Q11. You have deployed an Edge Services Gateway with the following interface configuration:

Your customer has requested that you provide the ability to use Remote Desktop Protocol to log into a virtual machine that has a tenant IP address of using the provider IP address You have performed the following configuration however, you cannot RDP into the virtual machine.

What configuration change do you need to make to allow this connection?

A. ChangeApplied Onto “Uplink”

B. Change theProtocolto “any”.

C. Change theTranslated Port/Rangeto “rdp”.

D. Swap theOriginal IP/RangeandTranslated IP/RangeIP Addresses.

Answer: A

Q12. A virtualized application needs access to a physical database. Both servers are on the subnet. NSX has been deployed across the entire virtual environment.

What method can be used to allow access between the servers?

A. Configure a DLR with an L2 bridge instance for VXLAN to VLAN traffic.

B. Route to the NSX Edge where the logical switch of the applicationexists.

C. Configure a NAT rule for 172.177.13/024 for the database physical router.

D. Configure the logical switch to bridge to the physical router of the database.

Answer: D

Q13. Which three NSX services are available for synchronization in a Cross-vCenter implementation? (Choose three.)

A. Spoofguard

B. Distributed Firewall

C. Edge Firewall

D. Logical Switch

E. Transport Zone

Answer: B,D,E


Referencehttps://pubs.vmware.com/NSX- 62/topic/com.vmware.ICbase/PDF/nsx_62_cross_vc_install.pdf

Q14. In a vSphere Distributed Switch architecture, which plane handles packet switching?

A. Data Plane

B. Forwarding Plane

C. Management Plane

D. Control Plan

Answer: A


Referencehttps://www.slideshare.net/VMworld/vmworld-2013-vsphere-distributed-switch-design-and-best-practices(slide 7)

Q15. An NSX administrator is creating a filter as shown below.

What would be the purpose of creating a filter?

A. To quickly add a new rule.

B. To temporarily filter traffic.

C. To quickly remove a rule.

D. To quickly identify rules.

Answer: D

Q16. What is required before running an Activity Monitoring report?

A. Enable data collection on the NSX Controller.

B. Enable data collection on the vCenter Server.

C. Enable data collection on the NSX Manager.

D. Enable data collection on the virtual machine.

Answer: D

Q17. What is a requirement of NSX Data Security?

A. NSX manager must be configured for Active Directory integration

B. The Global Flow Collection Status must be set to Enabled

C. Guest Introspection must be installed on the cluster

D. AN IP Pool must be created.

Answer: C



Q18. A workload was attached to a logical switch port group in Compute Cluster 1. Users are complaining that I hey can communicate with other workloads on that port group in the cluster, but not with other workloads on different networks.

What is the most probable cause?

A. The distributed firewall has a default rule set to deny all

B. The Distributed Logical Router was not configured on Compute Cluster 1

C. Compute Cluster 1 is NOT a member of the Transport Zone

D. An NSX Edge has NOT been deployed into Compute Cluster 1

Answer: A

Q19. An administrator wants to perform Activity Monitoring on a large group of virtual machines in an NSX environment.

How would this task be accomplished with minimal administrative effort?

A. Create a PowerCLI script to enable virtual machine data collection on each virtual machine.

B. Create a security group in Service Composer and add the virtual machines to the security group.

C. Add the virtual machines to the pre-defined Activity Monitoring security group in Service


D. Add the virtual machines to a VM folder in vCenter Server and enable data collection.

Answer: C

Q20. What is one of the benefits of a spine-leaf network topology?

A. A loop prevention protocol is not required

B. Automatic propagation of security policies to all nodes

C. Allows for VXl ANs to be defined in h traditional network topology

D. Network virtualization relies on spine leaf topologies to create logical switches

Answer: D