2V0-41.24 Question 16
Single answerAn organization is deploying VMware NSX and wants to ensure that security policies are consistently applied across all workloads, regardless of their physical location or the hypervisor they run on. The organization also aims to manage these policies centrally with minimal administrative overhead. Which feature of NSX policy and centralized policy management best addresses this requirement?
- A
Distributed Firewall (DFW)
- B
Group-Based Policies
- C
NSX Federation
- D
Identity Firewall
Show answer and explanation
Correct answer: C
Explanation
NSX Federation is the correct answer because it enables centralized policy management across multiple NSX environments, ensuring consistent enforcement of security policies regardless of workload location or hypervisor. This capability directly addresses the organization's requirement for minimal administrative overhead and consistent policy application.
- A. Incorrect.
Distributed Firewall (DFW) provides micro-segmentation and firewalling capabilities at the workload level, but it does not centralize policy management across multiple NSX environments.
- B. Incorrect.
Group-Based Policies allow for flexible policy application by grouping workloads based on attributes, but they do not inherently address central management across multiple NSX deployments.
- C. Correct.
NSX Federation allows for centralized policy management by enabling global policy configuration and enforcement across multiple NSX environments, ensuring consistency across locations.
- D. Incorrect.
Identity Firewall focuses on user-based access control and does not provide centralized policy management for workloads across multiple NSX environments.