2V0-41.24 Question 422
Select 3An organization has deployed VMware NSX-T to secure its workloads. The administrator wants to create dynamic security policies based on observed traffic patterns and enable detection of suspicious traffic in the environment. Which steps should the administrator take to achieve these requirements?
- A
Enable NSX Intelligence and review its recommendations to create micro-segmentation policies.
- B
Manually define firewall rules for all VMs to block suspicious IP addresses.
- C
Enable Distributed IDS/IPS functionality to detect suspicious traffic patterns.
- D
Use the Traceflow tool to observe traffic flow and automatically create security policies.
- E
Review flow analytics in NSX Manager and apply recommendations to create security groups.
Show answer and explanation
Correct answers: A, C, E
Explanation
To meet the requirements of creating dynamic security policies and detecting suspicious traffic, the administrator should enable NSX Intelligence to leverage its recommendations, utilize Distributed IDS/IPS for suspicious traffic detection, and review flow analytics in NSX Manager to apply suggested security groups. These features are specifically designed to enhance security operations within an NSX-T environment.
- A. Correct.
Enabling NSX Intelligence allows administrators to analyze traffic flows and provides recommendations for creating security policies. This aligns with the objective to use recommendations to create security policies.
- B. Incorrect.
Manually defining firewall rules for all VMs is a time-consuming process and does not leverage automated recommendations or detection capabilities provided by NSX.
- C. Correct.
Distributed IDS/IPS functionality in NSX detects suspicious traffic patterns and alerts administrators, fulfilling the requirement to enable detection of suspicious traffic.
- D. Incorrect.
Traceflow is a troubleshooting tool used to observe packet flows and identify connectivity issues, but it does not create security policies automatically.
- E. Correct.
Flow analytics in NSX Manager can provide insights into traffic patterns and suggest group-based security policies, assisting in creating dynamic and effective security configurations.