Question No 1: Which three objects are supported for universal synchronization in a Cross-vCenter NSX deployment Choose three. A. IP Pools B. IP Sets C. L2 bridges D. MAC Sets E. Transport Zones Answer: B D E

Question No 2: An organization has a PCI compliant application deployed as part of a larger NSX environment. Every year a team of contractors evaluates the security of the environment and recommends changes. What NSX Role and Scope should the contractors be given to minimize access but still allow them to fulfill the stated requirement A. NSX Administrator Limit access scope B. Enterprise Administrator Limit access scope C. Auditor Limit access scope D. Security Administrator No restrictions Answer: C

Question No 3: In a Cross-vCenter environment where is information about local logical switches and local logical routers maintained A. Local Controller Cluster B. Platform Services Controller C. Universal Controller Cluster D. Local Transport Zone Answer: C

Question No 4: When creating a new security policy how is the default weight determined A. The default weight is equal to the highest defined weight minus 1000. B. The default weight is equal to the highest defined weight plus 1000. C. The default weight is equal to the highest defined weight. D. The default weight is incremented by 100 starting at 0. Answer: B

Question No 5: What is the effect on NSX Edge virtual machines when NSX Edge high availability is configured but vSphere HA is NOT configured A. The active-standby NSX Edge pair will survive one failure. However the virtual machines must reside on the same host to prevent NSX Edge availability from being compromised. B. The active-standby NSX Edge HA pair will survive multiple failures. C. The active-standby NSX Edge HA pair will survive one failure. However if another failure happens before the second Edge appliance is restored NSX Edge availability can be compromised. D. The active-standby NSX Edge HA pair will survive two failures. However the virtual machines must reside on two different hosts. Answer: C

Question No 6: An administrator creates a SpoofGuard policy for specific networks. Which two modes are associated with this type of policy Choose two. A. Automatically trust IP assignments on their first use B. Manually inspect and approve all IP assignments before use C. Manually approve IP assignments listed in the Host file before use D. Automatically inspect and trust IP assignments on every use Answer: A B

Question No 7: Which is required to support unicast mode in NSX A. Hardware VTEP B. Distributed Logical Router C. NSX Controller D. NSX Edge Answer: C

Question No 8: Which type of VPN should be configured to ensure application mobility between data centers A. Application VPN B. L2VPN C. IPSec VPN D. SSL VPN-Plus Answer: B

Question No 9: How is high availability of the NSX Edge Gateway accomplished A. HA Application Monitoring on the Edge Gateway sends a heartbeat to the ESXi host. B. VMware Tools on the Edge Gateway sends a heartbeat to the ESXi host. C. The Edge appliance sends a heartbeat through an uplink interface. D. The Edge appliance sends a heartbeat through an internal interface. Answer: D

Question No 10: Which three changes to a distributed switch configuration could trigger a rollback Choose three. A. Blocking all ports in the distributed port group containing the management VMkernel network adapter. B. Configure the virtual machine system traffic to enable bandwidth allocation using Network I/O Control. C. Adding a new host with a previous vDS configuration. D. Changing the MTU. E. Changing the VLAN settings in the distributed port group of the management VMkernel adapter. Answer: A D E

