2V0-41.24 exam dumps

2V0-41.24 practice question 261 of 462

VMware Certified Professional - Network Virtualization 2024. Associate level, VMware. Free question with the correct answer and a full explanation.

2V0-41.24 Question 261

Select 3

An organization is using VMware NSX to secure its multi-tier application environment. The administrator needs to configure security policies to ensure that only web servers can communicate with application servers, and database servers are isolated except for specific queries from application servers. Which of the following steps should the administrator include in the security configuration workflow to achieve this?

  1. A

    Create a Distributed Firewall policy to define communication rules between web, application, and database server groups.

  2. B

    Assign the web, application, and database servers to their respective NSX Security Groups based on dynamic membership criteria.

  3. C

    Enable East-West traffic mirroring to monitor all communication between the servers.

  4. D

    Configure a Service Insertion policy to integrate third-party intrusion prevention systems (IPS).

  5. E

    Publish the configured security policies to enforce the rules across the NSX environment.

Show answer and explanation

Correct answers: A, B, E

Explanation

To secure a multi-tier application environment using VMware NSX, the administrator must follow the security configuration workflow. This includes defining communication rules in a Distributed Firewall policy, dynamically grouping workloads into Security Groups, and publishing the configured policies to enforce them. Traffic mirroring and service insertion are additional features that may be used as needed but are not required steps for this specific scenario.

  • A. Correct.

    Correct. Creating a Distributed Firewall policy is a key step in defining and enforcing communication rules between different tiers of the application.

  • B. Correct.

    Correct. Assigning servers to Security Groups based on dynamic membership ensures that policies are automatically applied to the appropriate workloads.

  • C. Incorrect.

    Incorrect. While traffic mirroring might be useful for monitoring, it is not part of the core workflow for configuring security policies in this scenario.

  • D. Incorrect.

    Incorrect. Service Insertion policies are used for integrating third-party services (e.g., IPS/IDS) but are not required for the basic security configuration described in this scenario.

  • E. Correct.

    Correct. Publishing the configured security policies ensures that the rules take effect across the NSX environment.

Timed practice exam

Take a 2V0-41.24 practice test under exam conditions

55 questions in 135 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam