nerdexam
Broadcom-VMware

5V0-42.21 · Question #11

During a security-related discussion, an administrator determines that guest users not be able to access any resources on the corporate network. Which VMware SD-WAN feature can achieve this goal in…

The correct answer is A. Segments. Segments is correct because VMware SD-WAN Segments provide network-level isolation that creates entirely separate virtual networks - guest traffic is logically isolated from corporate resources at the overlay level, making it the most scalable and manageable solution for…

SD-WAN Architecture and Technologies

Question

During a security-related discussion, an administrator determines that guest users not be able to access any resources on the corporate network. Which VMware SD-WAN feature can achieve this goal in the most scalable and manageable way?

Options

  • ASegments
  • BBusiness Policy
  • CVLANs
  • DFirewall

How the community answered

(37 responses)
  • A
    84% (31)
  • B
    11% (4)
  • C
    3% (1)
  • D
    3% (1)

Explanation

Segments is correct because VMware SD-WAN Segments provide network-level isolation that creates entirely separate virtual networks - guest traffic is logically isolated from corporate resources at the overlay level, making it the most scalable and manageable solution for separating user populations across potentially thousands of edges from a single centralized policy.

Business Policy (B) controls traffic steering and QoS (e.g., routing traffic over MPLS vs. internet) but does not restrict access to corporate resources - it shapes how traffic moves, not whether it can reach a destination. VLANs (C) can isolate traffic at Layer 2 on the LAN side, but they require configuration on every switch and edge device individually, making them far less scalable and manageable in a large SD-WAN deployment. Firewall (D) rules can block specific traffic, but maintaining granular firewall rules per-site for guest isolation is operationally complex compared to a single Segment policy applied globally.

Memory tip: Think of Segments as "virtual SD-WAN networks within your SD-WAN" - just as VRFs isolate routing tables in traditional networking, Segments isolate entire overlay networks in VMware SD-WAN, making them the go-to answer whenever you see "isolation," "separation," or "scalable guest access" in a question.

Topics

#Segments#Microsegmentation#Access Control#Security

Community Discussion

No community discussion yet for this question.

Full 5V0-42.21 Practice