Winter Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: myex65

Home > VMware > VCP-NV 2024 > 2V0-41.24

2V0-41.24 VMware NSX 4.X Professional V2 Question and Answers

Question # 4

What must be configured on Transport Nodes for encapsulation and decapsulation of Geneve protocol?

A.

TEP

B.

STT

C.

VXLAN

D.

UDP

Full Access
Question # 5

When a stateful service is enabled for the first time on a Tier-0 Gateway, what happens on the NSX Edge node?

A.

DR is instantiated and automatically connected with SR.

B.

SR is instantiated and automatically connected with DR.

C.

SR and DR doesn’t need to be connected to provide any stateful services.

D.

SR and DR is instantiated but requires manual connection.

Full Access
Question # 6

What is VMware’s recommendation for the minimum MTU requirements when planning an NSX deployment?

A.

MTU should be set to 1700 or greater across the data center network including inter-data center connections.

B.

MTU should be set to 1500 or less only on inter-data center connections.

C.

Configure Path MTU Discovery and rely on fragmentation.

D.

MTU should be set to 1550 or less across the data center network including inter-data center connections.

Full Access
Question # 7

What are four NSX built-in role-based access control (RBAC) roles? (Choose four.)

A.

None

B.

Read

C.

Auditor

D.

Full Access

E.

Network Admin

F.

Enterprise Admin

G.

Operator

Full Access
Question # 8

Which two of the following are used to configure Distributed Firewall on VDS? (Choose two.)

A.

vSphere API

B.

NSX API

C.

NSX CU

D.

vCenter API

E.

NSX UI

Full Access
Question # 9

Which troubleshooting step will resolve an error with code 1001 during the configuration of a time-based firewall rule?

A.

Restarting the NTPservice on the ESXi host.

B.

Reconfiguring the ESXi host with a local NTP server.

C.

Re-installing the NSX VIBs on the ESXi host.

D.

Changing the time zone on the ESXi host.

Full Access
Question # 10

Which of the following exist only on Tler-1 Gateway firewall configurations and not on Tier-0?

A.

Applied To

B.

Actions

C.

Profiles

D.

Sources

Full Access
Question # 11

Which of the following statements is true regarding the use of a Dynamic Routing Protocol on a Tier-1 Gateway?

A.

Both BGP and OSPF can be used on a Tier-1 Gateway.

B.

You can only use OSPF on the Tier-1 Gateway

C.

A Dynamic Routing Protocol cannot be used on a Tier-1 Gateway.

D.

You can only use BGP on the Tier-1 Gateway.

Full Access
Question # 12

Which CLI command shows syslog on NSX Manager?

A.

(show log manager follow

B.

gee log-file syslog

C.

[get log-file auch.log

D.

/var/log/syslog/syslog.log

Full Access
Question # 13

An NSX administrator is creating a Tier-1 Gateway configured in Active-Standby High Availability Mode. In the event of node failure, the failover policy should not allow the original failed node to become the Active node upon recovery.

Which failover policy meets this requirement?

A.

Enable Preemptive

B.

Non-Preemptive

C.

Preemptive

D.

Disable Preemptive

Full Access
Question # 14

As part of an organization’s IT security compliance requirement, NSX Manager must be configured for 2FA (two-factor authentication).

What should an NSX administrator have ready before the integration can be configured?

A.

Active Directory LDAP integration with ADFS

B.

VMware Identity Manager with NSX added as a Web Application

C.

VMware Identity Manager with an OAuth Client added

D.

Active Directory LDAP integration with OAuth Client added

Full Access
Question # 15

Which VMware GUI tool is used to identify problems in a physical network?

A.

VMware Aria Operations Networks

B.

VMware Aria Automation

C.

VMware Site Recovery Manager

D.

VMware Aria Orchestrator

Full Access
Question # 16

Refer to the exhibit.

An administrator would like to change the private IP address of the NAT VM 172.16.101.11 to a public address of 80.80.80.1 as the packets leave the NAT-Segment network.

Which type of NAT solution should be implemented to achieve this?

A.

NAT64

B.

Reflexive NAT

C.

DNAT

D.

SNAT

Full Access
Question # 17

An architect receives a request to apply distributed firewall in a customer environment without making changes to the network and vSphere environment. The architect decides to use Distributed Firewall on VDS.

Which two of the following requirements must be met in the environment? (Choose two.)

A.

vCenter 8.0 and later

B.

NSX version must be 3.2 and later

C.

NSX version must be 3.0 and later

D.

VDS version 6.6.0 and later

Full Access
Question # 18

Which statement is true about an alarm in a Suppressed state?

A.

An alarm can be suppressed for a specific duration in hours.

B.

An alarm can be suppressed for a specific duration in seconds.

C.

An alarm can be suppressed for a specific duration in days.

D.

An alarm can be suppressed for a specific duration in minutes

Full Access
Question # 19

What are four NSX built-in rote-based access control (RBAC) roles? (Choose four.)

A.

Network Admin

B.

Enterprise Admin

C.

Full Access

D.

Read

E.

LB Operator

F.

None

G.

Auditor

Full Access
Question # 20

Which two statements are true for IPSec VPN? (Choose two.)

A.

IPSec VPN services can be configured at Tier-0 and Tier-1 gateways.

B.

Dynamic routing is supported for any IPSec mode in NSX.

C.

IPSec VPNs use the DPDK accelerated performance library.

D.

VPNs can be configured on the command line interface on the NSX manager.

Full Access
Question # 21

Match the NSX Intelligence recommendations with their correct purpose.

Full Access
Question # 22

Which VMware NSX Portfolio product can be described as a distributed analysis solution that provides visibility and dynamic security policy enforcement for NSX environments?

A.

NSX Manager

B.

NSX Distributed IDS/IPS

C.

NSX Intelligence

D.

NSX Cloud

Full Access
Question # 23

Which of the two following characteristics about NAT64 are true? (Choose two.)

A.

NAT64 requires the Tier-1 gateway to be configured in active-active mode.

B.

NAT64 is stateless and requires gateways to be deployed in active-standby mode.

C.

NAT64 is supported on Tier-0 and Tier-1 gateways.

D.

NAT64 is supported on Tier-1 gateways only.

E.

NAT64 requires the Tier-1 gateway to be configured in active-standby mode.

Full Access
Question # 24

An administrator wants to validate the BGP connection status between the Tier-0 Gateway and the upstream physical router.

What sequence of commands could be used to check this status on NSX Edge node?

A.

- enable

- get vrf

- show bgp neighbor

B.

- get gateways

- vrf

- get bgp neighbor

C.

- set vrf

- show logical-routers

- show bgp

D.

- show logical-routers

- get vrf

- show ip route bgp

Full Access
Question # 25

An NSX administrator is troubleshooting a connectivity issue with virtual machines running on an ESXi transport node.

Which feature in the NSX UI shows the mapping between the virtual NIC and the host’s physical adapter?

A.

Port Mirroring

B.

Activity Monitoring

C.

IPF1X

D.

Switch Visualization

Full Access
Question # 26

Which CLI command does an NSX administrator run on the NSX Manager to generate support bundle logs if the NSX UI is inaccessible?

A.

esxcli system syslog config logger set --id=nsxmanager

B.

get support-bundle file vcpnv.tgz

C.

vm-support

D.

set support-bundle file vcpnv.tgz

Full Access
Question # 27

An NSX administrator is using ping to check connectivity between VM1 running on ESXi1 to VM2 running on ESXi2. The ping tests fail. The administrator knows the maximum transmission unit size on the physical switch is 1600.

Which command does the administrator use to check the VMware kernel ports for tunnel end point communication?

A.

vmkping ++netstack=geneve -d -s 1572

B.

vmkping ++netstack=vxlan -d -s 1572

C.

esxcli network diag ping –H

D.

esxcli network diag ping -I vmk0 -H

Full Access
Question # 28

Which two of the following will be used for ingress traffic on the Edge node supporting a Single Tier topology? (Choose two.)

A.

Tier-1 SR Router Port

B.

Tier-0 Uplink interface

C.

Downlink Interface for the Tier-0 DR

D.

Downlink Interface for the Tier-1 DR

E.

Inter-Tier interface on the Tier-0 gateway

Full Access
Question # 29

An administrator has connected two virtual machines on the same overlay segment. Ping between both virtual machines is successful.

What type of network boundary does this represent?

A.

Layer 2 bridge

B.

Layer 2 broadcast domain

C.

Layer 2 VPN

D.

Layer 3 route

Full Access
Question # 30

An administrator has a requirement to have consistent policy configuration and enforcement across NSX instances.

What feature of NSX fulfills this requirement?

A.

Multi-hvpervisor support

B.

Federation

C.

Load balancer

D.

Policy-driven configuration

Full Access
Question # 31

In an NSX environment, an administrator is observing low throughput and congestion between the Tier-0 Gateway and the upstream physical routers.

Which two actions could address low throughput and congestion? (Choose two.)

A.

Configure ECMP on the Tier-0 gateway.

B.

Configure a Tier-1 gateway and connect it directly to the physical routers.

C.

Deploy Large size Edge node/s.

D.

Configure NAT on the Tier-0 gateway.

E.

Add an additional vNIC to the NSX Edge node.

Full Access
Question # 32

Refer to the exhibit.

An administrator configured NSX Advanced Load Balancer to load balance the production web server traffic, but the end users are unable to access the production website by using the VIP address.

Which of the following Tier-1 gateway route advertisement settings needs to be enabled to resolve the problem? Mark the correct answer by clicking on the image.

Full Access
Question # 33

Which two commands does an NSX administrator use to check the IP address of the VMkernel port for the Geneve protocol on the ESXi transport node? (Choose two.)

A.

net-dvs

B.

esxcfg-nics -l

C.

esxcli network ip interface ipv4 get

D.

esxcfg-vmknic -l

E.

esxcli network nic list

Full Access
Question # 34

Which choice is a valid insertion point for North-South network introspection?

A.

Host Physical NIC

B.

Tier-0 gateway

C.

Guest VM vNIC

D.

Partner SVM

Full Access