2V0-41.24 exam dumps

2V0-41.24 practice question 421 of 462

VMware Certified Professional - Network Virtualization 2024. Associate level, VMware. Free question with the correct answer and a full explanation.

2V0-41.24 Question 421

Select 3

You are managing a VMware NSX-T Data Center environment for a financial institution. During a routine audit, you notice that sensitive application traffic might be at risk due to insufficient micro-segmentation. In addition, there have been recent reports of suspicious activity on the network. To address these issues, you decide to use NSX Intelligence to generate security policy recommendations and enable detection of suspicious traffic. Which combination of actions is required to achieve this?

  1. A

    Enable NSX Intelligence and configure the discovery of application dependencies.

  2. B

    Use the 'Recommendations' feature in NSX Intelligence to create firewall rules.

  3. C

    Enable IDS/IPS in NSX Manager and configure a rule to detect suspicious traffic.

  4. D

    Manually create firewall rules based on observed traffic patterns.

  5. E

    Enable Flow Monitoring to visualize suspicious traffic and automatically block it.

Show answer and explanation

Correct answers: A, B, C

Explanation

To address the issues of insufficient micro-segmentation and suspicious traffic detection, you must enable NSX Intelligence to analyze application dependencies and generate security policy recommendations. Additionally, enabling IDS/IPS in NSX Manager allows you to detect and respond to suspicious traffic. These steps ensure a proactive and automated approach to securing the network while addressing the specific requirements of this scenario.

  • A. Correct.

    Enabling NSX Intelligence and configuring the discovery of application dependencies is essential for generating accurate security policy recommendations.

  • B. Correct.

    Using the 'Recommendations' feature in NSX Intelligence allows you to create security policies based on observed application traffic patterns, which is crucial for micro-segmentation.

  • C. Correct.

    Enabling IDS/IPS in NSX Manager is required to detect and mitigate suspicious traffic effectively.

  • D. Incorrect.

    Manually creating firewall rules is not recommended in this scenario because NSX Intelligence can automate the process with greater accuracy.

  • E. Incorrect.

    Flow Monitoring provides traffic visibility but does not automatically block suspicious traffic, so it is insufficient for this requirement.

Timed practice exam

Take a 2V0-41.24 practice test under exam conditions

55 questions in 135 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam