N10-009 Question 29
Single answerNetwork functions virtualization (NFV)A company is opening several small branch offices and wants to reduce the cost and time required to deploy network services at each site. The network team plans to replace dedicated hardware firewalls, WAN optimizers, and VPN concentrators with software-based instances running on standard x86 servers. They also want the ability to spin up or update these services remotely without shipping new appliances to each branch. Which technology best meets these requirements?
- A
Network functions virtualization (NFV)
- B
Port mirroring
- C
Virtual LAN (VLAN)
- D
Link aggregation
Show answer and explanation
Correct answer: A
Explanation
The best answer is Network functions virtualization (NFV). NFV is designed to decouple network services from proprietary hardware appliances and run them as software on virtual machines or containers hosted on standard servers. This makes it especially useful in branch-office and edge deployments where organizations want faster provisioning, lower hardware costs, simplified logistics, and centralized management. In practice, NFV commonly supports functions such as virtual firewalls, virtual routers, IDS/IPS, load balancers, and VPN gateways. This aligns with industry guidance from ETSI NFV, which defines NFV as the virtualization of network functions traditionally carried out by dedicated hardware. For Network+, candidates should recognize that NFV focuses on virtualizing network services, while related technologies like VLANs, port mirroring, and link aggregation solve different networking problems.
- A. Correct.
Correct. Network functions virtualization (NFV) replaces dedicated network appliances with virtualized software functions, such as virtual firewalls, virtual routers, and virtual VPN gateways, running on commodity hardware. In this scenario, NFV directly addresses the need to deploy and manage network services remotely, reduce hardware dependency, and speed branch rollouts.
- B. Incorrect.
Incorrect. Port mirroring copies traffic from one switch port or VLAN to another destination for monitoring or analysis. It is useful for IDS, packet capture, and troubleshooting, but it does not virtualize network services or replace branch appliances.
- C. Incorrect.
Incorrect. A VLAN logically segments a Layer 2 network into separate broadcast domains. While VLANs are commonly used in branch networks, they do not provide firewall, VPN, or WAN optimization functions and do not replace dedicated network appliances.
- D. Incorrect.
Incorrect. Link aggregation combines multiple physical links into a single logical link to improve bandwidth or redundancy. Although helpful for resilience and throughput, it does not provide software-based network services or centralized deployment of virtualized network functions.