Q21. Which two network services are abstracted from the underlying hardware by NSX? (Choose two.)

A. Virtual Private Networks

B. Multiprotocol Label Switching

C. Load Balancing

D. Overlay Transport Virtualizations

Answer: A,C



Q22. If the Applied To scope is set to Distributed Firewall, which virtual machines with have the firewall rule applied?

A. Only the virtual machines defined in the Source field.

B. Only virtual machines defined in the Destination field.

C. All virtual machines in a Datacenter.

D. All virtual machines on prepared hosts.

Answer: C



Q23. What are the correct steps for connecting a virtual machine to a logical switch?

A. Select the logical switch, click the Add Virtual Machine Icon, select the VM, select the

vNIC to connect B. Select the Add Virtual Machine icon, select the logical switch, vNIC to connect

B. Select the logical switch, select the virtual machine, click the Add Virtual Machine .con. select the vNIC to connect

C. Select the vNIC, click the Add Virtual Machine Icon, select the logical switch

Answer: A

Explanation: 51C078EC601D.html

Q24. What is a requirement of NSX Data Security?

A. NSX manager must be configured for Active Directory integration

B. The Global Flow Collection Status must be set to Enabled

C. Guest Introspection must be installed on the cluster

D. AN IP Pool must be created.

Answer: C



Q25. What is the best practice workflow for a NSX installation to support logical switching?

A. Deploy NSX Manager, Configure Logical Switches, Register with vCenter, Deploy Controllers. Prepare hosts

B. Deploy NSX Manager, Deploy Controllers, Configure Logical Switches, Register withvCenter, Prepare hosts

C. Deploy NSX Manager, Register with vCenter, Prepare hosts, Deploy Controllers, Configure Logical Switches

D. Deploy NSX Manager, Register with vCenter, Deploy Controllers, Prepare hosts, Configure Logical Switches

Answer: B

Q26. Exhibit:

Which would best describe a workload in Compute Cluster 1 attached to a logical switch port group?

A. Within Compute Cluster 1, Layer 2 would function, but Layer 3 would fail.

B. Within Compute Cluster 1, Layer 2 would fail, and Layer 3 would fail.

C. Within ComputeCluster 1, Layer 2 would fail, but Layer 3 would function.

D. Within Compute Cluster 1, Layer 2 would function, and Layer 3 would function.

Answer: A


This has an interesting side effect: if you didn’t add all clusters of a given DVS to the TZ, those clusters you haven’t added will still have access to that Logical Switch. Let’s have a look at the following diagram:

From < understanding-transport-zone-scoping/>

his means that in out hypothetical case, if we were to create a DLR and connect to it that

LS we’ve created earlier, DLR instance would get created on hosts in clusters Comp B and

Mgmt / Edge, but not on hosts in clusteCr omp A:

From <

Q27. In a vSphere Distributed Switch architecture, which plane handles packet switching?

A. Data Plane

B. Forwarding Plane

C. Management Plane

D. Control Plan

Answer: A


Reference 7)

Q28. An organization has PCI compliant application deployed as part of a larger NSX environment. Every year a team of contractors evaluates the security of the environment and recommends changes.

What NSX Role and Scope should the contractors be given to minimize access but still allow them to fulfill the staled requirement?

A. Security Administrator, No restrictions

B. Auditor. Limit access scope

C. NSX Administrator, Limit access scope

D. Enterprise Administrator, Limit access scope

Answer: B

Explanation: d_Reference_Architecture_for_PCI_v3.0_June_2014b1844892b9e7e4c6aa280f5fd9df5a0f. pdf

Page 3

VMware NSX™ VMware NSX Edge™, VMware NSX Firewall, VMware NSX Router, VMware NSX Load

Balancer, and, VMware NSX Service Composer

Q29. A virtualized application needs access to a physical database. Both servers are on the subnet. NSX has been deployed across the entire virtual environment.

What method can be used to allow access between the servers?

A. Configure a DLR with an L2 bridge instance for VXLAN to VLAN traffic.

B. Route to the NSX Edge where the logical switch of the applicationexists.

C. Configure a NAT rule for 172.177.13/024 for the database physical router.

D. Configure the logical switch to bridge to the physical router of the database.

Answer: D

Q30. When designing a multi-site NSX deployment, which capably requires Enhanced Linked Mode to function?

A. Creating Universal Transport Zones

B. Creating Universal Logical Switches

C. Cross-vCenter vMotion

D. Registering a Secondary NSX Manager

Answer: A


Reference 62/topic/com.vmware.ICbase/PDF/nsx_62_cross_vc_install.pdf