Question 1:

Given this exhibit:

Which statement is true about the firewall rule?

A. It is a distributed firewall applied to App-Servers, DB-Servers and Web-Servers that rejects traffic on port 22.

B. It is a gateway firewall applied to a Tier-1 gateway that rejects traffic on port 22.

C. It is a distributed firewall applied to App-Servers, DB-Servers and Web-Servers that drops traffic on port 22.

D. It is a gateway firewall applied to a Tier-0 gateway that drops traffic on port 22.

Correct Answer: C

Question 2:

Given this exhibit:

Which statement is true about the host transport nodes?

A. sa-esxi-04.vclass.local is successfully prepared for NSX with a TEP address of

B. sa-esxi-02.vclass.local is successfully prepared for NSX with a TEP address of

C. sa-esxi-05.vclass.local is successfully prepared for NSX with a TEP address of

D. sa-esxi-03.vclass.local had an error while being prepared for NSX with no TEP address assigned.

Correct Answer: D

Question 3:

A customer needs to simplify application migration, workload rebalancing, and business continuity across data centers and clouds.

Which product can help?

A. vRealize Operations

B. NSX Cloud

C. VMware Carbon Black

D. VMware HCX

Correct Answer: D

Reference: https://docs.vmware.com/en/VMware-HCX/services/user-guide/GUID-A7E39202-11FA-476AA795-AB70BA821BD3.html

Question 4:

Which plane in the NSX-T Data Center Architecture is used to create, read, update, and delete (CRUD) operations?

A. Local Control Plane (LCP)

B. Management Plane

C. Data Plane

D. Central Control Plane (CCP)

Correct Answer: B

Reference: https://docs.vmware.com/en/VMware-NSX-Data-Center-for-vSphere/6.4/ com.vmware.nsx.troubleshooting.doc/GUID-88BA25EC-126B-41EE-9F06-BD6235C9EC77.html

Question 5:

How are NSX managed compute endpoints called?

A. Transport Zone

B. vSphere Node

C. Transport Node

D. Compute Node

Correct Answer: C

Reference: https://www.uk.insight.com/en-gb/content-and-resources/articles/cloud-hub/2018-02-12-hybridcloud-networking-with-vmware-nsx-t

Question 6:

A customer needs to create a multi-tier network infrastructure.

What does the customer need to do to create this infrastructure?

A. Connect segments to a Tier-1 gateway, and connect the Tier-1 gateway to the Tier-0 gateway.

B. Connect segments to the Tier-1 gateway only.

C. Connect segments to a Tier-0 gateway, and connect the Tier-0 gateway to the Tier-1 gateway.

D. Connect segments to the Tier-0 gateway only.

Correct Answer: D

Question 7:

Which plane is responsible for creating and deleting network objects in the NSX-T Data Center Architecture?

A. Control Plane

B. Data Plane

C. Life Cycle Plane

D. Management Plane

Correct Answer: D

Question 8:

Which security services are natively provided by NSX-T Data Center?

A. Network introspection

B. Endpoint protection

C. Distributed IDS

D. Anti-virus protection

Correct Answer: B

Question 9:

A customer has experienced a disaster.

Which statement describes a recovery benefit of a vSphere Environment with NSX Data Center?

A. NSX Datacenter enables replication between sites.

B. Workload mobility is tied to vCenter server.

C. It simplifies the DR by not requiring the change of the IP addresses of workloads.

D. It is a requirement to stretch cluster to have a DR scenario.

Correct Answer: D

Reference: https://docs.vmware.com/en/VMware-NSX-T-Data-Center/3.1/administration/GUID-5D7E3D436497-4273-99C1-77613C36AD75.html

Question 10:

What does a customer need to configure to create GENEVE backed segments using NSX-T Data Center?

A. VLAN Transport Zone

B. Virtual Distributed Switch

C. Virtual Standard Switch

D. Overlay Transport Zone

Correct Answer: A

Reference: https://docs.vmware.com/en/VMware-Validated-Design/6.1/sddc-architecture-and-design-for-avsphere-with-tanzu-workload-domain/GUID-B1A08A06-F475-436B-8BA4-31552450D63C.html

Question 11:

How can NSX-T Distributed Firewall help customers achieve security for newly migrated containerized applications?

A. Quality of service

B. Micro-segmentation

C. Dynamic routing

D. Network I/O control

Correct Answer: B

Reference: https://blogs.vmware.com/networkvirtualization/2020/04/nsx-t-3-0.html/

Question 12:

Which two statements are true about N-VDS/VDS? (Choose two.)

A. KVM hosts support both N-VDS and VDS.

B. It is a module deployed in all transport nodes that provides L2 functionality.

C. It is a module deployed in all transport nodes that provides L3 functionality.

D. ESXi hosts support both N-VDS and VDS.

E. Bare-metal servers support both N-VDS and VDS.

Correct Answer: CD

Reference: https://docs.vmware.com/en/VMware-NSX-T-Data-Center/2.3/com.vmware.nsxt.install.doc/ GUID-F47989B2-2B9D-4214-B3BA-5DDF66A1B0E6.html

Question 13:

Which protocol allows an administrator to provide overlay networks on top of physical networks used in NSX-T Datacenter?

A. Geneve Segments

B. Tier-0 Gateway


D. Distributed Firewall

Correct Answer: A

Reference: https://docs.vmware.com/en/VMware-Validated-Design/5.1/sddc-architecture-and-design-for-vmware-nsxt-workload-domains/GUID-CF3C47CA-9BEB-4213-8F08-1494261BF3EC.html

Question 14:

An administrator needs to encrypt file transfers between two sites that do not have the same subnet. Which NSX-T feature accomplishes this task?



C. Tier-0 Gateway


Correct Answer: A

Question 15:

A customer needs multi-cloud load balancing, web application firewall, and container ingress services across on-premises data centers and any cloud.

Which product meets this customer\’s needs?

A. VMware HCX

B. NSX Advanced Load Balancer

C. NSX Cloud

D. NSX Distributed IDS

Correct Answer: B

Reference: https://www.vmware.com/products/nsx-advanced-load-balancer.html