Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 3V0-42.20 All Questions

View all questions & answers for the 3V0-42.20 exam

Exam 3V0-42.20 topic 1 question 26 discussion

Actual exam question from VMware's 3V0-42.20
Question #: 26
Topic #: 1
[All 3V0-42.20 Questions]

A customer has a requirement to implement a next generation firewall (NGFW) to improve security network introspection. The customer wants to apply the NGFW to all workloads exposed both internally and externally. The customer wants the NGFW to work seamlessly with NSX-T Data Center and vSphere.
Which solution should be recommended to the customer? (Choose the best answer.)

  • A. Use network introspection only on the external workloads and use NSX DFW for internal workloads.
  • B. Apply the NGFW on bare metal hosts which will offer better performance of inline network introspection.
  • C. Apply the NGFW to internal and external workloads for increased protection and use NSX-T Data Center with Federation to set network policies.
  • D. Use NSX-T Data Center leveraged with NSX Intelligence to protect all workloads at the network inspection level.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
BrianOC
Highly Voted 3 years, 6 months ago
D is the correct answer
upvoted 5 times
...
AT45816
Most Recent 9 months, 4 weeks ago
Selected Answer: C
Correct Answer: C
upvoted 1 times
...
outlawww
1 year, 8 months ago
Selected Answer: C
C is totally feasible and satisfy the requirements. You can manage the steering rules with federation.
upvoted 2 times
...
ertin74
2 years ago
Selected Answer: C
Only C applies the requirements
upvoted 1 times
...
Alchot
2 years, 2 months ago
A is correct. D is not correct. How NSX Intelligence will help protect external workloads when only works for overlay networks plus is not a security feature.
upvoted 1 times
...
ShyamC
2 years, 9 months ago
Selected Answer: A
I feel this shoud be A, with C you have no control over DFW policies on external workloads, however A addresses network introspection for External and DFW for internal workloads which NSX can do
upvoted 2 times
...
sergejszajbaver
2 years, 10 months ago
NSX Intelligence is not a protection tool. It just monitors flows and let's you click on DFW rules that it suggests based on that.
upvoted 2 times
...
nick2u
3 years ago
I will go with D if I ran into this question during exam. NSX Intelligence is designed to plan for firewall rules and for deployment.
upvoted 1 times
...
tedybear
3 years ago
C, Can't be A as they want to use NGFW both externally and internally, can't be B as that only covers NS, and especially can't be D, as does it not mention the NGFW. Federation can be a use case for integration with NGFW
upvoted 2 times
nick2u
3 years ago
How would Federation be used in this case?
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...