Q1. From the NSX Edge CLI, which command would show VIP statistics?
A. show service loadbalancer pool
B. show service loadbalancer virtual
C. show service loadbalancer monitor
D. show service loadbalancer
Answer: B
Explanation:
https://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=2122708
Q2. Which three NSX services are available for synchronization in a Cross-vCenter implementation? (Choose three.)
A. Spoofguard
B. Distributed Firewall
C. Edge Firewall
D. Logical Switch
E. Transport Zone
Answer: B,D,E
Explanation:
Referencehttps://pubs.vmware.com/NSX- 62/topic/com.vmware.ICbase/PDF/nsx_62_cross_vc_install.pdf
Q3. Which two methods does VMware NSX offer to integrate with third-party partners? (Choose two )
A. Integration Manager
B. Service Chaining
C. VMwareNSXAPIs
D. Universal Synchronization Service
Answer: A,C
Explanation: https://docs.vmware.com/en/VMware-NSX-for-vSphere/6.3/com.vmware.nsx.admin.doc/GUID-EA477D96-E2D3-488B-90AA- 2F19B4AE327D.html#GUID-EA477D96-E2D3-488B-90AA-2F19B4AE327D
Q4. Which service cannot be included in a Security Policy using Service Composer?
A. Endpoint Services
B. Firewall Rules
C. Virtual Private Network Services
D. Network Introspection Services
Answer: C
Q5. When specifying a source for a security rule, what is the purpose of the Negates Source check box?
A. IfNegate Sourceis selected, the rule is sent to only the objects identified under object type.
B. IfNegate Sourceis selected, the rule is applied to traffic coming from all sources except for the source identified under the object type.
C. IfNegate Sourceis not selected, the rule is applied to traffic comingfrom all sources except for the source identified under the object type.
D. ifNegate Sourceis not selected, the rule is sent to only the objects identified under the object type.
Answer: B
Reference: https://pubs.vmware.com/NSX-6/index.jsp?topic=%2Fcom.vmware.nsx.admin.doc%2FGUID-C7A0093A-4AFA-47EC- 9187-778BDDAD1C65.html
Q6. Which are two uses of the NSX DLR protocol address? (Choose two.)
A. When configuring BGP the protocol address is used to forward traffic to peers.
B. When configuringBGP the protocol address is used by the protocol to form adjacencies with peers.
C. When configuring OSPF the protocol address is used to forward traffic to peers.
D. When configuring OSPF the protocol address is used by the protocol to form
adjacencies with peers.
Answer: B,D
Explanation:
For a logical router
a
Click Edit at the top right corner of the window.
b
Click Enable OSPF.
c
In Forwarding Address, type an IP address that is to be used by the router datapath module in the hosts to forward datapath packets.
d
In Protocol Address, type a unique IP address within the same subnet as the Forwarding Address. Protocol address is used by the protocol to form adjacencies with the peers
From <https://pubs.vmware.com/NSX-6/topic/com.vmware.nsx.admin.doc/GUID-6E985577-3629-42FE-AC22-C4B56EFA8C9B.html>
Q7. An NSX administrator notices an error during the initial configuration of the SSO lookup service, as shown:
The administrator pulls up the lookup service status, which displays Disconnected.
What step should be performed to resolve this issue?
A. Change the Port number from 7444 to 443
B. Change theSSO Administrator User Name
C. Regenerate the SSL Certificate and reboot the NSX Manager
D. Use IP address versus the DNS name in theLookup Service
Answer: C
Q8. You have deployed an Edge Services Gateway with the following interface configuration:
Your customer has requested that you provide the ability to use Remote Desktop Protocol to log into a virtual machine that has a tenant IP address of 192.168.7.21 using the provider IP address 192.168.100.4. You have performed the following configuration however, you cannot RDP into the virtual machine.
What configuration change do you need to make to allow this connection?
A. ChangeApplied Onto “Uplink”
B. Change theProtocolto “any”.
C. Change theTranslated Port/Rangeto “rdp”.
D. Swap theOriginal IP/RangeandTranslated IP/RangeIP Addresses.
Answer: A
Q9. In a vSphere Distributed Switch architecture, which plane handles packet switching?
A. Data Plane
B. Forwarding Plane
C. Management Plane
D. Control Plan
Answer: A
Explanation:
Referencehttps://www.slideshare.net/VMworld/vmworld-2013-vsphere-distributed-switch-design-and-best-practices(slide 7)
Q10. What is the most restrictive NSX role that can be used to create and publish security policies and install virtual appliances?
A. Security Administrator
B. NSX Administrator
C. Auditor
D. Enterprise Administrator
Answer: D