オンライン問題で最適な5V0-41.21試験練習問題(最新の72問題)
練習問題5V0-41.21素晴らしい練習用のVMware NSX-T Data Center 3.1 Securityテスト問題
質問 # 36
How does N5X Distributed IDS/IPS keep up to date with signatures?
- A. NSX Edge uses manually uploaded signatures by the security administrator.
- B. NSX Distributed IDS/IPS signatures are retrieved from updates.vmware.com.
- C. NSX-T Data Center is using a cloud based database to download the IDS/IPS signatures.
- D. NSX Manager has a local IDS/IPS signatures database that does not need to be updated.
正解:D
質問 # 37
An administrator wants to use Distributed Intrusion Detection. How is this implemented in an NSX-T Data Center?
- A. As a distributed solution across multiple NSX Managers.
- B. As a distributed solution across multiple KVM hosts.
- C. As a distributed solution across multiple NSX Edge nodes.
- D. As a distributed solution across multiple ESXi hosts.
正解:C
解説:
An administrator can implement Distributed Intrusion Detection as a distributed solution across multiple NSX Edge nodes in an NSX-T Data Center. This allows for real-time monitoring of network traffic, as well as detection and prevention of malicious activity. Additionally, it can be used to identify, investigate, and respond to potential security threats. Reference: [1] https://docs.vmware.com/en/VMware-NSX-T/3.0/vmware-nsx-t-30-administration-guide/GUID-1F8741C0-D1CD-4EA3-A2BB-98CEF7F8D1DA.html [2] https://www.vmware.com/content/dam/digitalmarketing/vmware/en/pdf/techpaper/vmware-nsx-data-center-for-vsphere-distributed-intrusion-detection-deployment-guide.pdf
質問 # 38
Which two are the insertion points for North-South service insertion? (Choose two.)
- A. Guest VM vNIC
- B. Uplink of tier-0 gateway
- C. Uplink of tier-1 gateway
- D. Partner Service VM
- E. Transport Node NIC
正解:B、D
質問 # 39
An administrator wants to use Distributed Intrusion Detection. How is this implemented in an NSX-T Data Center?
- A. As a distributed solution across multiple NSX Managers.
- B. As a distributed solution across multiple KVM hosts.
- C. As a distributed solution across multiple NSX Edge nodes.
- D. As a distributed solution across multiple ESXi hosts.
正解:C
解説:
An administrator can implement Distributed Intrusion Detection as a distributed solution across multiple NSX Edge nodes in an NSX-T Data Center. This allows for real-time monitoring of network traffic, as well as detection and prevention of malicious activity. Additionally, it can be used to identify, investigate, and respond to potential security threats. Reference: [1] https://docs.vmware.com/en/VMware-NSX-T/3.0/vmware-nsx-t-30-administration-guide/GUID-1F8741C0-D1CD-4EA3-A2BB-98CEF7F8D1DA.html [2] https://www.vmware.com/content/dam/digitalmarketing/vmware/en/pdf/techpaper/vmware-nsx-data-center-for-vsphere-distributed-intrusion-detection-deployment-guide.pdf
質問 # 40
What is an unprotected traffic flow in NSX Intelligence?
- A. A traffic flow that matches a reject rule more granular than the default.
- B. A traffic flow that matches the default distributed firewall rule.
- C. A traffic flow that matches an allow rule more granular than the default.
- D. A traffic flow that matches a drop rule more granular than the default.
正解:B
解説:
An unprotected traffic flow in NSX Intelligence is a traffic flow that matches the default distributed firewall rule. The default rule is a catch-all rule which allows all traffic to pass through the distributed firewall, and any traffic flows that match this rule will be marked as unprotected. NSX Intelligence will then generate an alert for any unprotected traffic flows, allowing the administrator to take action to secure the traffic flow. Reference: [1] https://docs.vmware.com/en/VMware-NSX-T/3.0/vmware-nsx-t-30-administration-guide/GUID-D43B9C85-7F4C-4504-8D2B-BC1D7CADB4CD.html [2] https://www.vmware.com/content/dam/digitalmarketing/vmware/en/pdf/techpaper/vmware-nsx-data-center-for-vsphere-distributed-firewall-deployment-guide.pdf
質問 # 41
At which OSI Layer do Next Generation Firewalls capable of analyzing application traffic operate?
- A. Layer 7
- B. Layer 2
- C. Layer 3
- D. Layer 4
正解:A
質問 # 42
What is the default action of the Default Layer 3 distributed firewall rule?
- A. Allow
- B. Forward
- C. Drop
- D. Reject
正解:C
解説:
The Default Layer 3 distributed firewall rule is a system-defined rule in NSX-T Data Center that applies to all distributed firewall sections. By default, this rule is set to drop all traffic, meaning that any traffic that does not match a specific rule will be dropped.
For more information on the Default Layer 3 distributed firewall rule and how to configure it, please refer to the NSX-T Data Center documentation: https://docs.vmware.com/en/VMware-NSX-T-Data-Center/3.0/nsx-t-3.0-firewall/GUID-B6B835F2-B6F2-4468-8F8E-6F7B9B9D6E91.html
質問 # 43
What is the default action of the Default Layer 3 distributed firewall rule?
- A. Allow
- B. Forward
- C. Reject
- D. Drop
正解:B
質問 # 44
At which two intervals are NSX-T IDS/IPS updates through VMware's cloud based internet service provided for threat signature files? (Choose two.)
- A. off-schedule for 0-day updates
- B. daily periodic updates
- C. weekly periodic updates
- D. monthly periodic updates
- E. bi-weekly periodic updates
正解:A、D
質問 # 45
A security administrator recently enabled Guest Introspection on NSX-T Data Center.
Which would be a reason none of the Microsoft Windows based VMs are reporting any information?
- A. NSX Manager require a reboot.
- B. NSX Manager needs to be reconfigured.
- C. Windows VMs require a reboot.
- D. VMware Tools need to be reconfigured.
正解:B
解説:
NSX Manager needs to be reconfigured. Guest Introspection requires additional configuration of the NSX Manager in order to collect information from the Windows based VMs. This configuration includes setting up the Guest Introspection service with the appropriate credentials and configuring the rules to allow the traffic through the firewall. Once this is done, the Windows VMs will start reporting information to the NSX Manager.
For more information on setting up Guest Introspection, please refer to the NSX-T Data Center documentation: https://docs.vmware.com/en/VMware-NSX-T-Data-Center/3.0/nsx-t-3.0-installing/GUID-3B7F12AD-D8F7-44B9-A56B-E71F64C2F6A0.html
質問 # 46
An administrator needs to send FW connections logs to a remote server.
Which sequence of commands does the administrator need to apply on their ESXi Host?
A)
B)
C)
D)
- A. Option B
- B. Option A
- C. Option C
- D. Option D
正解:C
質問 # 47
What component in a transport node receives the firewall configuration from the central control plane?
- A. nsx-proxy
- B. nsx-mpa
- C. nsx-appl-proxy
- D. nsx-ccp
正解:C
質問 # 48
Which of the following describes the main concept of Zero-Trust Networks for network connected devices?
- A. Network connected devices should only be trusted if their identity and integrity can be verified continually.
- B. Network connected devices should only be trusted if they are within the organizational boundary.
- C. Network connected devices should only be trusted if the user can be successfully authenticated.
- D. Network connected devices should only be trusted if they are issued by the organization.
正解:C
質問 # 49
An NSX administrator is trying to find the dvfilter name of the sa-web-01 virtual machine to capture the sa-web-01 VM traffic. What could be a reason the sa-web-01 VM dvfilter name is missing from the command output?
- A. sa-web-01 is powered Off on ESXi host.
- B. ESXi host has the firewall turned off.
- C. ESXi host has 5SH disabled.
- D. sa-web-01 VM has the no firewall rules configured.
正解:A
解説:
The most likely reason the sa-web-01 VM dvfilter name is missing from the command output is that the sa-web-01 VM is powered off on the ESXi host. The dvfilter name is associated with the VM when it is powered on, and is removed when the VM is powered off. Therefore, if the VM is powered off, then the dvfilter name will not be visible in the command output. Other possible reasons could be that the ESXi host has the firewall turned off, the ESXi host has 5SH disabled, or that the sa-web-01 VM has no firewall rules configured. Reference: [1] https://kb.vmware.com/s/article/2143718 [2] https://docs.vmware.com/en/VMware-NSX-T/3.0/vmware-nsx-t-30-administration-guide/GUID-AC3CC8A3-B2DE-4A53-8F09-B8EEE3E3C7D1.html
質問 # 50
What is one of the main use-cases of NSX-T Endpoint Protection?
- A. Use Network Security Services of a third party vendor
- B. East-West Firewalling
- C. Agentless Antivirus
- D. North-South Firewalling
正解:B
質問 # 51
Refer to the exhibit.
An administrator is reviewing NSX Intelligence information as shown in the exhibit.
What does the red dashed line for the UDP:137 flow represent?
- A. Discovered communication
- B. Allowed communication
- C. Unprotected communication
- D. Blocked communication
正解:D
質問 # 52
How does N5X Distributed IDS/IPS keep up to date with signatures?
- A. NSX Edge uses manually uploaded signatures by the security administrator.
- B. NSX Manager has a local IDS/IPS signatures database that does not need to be updated.
- C. NSX Distributed IDS/IPS signatures are retrieved from updates.vmware.com.
- D. NSX-T Data Center is using a cloud based database to download the IDS/IPS signatures.
正解:C
質問 # 53
Where is a partner security virtual machine (Partner SVM) deployed to process the redirected North-South traffic in an efficient manner?
- A. Deployed close to the compute nodes.
- B. Deployed close to the Partner Manager.
- C. Deployed close to the NSX Edge nodes.
- D. Deployed close to the VMware vCenter Server.
正解:C
解説:
Reference:
This allows for the Partner SVM to be close to the compute nodes, allowing for faster processing of the traffic and improved security. Additionally, the Partner SVM is also deployed close to the Partner Manager for added security and ease of management.
質問 # 54
To which network operations does a user with the Security Engineer role have full access permission?
- A. Networking IP Address Pools, Networking NAT, Networking DHCP
- B. Networking Load Balancing, Networking DNS, Networking Forwarding Policies
- C. Networking DHCP, Networking NAT, Networking Segments
- D. Networking Forwarding Policies, Networking NAT, Networking VPN
正解:C
質問 # 55
Which 3 CU commands ant required to configure remotelogging on an ESXI host? (Choose three.)
- A. esxcli systex syslog config set "loghost-udp://<log server IP>:<port>
- B. esxcl; systex syslcg -sx firewall enable
- C. esxcli systex syslcg reload
- D. esxcli network firewall ruleset set -r syslog -e true
- E. esxcli network services restart --firewall
正解:C、D、E
質問 # 56
A company's CTO has requested that all logging should be enabled for all NSX-T Data Center Distributed Firewall rules. What should be considered prior to executing this request?
- A. Large amounts of log information can fill up the vSphere Server database.
- B. Logging can only be enabled for sections and not for single rules.
- C. Once logging is enabled for all rules it cannot be disabled afterwards.
- D. Large amounts of log information will likely affect performance.
正解:C
質問 # 57
......
VMware 5V0-41.21試験は、VMware NSX-T Data Center 3.1セキュリティの専門知識を検証するための認定試験です。VMware NSX-T Data Centerは、仮想ネットワークの作成を可能にし、これらのネットワークを保護する包括的なセキュリティ機能を提供するネットワーク仮想化およびセキュリティプラットフォームです。この試験は、VMware NSX-T Data Center 3.1でセキュリティソリューションを構成、管理、トラブルシューティングするための候補者の知識とスキルをテストします。
リアルな5V0-41.21試験別格な練習試験問題:https://www.passtest.jp/VMware/5V0-41.21-shiken.html
100%合格率でリアルな5V0-41.21試験成功ゲット:https://drive.google.com/open?id=1BDc4gcCMhOwss5cyY0kXfcpm4i5KZqaG