5V0-43.21 · Question #16
An operator observes that the health score for a Virtual Service has reduced. When hovering over the health score popup, the operator sees a Security Penalty of -20 has been applied. Which issue…
The correct answer is C. The SSL certificate attached to the Virtual Service will expire within the next 30 days. A Security Penalty of -20 is specifically triggered in Avi Networks (NSX Advanced Load Balancer) when an SSL/TLS certificate attached to a Virtual Service is approaching expiration - within 30 days - because an expiring certificate represents an imminent security risk to…
Question
An operator observes that the health score for a Virtual Service has reduced. When hovering over the health score popup, the operator sees a Security Penalty of -20 has been applied. Which issue should be investigated as the most likely cause of this reduced score?
Options
- AThe Pool has been configured with an HTTP health monitor rather than an HTTPS health monitor.
- BThe WAF Policy has not been configured with Positive Security rules.
- CThe SSL certificate attached to the Virtual Service will expire within the next 30 days.
- DThe CPU utilization of the Service Engine on which the Virtual Service is placed is exceeding 80%.
How the community answered
(60 responses)- A17% (10)
- B5% (3)
- C70% (42)
- D8% (5)
Explanation
A Security Penalty of -20 is specifically triggered in Avi Networks (NSX Advanced Load Balancer) when an SSL/TLS certificate attached to a Virtual Service is approaching expiration - within 30 days - because an expiring certificate represents an imminent security risk to encrypted traffic. Option A is wrong because a mismatched health monitor affects the pool's operational status, not the security scoring. Option B is wrong because WAF Positive Security rules are a configuration best practice, but their absence would affect a WAF-related score component, not produce a discrete -20 security penalty. Option D is wrong because CPU utilization affects performance/resource health metrics, not security scoring.
Memory tip: Think "Security Penalty = Security Risk" - an expiring certificate is a ticking clock on your encryption, making it the most direct and measurable security threat the platform can detect and penalize automatically.
Topics
Community Discussion
No community discussion yet for this question.