Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

5V0-41.21 VMware NSX-T Data Center 3.1 Security Questions and Answers

Questions 4

What is the NSX feature that allows a user to block ICMP between 192.168.1.100 and 192.168.1.101?

Options:

A.

NSX Distributed Switch Agent

B.

NSX Distributed IDS/IPS

C.

NSX Distributed Routing

D.

NSX Distributed Firewall

Buy Now
Questions 5

Which two are true of the NSX Gateway Firewall? (Choose two.)

Options:

A.

Firewall rules in System category cannot be edited.

B.

Firewall rules in Pre Rule category are applied to all gateways.

C.

NAT service can be configured in NSX Gateway Firewall policy.

D.

Security Groups can be used in Applied-To column.

E.

Applied-To can be configured at Firewall Policy level.

Buy Now
Questions 6

Refer to the exhibit.

5V0-41.21 Question 6

Referencing the exhibit, what is the VMware recommended number of NSX Manager Nodes to additionally deploy to form an NSX-T Manager Cluster?

Options:

A.

4

B.

3

C.

2

D.

5

Buy Now
Questions 7

An administrator has configured a new firewall rule but needs to change the Applied-To parameter. Which two are valid options that the administrator can configure? (Choose two.)

Options:

A.

DFW

B.

rule

C.

services

D.

profiles

E.

groups

Buy Now
Questions 8

There has been a confirmed case of virus infection on multiple VMs managed by Endpoint Protection. A security administrator wants to create a group to quarantine infected VMs in the future.

What criteria will be used to build this group?

Options:

A.

NSX Tags

B.

Segment

C.

vSphere Tags

D.

VM Name

Buy Now
Questions 9

Which 3 CU commands ant required to configure remote logging on an ESXI host? (Choose three.)

Options:

A.

esxcl; systex syslcg -sx firewall enable

B.

esxcli network services restart --firewall

C.

esxcli systex syslcg reload

D.

esxcli systex syslog config set " loghost-udp:// < log server IP > : < port >

E.

esxcli network firewall ruleset set -r syslog -e true

Buy Now
Questions 10

An administrator is creating the first distributed firewall rules for a company ' s salts department. What is the first object that must be created in the distributed firewall '

Options:

A.

firewall policy

B.

firewall file

C.

firewall folder

D.

firewall service

Buy Now
Questions 11

Which of the following are the local user accounts used to administer NSX-T Data Center?

Options:

A.

operator, admin, audit

B.

admin, super, read-only

C.

operator, admin, root

D.

admin, audit, root

Buy Now
Questions 12

Which is an insertion point for East-West service insertion?

Options:

A.

tier-1 gateway

B.

Partner SVM

C.

Guest VM vNlC

D.

transport node

Buy Now
Questions 13

Which dot color indicates an on-going attack of medium severity in the IDS/IPS events tab of NSX-T Data Center?

Options:

A.

blinking yellow dot

B.

solid red dot

C.

solid orange dot

D.

blinking orange dot

Buy Now
Questions 14

Which two are used to define dynamic groups for an NSX Distributed Firewall? (Choose two.)

Options:

A.

segment

B.

physical servers

C.

machine name

D.

tags

E.

segment ' s port

Buy Now
Questions 15

Information Security Management (ISM) describes a set of controls that organizations employ to protect which properties?

Options:

A.

confidentiality, integrity, and availability

B.

confidentiality, interoperability, and availability

C.

configuration. Integrity, and availability

D.

confidentiality. Integrity, and accessibility

Buy Now
Questions 16

When using URL Analysis In NSX-T, which two services must be set in the URL rule to capture traffic over TCP and UDP? (Choose two.)

Options:

A.

DNS

B.

DNS-TSIG

C.

DHCPv6

D.

DHCP

E.

DNS-UDP

Buy Now
Questions 17

What type of IDS/IPS system deployment allows an administrator to block a known attack?

Options:

A.

A system deployed in SPAN port mode.

B.

A system deployed inline with ALERT and DROP action.

C.

A system deployed inline with ALERT action.

D.

A system deployed in TERM mode.

Buy Now
Questions 18

Which two are the insertion points for North-South service insertion? (Choose two.)

Options:

A.

Partner Service VM

B.

Uplink of tier-1 gateway

C.

Transport Node NIC

D.

Guest VM vNIC

E.

Uplink of tier-0 gateway

Buy Now
Questions 19

A security administrator is verifying why users are blocked from sports sites but are able to access gambling websites from the corporate network. What needs to be updated In nsx-T to block the gambling websites?

Options:

A.

vSphere Firewall Policy

B.

Endpoint Protection Rules

C.

Network Introspection Policy

D.

URL Analysis Attributes

Buy Now
Questions 20

An administrator needs to configure their NSX-T logging to audit changes on firewall security policy. The administrator Is using the following command from NSX-T3.1 documentation :

5V0-41.21 Question 20

Which Message ID from the following list will allow the administrator to track changes on firewall security rules?

Options:

A.

FABRIC

B.

MONITOR

C.

SYSTEM

D.

FIREWALL

Buy Now
Questions 21

Where is a partner security virtual machine (Partner SVM) deployed to process the redirected North-South traffic in an efficient manner?

Options:

A.

Deployed close to the Partner Manager.

B.

Deployed close to the NSX Edge nodes.

C.

Deployed close to the VMware vCenter Server.

D.

Deployed close to the compute nodes.

Buy Now
Exam Code: 5V0-41.21
Exam Name: VMware NSX-T Data Center 3.1 Security
Last Update: May 7, 2026
Questions: 70

PDF + Testing Engine

$63.52  $181.49

Testing Engine

$50.57  $144.49
buy now 5V0-41.21 testing engine

PDF (Q&A)

$43.57  $124.49
buy now 5V0-41.21 pdf