Q11. A workload was attached to a logical switch port group in Compute Cluster 1. Users are complaining that I hey can communicate with other workloads on that port group in the cluster, but not with other workloads on different networks.

What is the most probable cause?

A. The distributed firewall has a default rule set to deny all

B. The Distributed Logical Router was not configured on Compute Cluster 1

C. Compute Cluster 1 is NOT a member of the Transport Zone

D. An NSX Edge has NOT been deployed into Compute Cluster 1

Answer: A

Q12. What are two benefits of the NSX Distributed Firewall? (Choose two )

A. VMs are protected even as they are vMotioned

B. Each VM is individually protected by a L2-L4 stateful firewall

C. ESXi hosts are automatically protected by a distributed firewall

D. VXLANs are automatically protected by the Transport Zone definition

Answer: A,C

Q13. An NSX Edge Service Gateway has two interfaces:

• Internal interface named Internal Access

-- IP address =

-- Network mask =

• Uplink interface named Physical Uplink

-- IP address =

-- Network mask =

A vSphere administrator wants to add a SNAT rule to allow traffic from the internal network segment to access external resources via the uplink interface.

Which three steps should the vSphere administrator do to add the SNAT rule? (Choose three.)

A. Apply the SNAT rule to the Internal Access interface.

B. Select as the translated source IP.

C. Apply the SNAT rule on the Physical Uplink interface.

D. Select as the original subnet.

E. Choose as the translated source IP address.

Answer: C,D,E

Q14. An NSX administrator is validating the setup for a new NSX implementation and inputs this command:

A. It helps verify that VXLAN segments are functional and the transport network supports the proper MTU size for NSX.

B. It helps verify that the source virtual machine is configured with the proper MTU size for NSX.

C. It helps verify that the NSX Controller is communicating with the destination VTEP.

D. It helps verify that the NSX Logical Switch is routing packets to the destination host.

Answer: A



Q15. An NSX environment requires physical NIC redundancy for all dvPortGroups when connecting hosts to the physical network. There are two 10Gb NIC's per host.

Which two teaming methods should be used to ensure both links are utilized simultaneously? (Choose two )

A. Virtual Port Channel

B. LACP Port-Channel

C. Static Port-Channel

D. Explicit Failover Order

Answer: A,B

Q16. A network administrator is troubleshooting an issue and needs to observe an injected packet as it passes through the physical and logical network.

Which tool will accomplish this?

A. Traceflow

B. NetFlow

C. Flow Monitoring

D. Activity Monitoring

Answer: A


Referencehttps://pubs.vmware.com/NSX-62/index.jsp?topic=%2Fcom.vmware.nsx.admin.doc%2FGUID-05647D5E-B669-40A8- 8B84-02C18781186F.html

Q17. Which three methods can be used by the NSX Distributed Firewall to discover IP addresses? (Choose three )

A. DHCP Snooping

B. IP Sets

C. Spoofguard configured forTrust on First Use.

D. VMware Tools installed on every guest virtual machine.

E. ARP Spoofing

Answer: A,C,D



Q18. From the NSX Edge CLI, which command would show VIP statistics?

A. show service loadbalancer pool

B. show service loadbalancer virtual

C. show service loadbalancer monitor

D. show service loadbalancer

Answer: B



Q19. What is the most restrictive NSX role that can be used to create and publish security policies and install virtual appliances?

A. Security Administrator

B. NSX Administrator

C. Auditor

D. Enterprise Administrator

Answer: D

Q20. An administrator has been asked to provide single failure redundancy. What is the minimum supported number of NSX Controllers needed to meet this requirement?

A. 2

B. 3

C. 1

D. 5

Answer: B


Referencehttp://www.vmwarearena.com/vmware-nsx-installation-part-4-deploying-nsx- controller/