最上級の5V0-41.21試験問題VMwareテスト最高成績で最速合格をゲットせよ! [Q13-Q33]

Share

最上級の5V0-41.21試験問題VMwareテスト最高成績で最速合格をゲットせよ!

試験準備には最適な5V0-41.21試験問題2024年最新のVMware NSX-T Data Center Security Skills 2023究極な72問があります


VMware 5V0-41.21 試験に備えて、受験者はVMwareが提供する様々なトレーニングコースを利用することができます。これらのコースでは、試験に含まれる全てのトピックをカバーし、受験者が試験に合格するために必要な知識とスキルを習得することを目的としています。また、書籍、練習問題、オンラインフォーラムなどの学習材料を使用して学習を補完することができます。


VMware 5V0-41.21認定試験は、105分以内に完了する必要がある45の多肢選択問題で構成されています。この試験は、NSX-T Data Center 3.1アーキテクチャ、ネットワークセキュリティの概念と原則、分散ファイアウォールの構成、ネットワーク内視点の構成、およびマイクロセグメンテーションなど、さまざまなトピックをカバーしています。試験に合格するには、候補者は500点中少なくとも300点を獲得する必要があります。

 

質問 # 13
An organization wants to add security controlsfor contractor virtual desktops.Which statement Is true when configuring an NSX Identity firewall rule?

  • A. User Identity can only be used in the Destination Section of the firewall rule.
  • B. User Identity can only be used in the Source section of the firewall rule.
  • C. User Identity cannot be used in Source or Destination sections of the firewall rule.
  • D. User Identity can be used in the both the Source and the Destination sections of the firewall rule.

正解:C


質問 # 14
What is the NSX feature that allows a user to block ICMP between 192.168.1.100 and 192.168.1.101?

  • A. NSX Distributed Switch Agent
  • B. NSX Distributed Routing
  • C. NSX Distributed IDS/IPS
  • D. NSX Distributed Firewall

正解:D

解説:
NSX Distributed Firewall is used to create firewall rules to control traffic between networks.
For further reading, see the VMware NSX-T Data Center Administration Guide (https://pubs.vmware.com/NSX-T-Data-Center/index.html#com.vmware.nsxt.admin.doc/GUID-4B6A4A87-F9C7-4AAB-923F-C6B84C33AF7D.html) for more information on configuring firewall rules.


質問 # 15
Which two are the insertion points for North-South service insertion? (Choose two.)

  • A. Uplink of tier-0 gateway
  • B. Transport Node NIC
  • C. Uplink of tier-1 gateway
  • D. Guest VM vNIC
  • E. Partner Service VM

正解:A、E


質問 # 16
Which two are true of the NSX Gateway Firewall? (Choose two.)

  • A. Firewall rules in System category cannot be edited.
  • B. NAT service can be configured in NSX Gateway Firewall policy.
  • C. Security Groups can be used in Applied-To column.
  • D. Firewall rules in Pre Rule category are applied to all gateways.
  • E. Applied-To can be configured at Firewall Policy level.

正解:C、D

解説:
NSX Gateway Firewall is a distributed firewall that provides security for east-west traffic within a virtual environment.
1. Firewall rules in Pre Rule category are applied to all gateways. This category contains system-defined rules that are always applied first to all gateways and cannot be modified. These rules include the default deny all rule and others that control basic connectivity.
2. Security Groups can be used in Applied-To column. Security groups allow you to group together VMs that have similar security requirements and then apply firewall policies to those groups. This way you can apply the same security rules to multiple VMs at once, instead of configuring the rules on each individual VM.
Reference:
VMware NSX-T Data Center documentation https://docs.vmware.com/en/VMware-NSX-T-Data-Center/index.html VMware NSX-T Data Center Gateway Firewall documentation https://docs.vmware.com/en/VMware-NSX-T-Data-Center/3.1/com.vmware.nsxt.firewall.doc/GUID-4C5D5A5F-8FDF-4F2A-9C5A-2C1903A3E5A5.html


質問 # 17
Which three criteria help to determine the severity for a Distributed IDS/IPS? (Choose three.)

  • A. The Distributed Intrusion Detection and Intrusion Prevention rules.
  • B. The severity specified in the signature itself
  • C. The type-rating associated with the classification type.
  • D. The Common Vulnerability Scoring System score specified in the signature.
  • E. The load balancer deployment type.

正解:A、B、E


質問 # 18
What component in a transport node receives the firewall configuration from the central control plane?

  • A. nsx-ccp
  • B. nsx-proxy
  • C. nsx-appl-proxy
  • D. nsx-mpa

正解:D

解説:
The component in a transport node that receives the firewall configuration from the central control plane is the NSX-MPA (Management Plane Agent). The NSX-MPA runs on each transport node and is responsible for connecting to the NSX-T central control plane and receiving the configuration for the transport node. It is also responsible for pushing the configuration down to the other components on the transport node, such as the NSX-Proxy, NSX-Appl-Proxy, and NSX-CCP. Reference: [1] https://docs.vmware.com/en/VMware-NSX-T/3.0/vmware-nsx-t-30-administration-guide/GUID-8C33F5B5-1B98-4A5F-B5B1-D70BE45F9FAD.html [2] https://docs.vmware.com/en/VMware-NSX-T/3.0/com.vmware.nsxt.install.doc/GUID-C129F7F0-E6F8-4A14-B2B0-9D6F3A7A3F62.


質問 # 19
Refer to the exhibit.

An administrator configured a firewall rule on their Edge Gateway to allow access to web servers.
What is missing in the Gateway Firewall policy to have the firewall rule applied?

  • A. Firewall rule needs to be published
  • B. Firewall rule needs to be enabled.
  • C. Firewall service needs to be enabled on gateway.
  • D. Firewall rule needs to be moved to Default category.

正解:D


質問 # 20
To which network operations does a user with the Security Engineer role have full access permission?

  • A. Networking DHCP, Networking NAT, Networking Segments
  • B. Networking Forwarding Policies, Networking NAT, Networking VPN
  • C. Networking IP Address Pools, Networking NAT, Networking DHCP
  • D. Networking Load Balancing, Networking DNS, Networking Forwarding Policies

正解:B


質問 # 21
Which of the following are the local user accounts used to administer NSX-T Data Center?

  • A. operator, admin, root
  • B. admin, audit, root
  • C. admin, super, read-only
  • D. operator, admin, audit

正解:B


質問 # 22
An NSX administrator is trying to find the dvfilter name of the sa-web-01 virtual machine to capture the sa-web-01 VM traffic. What could be a reason the sa-web-01 VM dvfilter name is missing from the command output?

  • A. ESXi host has 5SH disabled.
  • B. sa-web-01 VM has the no firewall rules configured.
  • C. sa-web-01 is powered Off on ESXi host.
  • D. ESXi host has the firewall turned off.

正解:C


質問 # 23
An administrator needs to send FW connections logs to a remote server.
Which sequence of commands does the administrator need to apply on their ESXi Host?
A)

B)

C)

D)

  • A. Option A
  • B. Option B
  • C. Option C
  • D. Option D

正解:C


質問 # 24
Which two statements are true about IDS/IPS signatures? (Choose two.)

  • A. Users can create their own IDS signature definitions from the NSX UI.
  • B. An IDS signature contains a set of instructions that determine which traffic is analyzed.
  • C. An IDS signature contains data used to identify known exploits and vulnerabilities.
  • D. IDS Signatures can be High Risk, Suspicious, Low Risk and Trustworthy.
  • E. Users can upload their own IDS signature definitions from the NSX UI.

正解:B、C

解説:
(https://pubs.vmware.com/NSX-T-Data-Center/index.html#com.vmware.nsxt.admin.doc/GUID-AFAF58DB-E661-4A7D-A8C9-70A3F3A3A3D3.html)


質問 # 25
Which vCenter component is used by the NSX Manager to deploy the Partner Service VM on every host of a cluster configured for guest introspection?

  • A. Update Manager (VUM)
  • B. Component Manager
  • C. Auto Deploy
  • D. ESXi Agent Manager (EAM)

正解:B


質問 # 26
Which of the following describes the main concept of Zero-Trust Networks for network connected devices?

  • A. Network connected devices should only be trusted if the user can be successfully authenticated.
  • B. Network connected devices should only be trusted if their identity and integrity can be verified continually.
  • C. Network connected devices should only be trusted if they are issued by the organization.
  • D. Network connected devices should only be trusted if they are within the organizational boundary.

正解:A


質問 # 27
Which two are used to define dynamic groups for an NSX Distributed Firewall? (Choose two.)

  • A. segment
  • B. tags
  • C. physical servers
  • D. segment's port
  • E. machine name

正解:C、E


質問 # 28
Which two criteria would an administrator use to filter firewall connection logs on NSX?

  • A. FIREWALL RULE TAG
  • B. FIREWALL MONITORING
  • C. FIREWALL-PKTLOG
  • D. FIREWALL SYSTEM
  • E. FIREWALL CONNECTION

正解:D、E


質問 # 29
There has been a confirmed case of virus infection on multiple VMs managed by Endpoint Protection. A security administrator wants to create a group to quarantine infected VMs in the future.
What criteria will be used to build this group?

  • A. NSX Tags
  • B. Segment
  • C. vSphere Tags
  • D. VM Name

正解:C


質問 # 30
Which three are required to configure a firewall rule on a getaway to allow traffic from the internal to web servers? (Choose three.)

  • A. Enable Firewall Service for gateway.
  • B. Create a firewall policy in Local Gateway category.
  • C. Create a firewall rule in System category.
  • D. Create a URL analysis profile for web hosting category.
  • E. Disable the firewall rule in Default category.
  • F. Add a firewall rule in Local Gateway category.

正解:A、B、F

解説:
In order to configure a firewall rule on a gateway to allow traffic from the internal to web servers, the administrator needs to enable the Firewall Service for the gateway, create a firewall policy in the Local Gateway category, and add a firewall rule in the Local Gateway category. This firewall rule should specify the web servers as the destination and the internal network as the source.
For more information on how to configure firewall rules on a gateway, please refer to the NSX-T Data Center documentation: https://docs.vmware.com/en/VMware-NSX-T-Data-Center/3.0/nsx-t-3.0-firewall/GUID-3A79CA7A-9D5E-4F2B-8F75-4EA298E4A4D5.html


質問 # 31
Which two Guest OS drivers are required for the Identity Firewall to operate? (Choose two.)

  • A. Guest Introspection
  • B. e1000e
  • C. vmxnet3
  • D. NSX Network Introspection
  • E. NSX File Introspection

正解:A、D

解説:
The two Guest OS drivers that are required for the Identity Firewall to operate are NSX Network Introspection and Guest Introspection. NSX Network Introspection provides network-level visibility and control, while Guest Introspection provides kernel-level visibility and control. The other drivers listed, vmxnet3, NSX File Introspection, and e1000e, are not required for the Identity Firewall to operate.


質問 # 32
In a brownfield environment with NSX-T Data Center deployed and configured, acustomer is interested in Endpoint Protection integrations. What recommendation should be provided to the customer when it comes to their existing virtual machines?

  • A. Virtual machine must be protected by vSphere HA.
  • B. Virtual machine hardware should be version 10 or higher.
  • C. A custom install of VMware tools is required to select the drivers.
  • D. A minimum installation of VMware tools is required.

正解:B


質問 # 33
......

注目の5V0-41.21豪華セット試験ガイドで最速合格を目指そう:https://www.passtest.jp/VMware/5V0-41.21-shiken.html

5V0-41.21試験ガイド豪華セットで最速合格を目指そう:https://drive.google.com/open?id=1_jkynxVSbRB3LUw83nUfNOlPARXYIUb-