Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dcdisc65

Page: 1 / 3
Total 21 questions
Exam Code: 5V0-41.21                Update: Oct 15, 2025
Exam Name: VMware NSX-T Data Center 3.1 Security

VMware VMware NSX-T Data Center 3.1 Security 5V0-41.21 Exam Dumps: Updated Questions & Answers (October 2025)

Question # 1

Which two are requirements for URL Analysis? (Choose two.)

A.

The ESXi hosts require access to the Internet to download category and reputation definitions.

B.

A layer 7 gateway firewall rule must be configured on the tier-0 gateway uplink to capture DNS traffic.

C.

A layer 7 gateway firewall rule must be configured on the tier-1 gateway uplink to capture DNS traffic,

D.

The NSX Edge nodes require access to the Internet to download category and reputation definitions.

E.

The NSX Manager requires access to the Internet to download category and reputation definitions.

Question # 2

Which of the following describes the main concept of Zero-Trust Networks for network connected devices?

A.

Network connected devices should only be trusted if they are issued by the organization.

B.

Network connected devices should only be trusted if the user can be successfully authenticated.

C.

Network connected devices should only be trusted if their identity and integrity can be verified continually.

D.

Network connected devices should only be trusted if they are within the organizational boundary.

Question # 3

Reference the CLI output.

What is the source IP address in the distributed firewall rule to accept HTTP traffic?

A.

172.16.30.11

B.

172.16.10.12

C.

172.16.10.11

D.

172.16.20.11

Question # 4

A security administrator is required to protect East-West virtual machine traffic with the NSX Distributed Firewall. What must be completed with the virtual machine's vNIC before applying the rules?

A.

It is connected to the underlay.

B.

It must be connected to a vSphere Standard Switch.

C.

It is connected to an NSX managed segment.

D.

It is connected to a transport zone.

Question # 5

As part of an audit, an administrator is required to demonstrate that measures have been taken to prevent critical vulnerabilities from being exploited. Which Distributed IDS/IPS event filter can the administrator show as proof?

A.

Attack Type

B.

CVSS

C.

CVE

D.

Signature ID

Question # 6

What component in a transport node receives the firewall configuration from the central control plane?

A.

nsx-ccp

B.

nsx-appl-proxy

C.

nsx-mpa

D.

nsx-proxy

Question # 7

Which is the port number used by transport nodes to export firewall statistics to NSX Manager?

A.

1235

B.

4789

C.

6081

D.

1234

Question # 8

An NSX administrator has been tasked with deploying a NSX Edge Virtual machine through an ISO image.

Which virtual network interface card (vNIC) type must be selected while creating the NSX Edge VM allow participation in overlay and VLAN transport zones?

A.

e1000

B.

VMXNET2

C.

VMXNET3

D.

Flexible

Question # 9

At which two intervals are NSX-T IDS/IPS updates through VMware's cloud based internet service provided for threat signature files? (Choose two.)

A.

weekly periodic updates

B.

off-schedule for 0-day updates

C.

monthly periodic updates

D.

daily periodic updates

E.

bi-weekly periodic updates

Question # 10

Which is an insertion point for East-West service insertion?

A.

tier-1 gateway

B.

Partner SVM

C.

Guest VM vNlC

D.

transport node

Page: 1 / 3
Total 21 questions

Most Popular Certification Exams

Payment

       

Contact us

dumpscollection live chat

Site Secure

mcafee secure

TESTED 16 Oct 2025