VCP-VCF Administrator 2024 exam dumps

VCP-VCF Administrator 2024 practice question 239 of 379

VMware Certified Professional - VMware Cloud Foundation Administrator 2024. Free level, VMware. Free question with the correct answer and a full explanation.

VCP-VCF Administrator 2024 Question 239

Select 3

An organization is configuring a VPN service in NSX to establish secure connectivity between their on-premises data center and a VMware Cloud Foundation workload domain. As the VMware Cloud Foundation Administrator, you are tasked to set up the VPN. Which steps are required to successfully configure the VPN service in NSX?

  1. A

    Create an IPsec or L2VPN session on the NSX Edge Gateway.

  2. B

    Configure a Tier-1 Gateway to serve as the VPN endpoint.

  3. C

    Ensure that MTU settings are configured properly on both VPN endpoints.

  4. D

    Establish a firewall rule allowing VPN traffic on the Tier-0 Gateway.

  5. E

    Enable SSL VPN-Plus on the NSX Edge appliance for remote access.

Show answer and explanation

Correct answers: A, C, D

Explanation

To configure VPN service in NSX, the administrator must create an IPsec or L2VPN session on the NSX Edge Gateway, ensure proper MTU settings are applied, and create firewall rules to allow VPN traffic on the Tier-0 Gateway. Configuring a Tier-1 Gateway or enabling SSL VPN-Plus is not relevant for setting up a site-to-site VPN in this scenario.

  • A. Correct.

    Correct: Creating an IPsec or L2VPN session on the NSX Edge Gateway is required to establish the VPN connection. This is a fundamental step in VPN configuration.

  • B. Incorrect.

    Incorrect: A Tier-1 Gateway cannot act as a VPN endpoint. VPN endpoints are typically configured on Tier-0 Gateways or NSX Edge devices.

  • C. Correct.

    Correct: MTU settings must align between both VPN endpoints to avoid packet fragmentation and ensure smooth data transfer.

  • D. Correct.

    Correct: Traffic for the VPN must be allowed on the Tier-0 Gateway via appropriate firewall rules. Without this, the VPN traffic will be blocked.

  • E. Incorrect.

    Incorrect: SSL VPN-Plus is used for remote access VPN scenarios, not site-to-site VPN configurations typically required in this scenario.

Timed practice exam

Take a VCP-VCF Administrator 2024 practice test under exam conditions

70 questions in 135 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam