nerdexam
Broadcom-VMware

5V0-43.21 · Question #16

An operator observes that the health score for a Virtual Service has reduced. When hovering over the health score popup, the operator sees a Security Penalty of -20 has been applied. Which issue…

The correct answer is C. The SSL certificate attached to the Virtual Service will expire within the next 30 days. A Security Penalty of -20 is specifically triggered in Avi Networks (NSX Advanced Load Balancer) when an SSL/TLS certificate attached to a Virtual Service is approaching expiration - within 30 days - because an expiring certificate represents an imminent security risk to…

Avi Vantage Platform Troubleshooting

Question

An operator observes that the health score for a Virtual Service has reduced. When hovering over the health score popup, the operator sees a Security Penalty of -20 has been applied. Which issue should be investigated as the most likely cause of this reduced score?

Options

  • AThe Pool has been configured with an HTTP health monitor rather than an HTTPS health monitor.
  • BThe WAF Policy has not been configured with Positive Security rules.
  • CThe SSL certificate attached to the Virtual Service will expire within the next 30 days.
  • DThe CPU utilization of the Service Engine on which the Virtual Service is placed is exceeding 80%.

How the community answered

(60 responses)
  • A
    17% (10)
  • B
    5% (3)
  • C
    70% (42)
  • D
    8% (5)

Explanation

A Security Penalty of -20 is specifically triggered in Avi Networks (NSX Advanced Load Balancer) when an SSL/TLS certificate attached to a Virtual Service is approaching expiration - within 30 days - because an expiring certificate represents an imminent security risk to encrypted traffic. Option A is wrong because a mismatched health monitor affects the pool's operational status, not the security scoring. Option B is wrong because WAF Positive Security rules are a configuration best practice, but their absence would affect a WAF-related score component, not produce a discrete -20 security penalty. Option D is wrong because CPU utilization affects performance/resource health metrics, not security scoring.

Memory tip: Think "Security Penalty = Security Risk" - an expiring certificate is a ticking clock on your encryption, making it the most direct and measurable security threat the platform can detect and penalize automatically.

Topics

#Health Score Penalties#SSL Certificate Lifecycle#Virtual Service Monitoring#Security Assessment

Community Discussion

No community discussion yet for this question.

Full 5V0-43.21 Practice