nerdexam
Huawei

H12-891_V1.0 · Question #183

In the network design scenario of large and medium-sized virtualized campuses, which of the following descriptions about VN design is wrong?

The correct answer is B. Define mutual access policies between VNs based on the policy control matrix. Option B is the wrong description because the *policy control matrix governs access between security groups within a VN, not between separate VNs. Inter-VN access policies are a distinct, higher-level construct enforced at border/gateway nodes - applying the intra-VN matrix to…

Data Center Network Technologies

Question

In the network design scenario of large and medium-sized virtualized campuses, which of the following descriptions about VN design is wrong?

Options

  • ADefine security groups and policy control matrix based on user roles and access requirements
  • BDefine mutual access policies between VNs based on the policy control matrix
  • CVNs are usually divided according to the geographical location of the campus office
  • DIt is necessary to plan the mapping relationship between VLAN and BD

How the community answered

(39 responses)
  • A
    5% (2)
  • B
    82% (32)
  • C
    10% (4)
  • D
    3% (1)

Explanation

Option B is the wrong description because the policy control matrix governs access between security groups within a VN, not between separate VNs. Inter-VN access policies are a distinct, higher-level construct enforced at border/gateway nodes - applying the intra-VN matrix to cross-VN traffic conflates two different policy layers.

Why the distractors are correct (not the wrong answer):

  • A is correct practice - security groups and the policy control matrix are specifically designed around user roles and access requirements, which is the foundational step in VN policy design.
  • C is a valid design approach - VNs can be segmented by geographic campus location (e.g., separate buildings or branch offices), making this a legitimate, not erroneous, description.
  • D is a real technical requirement - in VXLAN-based virtualized campuses, you must map VLANs to Bridge Domains (BDs) to integrate legacy Layer 2 infrastructure with the overlay network.

Memory tip: Think of the policy control matrix as a "room key card list" - it controls who can enter which rooms inside one building (VN). Deciding whether two buildings can connect at all is a separate architectural decision, not something the room key list handles.

Topics

#campus virtualization#VN design#VXLAN#security groups

Community Discussion

No community discussion yet for this question.

Full H12-891_V1.0 Practice