5V0-41.21 Exam Questions
69 real 5V0-41.21 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1vRealize Operations Architecture and Technologies
Which of the following describes the main concept of Zero-Trust Networks for network connected devices?
Zero-Trust Networksdevice identityintegrity verificationnetwork security - Question #2vRealize Operations Architecture and Technologies
Which vCenter component is used by the NSX Manager to deploy the Partner Service VM on every host of a cluster configured for guest introspection?
NSX Managerguest introspectionESXi Agent ManagerPartner SVM - Question #3
To which object can time based rules be applied?
- Question #4Administering and Operating vRealize Operations
An organization wants to add security controls for contractor virtual desktops. Which statement Is true when configuring an NSX Identity firewall rule?
NSX Identity Firewalluser identityfirewall rulessource configuration - Question #5
Refer to the exhibit. An administrator needs to configure a security policy with a firewall rule allowing a group of applications to retrieve the correct time from an NTP server. W...
- Question #6
Which two statements are true about IDS/IPS signatures? (Choose two.)
- Question #7vRealize Operations Architecture and Technologies
What is the NSX feature that allows a user to block ICMP between 192.168.1.100 and 192.168.1.101?
NSX Distributed FirewallICMP blockingnetwork security - Question #8
Which three criteria help to determine the severity for a Distributed IDS/IPS? (Choose three.)
- Question #9vRealize Operations Architecture and Technologies
Which is the port number used by transport nodes to export firewall statistics to NSX Manager?
firewall statisticsport numberstransport nodesNSX Manager - Question #10vRealize Operations Architecture and Technologies
Where is a partner security virtual machine (Partner SVM) deployed to process the redirected North-South traffic in an efficient manner?
Partner SVMNSX EdgeNorth-South trafficservice insertion - Question #11
To which network operations does a user with the Security Engineer role have full access permission?
- Question #12Deploying and Configuring vRealize Operations
Which two Guest OS drivers are required for the Identity Firewall to operate? (Choose two.)
Identity FirewallGuest IntrospectionNSX driversguest OS - Question #13
An administrator has enabled the "logging" option on a specific firewall rule. The administrator does not see messages on the Logging Server related to this firewall rule. What cou...
- Question #14
How does N5X Distributed IDS/IPS keep up to date with signatures?
- Question #15vRealize Operations Architecture and Technologies
Which two statements are true about NSX Intelligence? (Choose two.)
NSX Intelligencedistributed firewall planningservice insertionnetwork visibility - Question #16NSX-T Data Center Architecture and Technologies
An administrator wants to use Distributed Intrusion Detection. How is this implemented in an NSX-T Data Center?
distributed IDSNSX Edge nodesintrusion detectionsecurity services - Question #17NSX-T Data Center Architecture and Technologies
Information Security Management (ISM) describes a set of controls that organizations employ to protect which properties?
CIA triadinformation securityISMconfidentiality - Question #18NSX-T Data Center Troubleshooting
An NSX administrator is trying to find the dvfilter name of the sa-web-01 virtual machine to capture the sa-web-01 VM traffic. What could be a reason the sa-web-01 VM dvfilter name...
dvfilterpacket captureVM power statetraffic capture - Question #19NSX-T Data Center Operations and Management
What is an unprotected traffic flow in NSX Intelligence?
NSX Intelligenceunprotected trafficdefault firewall ruletraffic flow - Question #20NSX-T Data Center Deployment and Configuration
Refer to the exhibit. A security administrator is configuring a time window to create a time-based distributed firewall rule. While configuring the time window, an error displayed...
time-based firewall ruleNTP configurationESXi hostDFW - Question #21
When using URL Analysis In NSX-T, which two services must be set in the URL rule to capture traffic over TCP and UDP? (Choose two.)
- Question #22NSX-T Data Center Operations and Management
Which 3 CU commands ant required to configure remote logging on an ESXI host? (Choose three.)
remote loggingsyslogESXi CLIfirewall ruleset - Question #23NSX-T Data Center Operations and Management
An administrator needs to configure their NSX-T logging to audit changes on firewall security policy. The administrator Is using the following command from NSX-T3.1 documentation :...
audit loggingfirewall policysyslog message IDNSX-T logging - Question #24NSX-T Data Center Deployment and Configuration
A customer has deployed NSX Intelligence appliance with an incorrect IP address. What should the customer do to correct the IP address?
NSX IntelligenceIP reconfigurationCLIappliance management - Question #25NSX-T Data Center Troubleshooting
A security administrator recently enabled Guest Introspection on NSX-T Data Center. Which would be a reason none of the Microsoft Windows based VMs are reporting any information?
Guest IntrospectionWindows VMsendpoint securityNSX Manager - Question #26NSX-T Data Center Architecture and Technologies
What is the default action of the Default Layer 3 distributed firewall rule?
distributed firewalldefault ruleLayer 3drop action - Question #27NSX-T Data Center Architecture and Technologies
What is one of the main use-cases of NSX-T Endpoint Protection?
Endpoint Protectionagentless antivirusGuest Introspectionsecurity services - Question #28NSX-T Data Center Deployment and Configuration
A security administrator is required to protect East-West virtual machine traffic with the NSX Distributed Firewall. What must be completed with the virtual machine's vNIC before a...
distributed firewallEast-West trafficNSX segmentvNIC - Question #29NSX-T Data Center Operations and Management
Which two criteria would an administrator use to filter firewall connection logs on NSX?
firewall connection logslog filteringFIREWALL-PKTLOGmonitoring - Question #30NSX-T Data Center Deployment and Configuration
A security administrator is verifying why users are blocked from sports sites but are able to access gambling websites from the corporate network. What needs to be updated In nsx-T...
URL analysisweb content filteringNGFWgateway policy - Question #31NSX-T Data Center Operations and Management
Refer to the exhibit. An administrator is reviewing NSX Intelligence information as shown in the exhibit. What does the red dashed line for the UDP:137 flow represent?
NSX Intelligencetraffic visualizationblocked communicationUDP flow - Question #32NSX-T Data Center Deployment and Configuration
When configuring members of a Security Group, which membership criteria art permitted?
security groupsmembership criteriaNSX groupingIP Set - Question #33NSX-T Data Center Architecture and Technologies
At which OSI Layer do Next Generation Firewalls capable of analyzing application traffic operate?
NGFWOSI modelLayer 7application inspection - Question #34NSX-T Data Center Deployment and Configuration
Which three are required to configure a firewall rule on a getaway to allow traffic from the internal to web servers? (Choose three.)
gateway firewallfirewall policyLocal Gateway categorytraffic rules - Question #35NSX-T Data Center Planning and Design
A customer has a requirement to achieve Zero-Trust Security and minimize operational overhead. Which VMware solution can be used by the customer to achieve the requirement?
Zero TrustNSX Intelligencesecurity automationoperational overhead - Question #36NSX-T Data Center Deployment and Configuration
An NSX administrator has been tasked with deploying a NSX Edge Virtual machine through an ISO image. Which virtual network interface card (vNIC) type must be selected while creatin...
NSX EdgeVMXNET3vNIC typetransport zone - Question #37NSX-T Data Center Troubleshooting
Which esxcli command lists the firewall configuration on ESXi hosts?
esxclifirewall rulesetESXi hostCLI commands - Question #38NSX-T Data Center Deployment and Configuration
Which three are required by URL Analysis? (Choose three.)
URL AnalysisEdge node sizingLayer 7 DNS firewallTier-1 gateway - Question #39NSX-T Data Center Deployment and Configuration
Which two are requirements for URL Analysis? (Choose two.)
URL AnalysisDNS firewall ruleEdge node Internet accessTier-1 gateway - Question #40NSX-T Data Center Deployment and Configuration
Refer to the exhibit, what is the VMware recommended number of NSX Manager Nodes to additionally deploy to form an NSX-T Manager Cluster?
NSX Manager clustercluster node counthigh availability - Question #41NSX-T Data Center Deployment and Configuration
In a brownfield environment with NSX-T Data Center deployed and configured, a customer is interested in Endpoint Protection integrations. What recommendation should be provided to...
Endpoint ProtectionVMware Tools custom installbrownfield deploymentvirtual machine requirements - Question #42NSX-T Data Center Architecture and Technologies
Which two are true of the NSX Gateway Firewall? (Choose two.)
Gateway FirewallPre Rule categorySecurity GroupsApplied-To - Question #43NSX-T Data Center Operations and Management
At which two intervals are NSX-T IDS/IPS updates through VMware's cloud based internet service provided for threat signature files? (Choose two.)
IDS/IPSsignature updatescloud-based threat intelupdate intervals - Question #44NSX-T Data Center Architecture and Technologies
Which two are the insertion points for North-South service insertion? (Choose two.)
service insertionNorth-Southtier-0 gateway uplinkGuest VM vNIC - Question #45NSX-T Data Center Architecture and Technologies
Which are two use-cases for the NSX Distributed Firewall' (Choose two.)
Distributed FirewallZero-Trustmicro-segmentationlateral movement prevention - Question #46NSX-T Data Center Deployment and Configuration
An administrator wants to configure NSX-T Security Groups inside a distributed firewall rule. Which menu item would the administrator select to configure the Security Groups?
Security GroupsDistributed FirewallNSX Manager UISecurity menu - Question #47
Reference the CLI output. What is the source IP address in the distributed firewall rule to accept HTTP traffic?
- Question #48NSX-T Data Center Architecture and Technologies
What component in a transport node receives the firewall configuration from the central control plane?
nsx-mpacentral control planetransport nodefirewall config distribution - Question #49NSX-T Data Center Troubleshooting
An NSX administrator has turned on logging for the distributed firewall rule. On an ESXi host, where will the logs be stored?
DFW loggingdfwpktlogs.logESXi log pathpacket logging - Question #50
A Security Administrator needs to update their NSX Distributed IDS/IPS policy to detect new attacks with critical CVSS scoring that leads to credential theft from targeted systems....