exam questions

Exam NCP-MCI v6.5 All Questions

View all questions & answers for the NCP-MCI v6.5 exam

Exam NCP-MCI v6.5 topic 1 question 86 discussion

Actual exam question from Nutanix's NCP-MCI v6.5
Question #: 86
Topic #: 1
[All NCP-MCI v6.5 Questions]

An administrator is preparing to deploy a new application on an AHV cluster. Security requirements dictate that all virtual servers supporting this application must be prevented from communicating with unauthorized hosts.

Which option would achieve this goal?

  • A. Create a new subnet and assign to an existing VPC, assign the network IP prefix and gateway for the subnet, deploy servers with vNICs in the new subnet.
  • B. Create a new Isolation Environment policy and apply it to the new servers and all authorized hosts.
  • C. Create a new Application Security Policy restricting communication to the authorized hosts and apply it to the servers in enforce mode.
  • D. Create a new VLAN, create a subnet on the cluster with the VLAN tag, deploy servers with vNICs in the new subnet.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
JordansGhost
1 month ago
Selected Answer: B
I think the correct answer is actually B. Isolation policies allow you to protect all "prod" or "dev" or "security" tagged servers (category driven) isolating that entity from all other items, in this case unauthorised hosts. Application Security policies are more like traditional IP/port based rule sets. It would achieve the desired result, but its not as simple as isolating the environment, which is the question asked.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago