verifying why users are blocked from sports sites but are able to access gambling websites from the corporate network. What needs to be updated In nsx-T...
- Question #31
Refer to the exhibit. An administrator is reviewing NSX Intelligence information as shown in the exhibit. What does the red dashed line for the UDP:137 flow represent?
- Question #32
When configuring members of a Security Group, which membership criteria art permitted?
- Question #33
At which OSI Layer do Next Generation Firewalls capable of analyzing application traffic operate?
- Question #34
Which three are required to configure a firewall rule on a getaway to allow traffic from the internal to web servers? (Choose three.)
- Question #35
A customer has a requirement to achieve Zero-Trust Security and minimize operational overhead. Which VMware solution can be used by the customer to achieve the requirement?
- Question #36
An NSX administrator has been tasked with deploying a NSX Edge Virtual machine through an ISO image. Which virtual network interface card (vNIC) type must be selected while creatin...
- Question #37
Which esxcli command lists the firewall configuration on ESXi hosts?
- Question #38
Which three are required by URL Analysis? (Choose three.)
- Question #39
Which two are requirements for URL Analysis? (Choose two.)
- Question #40
Refer to the exhibit, what is the VMware recommended number of NSX Manager Nodes to additionally deploy to form an NSX-T Manager Cluster?
- Question #41
In a brownfield environment with NSX-T Data Center deployed and configured, a customer is interested in Endpoint Protection integrations. What recommendation should be provided to...
- Question #42
Which two are true of the NSX Gateway Firewall? (Choose two.)
- Question #43
At which two intervals are NSX-T IDS/IPS updates through VMware's cloud based internet service provided for threat signature files? (Choose two.)
- Question #44
Which two are the insertion points for North-South service insertion? (Choose two.)
- Question #45
Which are two use-cases for the NSX Distributed Firewall' (Choose two.)
- Question #46
An administrator wants to configure NSX-T Security Groups inside a distributed firewall rule. Which menu item would the administrator select to configure the Security Groups?
- Question #47
Reference the CLI output. What is the source IP address in the distributed firewall rule to accept HTTP traffic?
- Question #48
What component in a transport node receives the firewall configuration from the central control plane?
- Question #49
An NSX administrator has turned on logging for the distributed firewall rule. On an ESXi host, where will the logs be stored?
- Question #50
A Security Administrator needs to update their NSX Distributed IDS/IPS policy to detect new attacks with critical CVSS scoring that leads to credential theft from targeted systems....