VMware VCAN610 - VMware Certified Associate– Network Virtualization Exam

Question #11 (Topic: )
An administrator has deployed and powered on a new virtual machine configured to get its
networking information via DHCP. The virtual machine is connected to an NSX network
and connectivity has been verified. After reconfiguring the virtual machine with a static IP
address, network connectivity is lost.
Which statement explains what happened?
A. SpoofGuard is disabled B. SpoofGuard is enabled and the operation mode is set to automatic C. SpoofGuard is enabled and the operation mode is set to manual D. SpoofGuard is enabled but not configured
Answer: B
Question #12 (Topic: )
An NSX Edge Service Gateway has two interfaces:
Internal interface named Internal Access
-- IP address = 10.10.10.1
-- Network mask = 255.255.255.0
Uplink interface named Physical Uplink
-- IP address = 20.20.20.1
-- Network mask = 255.255.255.0
A vSphere administrator wants to add a SNAT rule to allow traffic from the internal network
segment to access external resources via the uplink interface.
Which three steps should the vSphere administrator do to add the SNAT rule? (Choose
three)
A. Apply the SNAT rule to the Internal Access interface. B. Select 10.10.10.1 as the translated source IP. C. Apply the SNAT rule on the Physical Uplink interface. D. Select 10.10.10.0/24 as the original subnet. E. Choose 20.20.20.2 as the translated source IP.
Answer: C,D,E
Question #13 (Topic: )
A company has augmented its Data Center infrastructure by using vCloud Hybrid Service
during peak hours. The company wants to extend their existing subnets into the cloud while
workloads retain their existing IP addresses. The virtual machines in these subnets use an
NSX Edge Gateway as their default gateway.
Which solution should this company use?
A. Layer 2 VPN B. MPLS VPN C. IPSec VPN D. SSL VPN
Answer: A
Question #14 (Topic: )
An administrator wishes to control traffic flow between two virtual machines. The virtual
machines are in the same subnet, but are located on separate ESXi hosts.
The administrator deploys an Edge Firewall to one of the hosts and verifies the default
firewall rule is set to deny, but the two virtual machines can still communicate with each
other.
What task will correct this issue?
A. Configure both ESXi host firewalls to deny traffic from the virtual machine on the other host. B. Deploy another Edge Firewall on the host running the second virtual machine. C. Remove any other firewall appliances that may exist on either of the ESXi hosts. D. Deploy a Distributed Firewall with firewall rules to prevent traffic between the virtual machines.
Answer: D
Question #15 (Topic: )
Which option shows an advantage of implementing logical firewalls in NSX?
A. NSX allows segmentation of virtual machines based upon VM names or user identity. B. NSX provides traffic forwarding between layer 2 broadcast domains. C. NSX allows virtual machine traffic to follow multiple paths to a specific destination. D. NSX provides the ability to provide IPv4 and IPv6 dual stack configuration.
Answer: A
Download Exam
Page: 3 / 36
Total 178 questions