Pre-Summer Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

VMware 6V0-21.25 VMware vDefend Security for VCF 5.x Administrator Exam Practice Test

Page: 1 / 8
Total 75 questions

VMware vDefend Security for VCF 5.x Administrator Questions and Answers

Question 1

Which of the following is true regarding the VMware vDefend Distributed Firewall?

Options:

A.

VMware vDefend Distributed Firewall is a hypervisor-based software defined firewall solution

B.

VMware vDefend Distributed Firewall runs in the ESXi vSwitch

C.

VMware vDefend Distributed Firewall can be deployed as a virtual machine or on bare metal hardware

D.

VMware vDefend Distributed Firewall runs as an agent in a physical switch with open software development capabilities

Question 2

Which of the following are important components to cyber security design? (Select all that apply)

Options:

A.

Proactive protection

B.

Deep visibility

C.

Recovery

D.

Kernel remediation and upgrade

Question 3

NestDB is a central Database deployed on all three NSX Managers nodes responsible for storing the user intent.

Options:

A.

True

B.

False

Question 4

If you want to run Gateway IDS/IPS, what is the minimum Edge Form Factor size supported to run this feature?

Options:

A.

Medium

B.

X-Large

C.

Small

D.

Large

Question 5

Which type of firewall enforcement point is NOT supported on the Gateway Firewall?

Options:

A.

Uplink/External Interfaces on Tier-0/1

B.

Service Interfaces on Tier-0/1

C.

Downlinks on Tier-0/1

D.

Bare Metal Interfaces

Question 6

Which one of the following are the ICMP Timer Variables that can be customized within the vDefend Distributed Firewall?

Options:

A.

First Packet, Open, Established, Closing, Fin Wait, and Closed

B.

First Packet, Single, and Multiple

C.

First Packet, and Error Reply

D.

Last Packet, and Static and Dynamic Errors

Question 7

Which of the following is not an available option for membership criteria selection when creating group of type Antrea?

Options:

A.

K8s Namespace

B.

Antrea Egress

C.

K8s NetworkPolicy

D.

K8s Service

Question 8

Which one of the following is NOT one of the use-cases of Distributed Intrusion Detection and Prevention?

Options:

A.

Provide routing capability for an air-gapped network to securely access the internet

B.

Enable software-based IDS/IPS for Critical applications

C.

Prevent lateral movement of attackers by blocking vulnerabilities

D.

Achieve regulatory compliance requirements for PCI-DSS, HIPAA, SOX

Question 9

What features does NSX Live Traffic Analysis tool provide? (Select all that apply)

Options:

A.

Live Traffic Trace

B.

Packet Capture

C.

Performance

D.

Packet Count

Question 10

Which of these are NOT a grouping criteria when creating a dynamic group? (Select all that apply)

Options:

A.

IncludeAll

B.

ExcludeAll

C.

StartsWith

D.

Contains

Question 11

Which of the following is NOT true regarding the Gateway IDS/IPS?

Options:

A.

Can be combined with Decryption policies

B.

Distributed IDS/IPS must be configured to utilize Gateway IDS/IPS

C.

Distributed IDS/IPS and Gateway IDS/IPS have same set of signatures

D.

Can be used to Detect/Prevent intrusions at network or Zone perimeter

Question 12

Which of the following is NOT true in the context of Malware Prevention?

Options:

A.

Static Analysis is good at catching the benign files and good at catching the obvious malicious files

B.

Static Analysis determines if dynamic analysis is needed

C.

All the files are sent to NSX advanced threat prevention service for dynamic analysis

D.

Dynamic Analysis provides full visibility into subject behavior and system memory

Question 13

Which of the following does the Applied To field impact?

Options:

A.

Per VM vNIC rule count

B.

System wide rule count

C.

ESX host rule count

D.

NSX Manager rule count

Question 14

Which of the following is true regarding the vDefend Gateway Firewall?

Options:

A.

Supported only on the T0 Gateway

B.

Supported only on the T1 Gateway

C.

Supported on both T0 and T1 Gateway

D.

Supported only when IPSec VPN is configured

Question 15

Which statements are true for DFW and Rule processing order based on the information shown in the image? (Select all that apply)

[root@vesxi-nsxt-10:~] vsipioctl getconfig -f nic-2292571-ethO-vmware-sfw.2

ruleset mains {

# generation number: 0

# realization time : 2020-05-21T13:01:48

# FILTER rules

rule 1596 at 1 inout protocol tcp from addrset e70a9a79-c346-48c4-8b9d- 402e97e38a7c to addrset be665396-14d9-4ee4-98b9- 9c21ebfl27a port 464 accept;

rule 1596 at 2 inout protocol udp from addrset e70a9a79-c346-48c4-8b9d- 402e97e38a7c to addrset be665396-14d9-4ee4-98b9- 9c21ebfl27a port 464 accept;

rule 1595 at 3 inout protocol udp from addrset e70a9a79-c346-48c4-8b9d- 402e97e38a7c to addrset 9edl2e5f-36f4-42a9-a79b- 87efc243alef port 53 accept;

rule 1594 at 4 inout protocol udp from addrset e70a9a79-c346-48c4-8b9d- 402e97e38a7c to addrset 59e6aa90-e360-4341-9fb3- b312772b79fb port 123 accept;

rule 2 at 5 inout protocol any from any to any accept;

}

Options:

A.

Rule 1595 will be processed before rule 1596

B.

Rule 1594 will be processed after 1595 and 1596

C.

Rule 1596 will be the first one to be processed

D.

Rule 2 will only be processed if the conditions for the above rules are not met

Question 16

What of the following is true regarding Distributed Firewall logging?

Options:

A.

Broadcom recommends logging all the DFW rules, as it does not have any CPU overhead

B.

VMware Cloud Foundation logging tools are the only supported remote log server supported

C.

The Firewall logs are first sent to the management plane to sanitize any Personally Identifiable Information

D.

Logging can be enabled on per rule basis

Question 17

In the context of Role-Based access control which of the following is NOT a built-in vDefend Role?

Options:

A.

Privileged Admin

B.

Auditor

C.

Network Admin

D.

Security Admin

Question 18

Which of the following are valid configuration options for a VMware vDefend Distributed Firewall Policy? (Select all that apply)

Options:

A.

TCP Strict

B.

Stateful

C.

Locked

D.

Open

Question 19

You need to build a security group that references External DNS servers. Which of the following is the best way to build the Security group?

Options:

A.

Build a Security Group and statically assign the IP addresses of the DNS servers

B.

Build a Security Group that uses OS Name to assign membership to the group

C.

Build a Security Group that uses VM Name to assign membership to the group

D.

Build a Security Group that uses a specific tag name. Assign that tag to each respective DNS server

Question 20

What layers of the OSI model does the vDefend Firewall provide protection?

Options:

A.

L1 - L4

B.

L2 - L7

C.

L3 - L5

D.

L4 - L6

Question 21

Which of the following components can enforce Layer 7 Context Firewall Rules? (Select all that apply)

Options:

A.

Distributed Firewall

B.

Tier 1 Gateway

C.

Tier 0 Gateway

D.

VMK Interface

Question 22

Which vDefend Gateway Firewall feature is ONLY supported on T1 Gateways?

Options:

A.

Gateway IDRS

B.

Stateful Services on A/A Gateways

C.

Gateway IDFW

D.

L3/L4 Gateway Firewall

Page: 1 / 8
Total 75 questions