VCP-VCF Administrator 2024 Question 230
Single answerYou are tasked with configuring advanced features in VMware NSX within a VMware Cloud Foundation deployment. The security team has requested that east-west traffic between virtual machines be inspected to detect and prevent potential threats in real-time. Which NSX advanced feature must you configure to meet this requirement?
- A
Distributed Firewall (DFW)
- B
Service Insertion and Network Introspection
- C
Edge NAT
- D
Dynamic Routing Protocols
Show answer and explanation
Correct answer: B
Explanation
To inspect and prevent threats in east-west traffic in real-time within an NSX environment, the Service Insertion and Network Introspection feature must be configured. This feature enables integration with third-party security services, such as IDS/IPS or anti-virus solutions, to inspect and secure VM-to-VM traffic.
- A. Incorrect.
Distributed Firewall (DFW) is primarily used to enforce micro-segmentation and control traffic between virtual machines but does not perform real-time threat inspection.
- B. Correct.
Service Insertion and Network Introspection is the correct feature, as it allows third-party security services to be integrated with NSX to inspect and manage east-west traffic for threats.
- C. Incorrect.
Edge NAT is used for translating network addresses at the edge of the network and does not provide traffic inspection or threat prevention capabilities.
- D. Incorrect.
Dynamic Routing Protocols are used for managing routing decisions in the network and have no role in traffic inspection or threat prevention.