Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

VMware 6V0-21.25 VMware vDefend Security for VCF 5.x Administrator Exam Practice Test

Demo: 22 questions
Total 75 questions

VMware vDefend Security for VCF 5.x Administrator Questions and Answers

Question 1

Which of the following are maintained by the vDefend Distributed Firewall on a per vnic basis? (Select all that apply)

Options:

A.

Rule Table

B.

Flow Table

C.

Firewall Table

D.

IDPS Table

Question 2

Which of the following statements are true about Distributed Malware? (Select all that apply)

Options:

A.

Offers Detection

B.

Offers Detection and Prevention

C.

Supports Windows and Linux

D.

Sends events to NDR

E.

All of the above

Question 3

Which of the following are valid configuration options for a VMware vDefend Distributed Firewall Policy? (Select all that apply)

Options:

A.

TCP Strict

B.

Stateful

C.

Locked

D.

Open

Question 4

Which NSX authentication uses cookies for subsequent API calls instead of the username and password?

Options:

A.

HTTP Basic authentication

B.

Principal Identity authentication

C.

Certificate based authentication

D.

Session based authentication

Question 5

By default, vDefend Malware Detection and Prevention blocks which of the following file types?

Options:

A.

Benign File

B.

Corrupted File

C.

Malicious File

D.

Suspicious File

Question 6

Distributed IDS cannot be implemented on which of the following?

Options:

A.

Standard switch portgroup

B.

Distributed portgroup

C.

NSX backed VLAN segment

D.

NSX backed Overlay Segment

Question 7

Which of the following are valid Network Traffic Analysis detectors in vDefend ATP? (Select all that apply)

Options:

A.

DNS tunneling

B.

Unusual traffic pattern

C.

Password brute force

D.

Vertical port scan

Question 8

Which of the following are vDefend Advanced Threat Prevention capabilities? (Select all that apply)

Options:

A.

Intrusion Detection/Protection Systems (IDS/IPS)

B.

Network Traffic Analysis (NTA)

C.

Gateway Firewall

D.

Network Detection and Response (NDR)

E.

Malware Analysis/Sandboxing

Question 9

Which of the following components can enforce Layer 7 Context Firewall Rules? (Select all that apply)

Options:

A.

Distributed Firewall

B.

Tier 1 Gateway

C.

Tier 0 Gateway

D.

VMK Interface

Question 10

Which of the following VMware vDefend architecture components is responsible for providing API access?

Options:

A.

Management plane

B.

Control plane

C.

Data plane

D.

Orchestration plane

Question 11

Which vDefend Gateway Firewall feature is ONLY supported on T1 Gateways?

Options:

A.

Gateway IDRS

B.

Stateful Services on A/A Gateways

C.

Gateway IDFW

D.

L3/L4 Gateway Firewall

Question 12

What is a confidence score in regard to IDS/IPS scores?

Options:

A.

Numeric value indicating "badness" of a threat

B.

Combined Value of Risk Score and confidence score 0-100

C.

Confidence of the detection being accurate

D.

Confidence of the detection being inaccurate

Question 13

In vDefend Malware Detection and Prevention, when does local file analysis occur?

Options:

A.

After Cloud file analysis and before hash comparison

B.

Before Cloud file analysis and after hash comparison

C.

After Cloud file analysis and after hash comparison

D.

Before Cloud file analysis and before hash comparison

Question 14

For Distributed IDS/IPS to work, a Distributed firewall must be enabled.

Options:

A.

True

B.

False

Question 15

What layers of the OSI model does the vDefend Firewall provide protection?

Options:

A.

L1 - L4

B.

L2 - L7

C.

L3 - L5

D.

L4 - L6

Question 16

Which of these are NOT a grouping criteria when creating a dynamic group? (Select all that apply)

Options:

A.

IncludeAll

B.

ExcludeAll

C.

StartsWith

D.

Contains

Question 17

Which of the following is true regarding the VMware vDefend Distributed Firewall?

Options:

A.

VMware vDefend Distributed Firewall is a hypervisor-based software defined firewall solution

B.

VMware vDefend Distributed Firewall runs in the ESXi vSwitch

C.

VMware vDefend Distributed Firewall can be deployed as a virtual machine or on bare metal hardware

D.

VMware vDefend Distributed Firewall runs as an agent in a physical switch with open software development capabilities

Question 18

Which of the following make up the Network Detection and Response capabilities of VMware vDefend? (Select all that apply)

Options:

A.

Malware events

B.

Threat detection events

C.

Anomaly events

D.

Encryption/Decryption events

Question 19

Which of the following regular expressions can be used to define a custom FQDN or URL in the vDefend Firewall Context Profiles?

Options:

A.

*eng*.vmware.com

B.

eng*.vmware.com

C.

eng.*vmware.com

D.

*eng.vmware.com

Question 20

Which of the following is true regarding the capabilities of Antrea?

Options:

A.

To provide network connectivity between the Azure cloud and the On-Prem datacenter

B.

To provide pod connectivity and network policy enforcement with Open vSwitch in Kubernetes

C.

To provide pod connectivity and network policy enforcement with Nexus 1000v in AWS cloud

D.

To provide network connectivity between the AWS cloud and the on-Prem datacenter

Question 21

Which of the following are advantages of VMware vDefend versus using legacy security tools? (Select all that apply)

Options:

A.

No network changes are required to implement security policies

B.

Tapless network visibility

C.

Centralized Intrusion Detection and Intrusion Prevention

D.

IP/Subnet based policy creation

Question 22

Which of the following is NOT true regarding the Gateway IDS/IPS?

Options:

A.

Can be combined with Decryption policies

B.

Distributed IDS/IPS must be configured to utilize Gateway IDS/IPS

C.

Distributed IDS/IPS and Gateway IDS/IPS have same set of signatures

D.

Can be used to Detect/Prevent intrusions at network or Zone perimeter

Demo: 22 questions
Total 75 questions