2V0-41.24 Question 257
Select 3An organization has deployed VMware NSX Federation to manage a multi-site network with centralized policy enforcement. The security team wants to ensure that sensitive data communication between the Global Manager (GM) and Local Managers (LMs) is protected, and they also need to secure inter-site communication for disaster recovery purposes. Which of the following are valid security use cases for VMware NSX Federation?
- A
Encrypting communication between the Global Manager (GM) and Local Managers (LMs).
- B
Implementing role-based access control (RBAC) for administrative users across sites.
- C
Securing data plane traffic between Virtual Machines (VMs) across federated sites.
- D
Providing secure communication between sites for disaster recovery and failover.
- E
Enforcing guest OS-level security policies on VMs managed by NSX Federation.
Show answer and explanation
Correct answers: A, B, D
Explanation
VMware NSX Federation provides security use cases such as encrypted communication between management components (Global Manager and Local Managers), role-based access control for administrators across federated sites, and secure communication between sites for critical scenarios like disaster recovery and failover. These features ensure a secure and scalable multi-site network management environment.
- A. Correct.
Correct: VMware NSX Federation encrypts communication between the Global Manager and Local Managers to ensure secure management traffic.
- B. Correct.
Correct: NSX Federation supports role-based access control (RBAC) to manage administrative access and permissions across multiple sites securely.
- C. Incorrect.
Incorrect: Securing data plane traffic between VMs is not a direct security use case of NSX Federation, as it focuses on management and control plane security rather than VM-to-VM data traffic.
- D. Correct.
Correct: NSX Federation provides secure communication between sites, which is critical for disaster recovery and failover scenarios.
- E. Incorrect.
Incorrect: Enforcing guest OS-level security policies is outside the scope of NSX Federation, as it focuses on network virtualization and not guest OS-level management.