Where does an administrator configure the VLANs used In VRF Lite? (Choose two.)
A. segment connected to the Tler-1 gateway
B. uplink trunk segment
C. downlink interface of the default Tier-0 gateway
D. uplink Interface of the VRF gateway
E. uplink interface of the default Tier-0 gateway
Which two choices are use cases for Distributed Intrusion Detection? (Choose two.)
A. Use agentless antivirus with Guest Introspection.
B. Quarantine workloads based on vulnerabilities.
C. Identify risk and reputation of accessed websites.
D. Gain Insight about micro-segmentation traffic flows.
E. Identify security vulnerabilities in the workloads.
When collecting support bundles through NSX Manager, which files should be excluded for potentially containing sensitive information?
A. Controller Files
B. Management Files
C. Core Files
D. Audit Files
Which CLI command would an administrator use to allow syslog on an ESXi transport node when using the esxcli utility?
A. esxcli network firewall ruleset set-r syslog-e true
B. esxcli network firewall ruleset-e syslog
C. esxcli network firewall ruleset set-r syslog-e false
D. esxcli network firewall ruleset set-a-e false
The security administrator turns on logging for a firewall rule.
Where is the log stored on an ESXi transport node?
A. /var/log/vmware/nsx/firewall.log
B. /var/log/messages.log
C. /var/log/dfwpktlogs.log
D. /var/log/fw.log
An NSX administrator Is treating a NAT rule on a Tler-0 Gateway configured In active-standby high availability mode. Which two NAT rule types are supported for this configuration? (Choose two.)
A. Reflexive NAT
B. Destination NAT
C. 1:1 NAT
D. Port NAT
E. Source NAT
Which two statements are correct about East-West Malware Prevention? (Choose two.)
A. A SVM is deployed on every ESXi host.
B. NSX Application Platform must have Internet access.
C. An agent must be installed on every ESXi host.
D. An agent must be installed on every NSX Edge node.
E. NSX Edge nodes must have Internet access.
Refer to the exhibit.
An administrator would like to change the private IP address of the NAT VM I72.l6.101.il to a public address of 80.80.80.1 as the packets leave the NAT-Segment network.
Which type of NAT solution should be implemented to achieve this?

A. DNAT
B. SNAT
C. Reflexive NAT
D. NAT64
When a stateful service is enabled for the first lime on a Tier-0 Gateway, what happens on the NSX Edge node'
A. SR is instantiated and automatically connected with DR.
B. DR Is instantiated and automatically connected with SR.
C. SR and DR Is instantiated but requites manual connection.
D. SR and DR doesn't need to be connected to provide any stateful services.
Which field in a Tier-1 Gateway Firewall would be used to allow access for a collection of trustworthy web sites?
A. Source
B. Profiles-> Context Profiles
C. Destination
D. Profiles-> L7 Access Profile