Which option is VMware's best practice for the deployment of NSX Manager and NSX Controller components?
A. Deploy the NSX Manager and NSX Controller components to a management cluster.
B. Deploy the NSX Manager component to a management cluster and the NSX Controller components to a resource cluster.
C. Deploy the NSX Controller components to a management cluster and the NSX Manager component to a resource cluster.
D. Deploy the NSX Manager and NSX Controller components to a resource cluster.
Which two components are required to enable layer 2 bridging? (Choose two.)
A. Distributed firewall rule to allow layer 2 traffic in the bridge.
B. Deployed Logical Switch.
C. Deployed Logical Router.
D. VLAN trunk configured on logical switch.
A vSphere administrator deploys the NSX Edge Load Balancer in Inline mode. Which is not a requirement for the Load Balancer to operate correctly?
A. Perform Source NAT on the traffic from the clients.
B. Connect the Load Balancer directly to the same subnet as the VMs that are part of the Server Pool.
C. Perform Destination NAT on the traffic from the clients.
D. Point the virtual machines in the Server Pool to the Load Balancer as their default gateway.
A vSphere administrator deployed an NSX Edge Load Balancer in High Availability (HA) mode. What happens in the event the Load Balancer has a failure?
A. The secondary NSX Edge Load Balancer assumes the role of primary. Existing Flows will need to have their connections reestablished.
B. HA will start the NSX Edge Load Balancer on another ESXi host in the cluster. All existing flows will need to have their connections reestablished.
C. HA will start the NSX Edge Load Balancer on another ESXi host in the cluster. The NSX Controller caches existing flows and hands them to the Load Balancer when it is back up.
D. The secondary NSX Edge Load Balancer assumes the role of primary. The NSX Controller caches existing flows and hands them to the Load Balancer when it is back up.
Which two statements are true regarding Layer 2 VPNs? (Choose two.)
A. Layer 2 VPNs are used to securely extend Ethernet segments over an untrusted medium.
B. The NSX Edge Service Gateway can form a Layer 2 VPN with a standards-compliant physical appliance.
C. The Distributed Router can form a Layer 2 VPN to another Distributed Router or NSX Edge Service Gateway.
D. Layer 2 VPNs require the two VPN endpoints be in the same Layer 2 segment.
A company has augmented its Data Center infrastructure by using vCloud Hybrid Service during peak hours. The company wants to extend their existing subnets into the cloud while workloads retain their existing IP addresses. The virtual machines in these subnets use an NSX Edge Gateway as their default gateway.
Which solution should this company use?
A. Layer 2 VPN
B. MPLS VPN
C. IPSec VPN
D. SSL VPN
Which component automates the consumption of third-party services and provides mapping to virtual machines using a logical policy?
A. NSX Manager
B. Cloud Management Platform (CMP)
C. Service Composer
D. NSX Data Security
An administrator configures the IPSec VPN service on an NSX Edge instance, but the negotiation fails.
Examining the log file, the administrator notices the following message.
INVALID_ID_INFORMATION
Which misconfiguration caused the error?
A. Pre-shared key (PSK) does not match.
B. Diffie-Hellman (DH) Group does not match.
C. Perfect Forward Secrecy (PFS) does not match.
D. VPN tunnel address is incorrect.
What is the packet size of the VXLAN standard test packet when using the Ping test on the logical switches?
A. 1500
B. 1550
C. 1575
D. 1600
-- Exhibit -

-- Exhibit -An NSX administrator has deployed the network shown in the Exhibit.
Based on the exhibit, which statement describes a valid method for redirecting traffic around the fault?
A. Building this topology using a layer 2 switched fabric with connectivity between the leafs would allow traffic to be redirected around the fault to another leaf.
B. Building this topology using a layer 3 routed fabric with connectivity between the leafs would allow traffic to be redirected around the fault to another leaf.
C. Building this topology using a layer 2 switched fabric with spanning tree will provide the quickest path around the fault to another spine when connectivity is lost.
D. Building this topology using a layer 3 routed fabric will provide the quickest path around the fault to another spine when connectivity is lost.