2V0-41.24 Question 421
Select 3You are managing a VMware NSX-T Data Center environment for a financial institution. During a routine audit, you notice that sensitive application traffic might be at risk due to insufficient micro-segmentation. In addition, there have been recent reports of suspicious activity on the network. To address these issues, you decide to use NSX Intelligence to generate security policy recommendations and enable detection of suspicious traffic. Which combination of actions is required to achieve this?
- A
Enable NSX Intelligence and configure the discovery of application dependencies.
- B
Use the 'Recommendations' feature in NSX Intelligence to create firewall rules.
- C
Enable IDS/IPS in NSX Manager and configure a rule to detect suspicious traffic.
- D
Manually create firewall rules based on observed traffic patterns.
- E
Enable Flow Monitoring to visualize suspicious traffic and automatically block it.
Show answer and explanation
Correct answers: A, B, C
Explanation
To address the issues of insufficient micro-segmentation and suspicious traffic detection, you must enable NSX Intelligence to analyze application dependencies and generate security policy recommendations. Additionally, enabling IDS/IPS in NSX Manager allows you to detect and respond to suspicious traffic. These steps ensure a proactive and automated approach to securing the network while addressing the specific requirements of this scenario.
- A. Correct.
Enabling NSX Intelligence and configuring the discovery of application dependencies is essential for generating accurate security policy recommendations.
- B. Correct.
Using the 'Recommendations' feature in NSX Intelligence allows you to create security policies based on observed application traffic patterns, which is crucial for micro-segmentation.
- C. Correct.
Enabling IDS/IPS in NSX Manager is required to detect and mitigate suspicious traffic effectively.
- D. Incorrect.
Manually creating firewall rules is not recommended in this scenario because NSX Intelligence can automate the process with greater accuracy.
- E. Incorrect.
Flow Monitoring provides traffic visibility but does not automatically block suspicious traffic, so it is insufficient for this requirement.