01. Project Media already contains VPCs for two teams. A third group, the streaming unit, asks for its own network space. Its engineers must create and manage their own Tier-1 gateways, and its north-south traffic and the traffic between its own networks must run through a Transit Gateway that no other team uses. Media's Project Admin proposes a new VPC in Media instead of a new Project.
Which two requirements can a VPC inside Media NOT meet?
(Choose two.)
a) A Transit Gateway that carries only the streaming unit's traffic
b) Subnets that each form an independent Layer 2 broadcast domain
c) Engineers who create and manage the unit's own Tier-1 gateways
d) A routing domain that is independent of the other teams' networks
e) Engineers who add subnets themselves, without asking Media's Project Admin
02. Before a remote site is onboarded into an existing NSX Federation, the team reviews its readiness report. The site will not host any stretched segments.
NSX Manager: three nodes with a cluster VIP, one patch release behind the Global Manager
Global Manager to Local Manager path: crosses a firewall that applies source NAT
Round-trip latency to the Global Manager: within the documented limit for non-stretched networks
Default overlay transport zone: present
Which two corrections are required before the site is onboarded?
(Choose two.)
a) Bring the site's NSX Manager to the same version as the Global Manager
b) Expand the NSX Manager cluster to more than three nodes
c) Reduce the latency to the tighter limit that applies to stretched networks
d) Replace the default overlay transport zone with a site-specific one
e) Remove source NAT from the Global Manager to Local Manager path
03. Workloads on segments behind Tier-1 gateway T1-Dev must resolve names in corp.example.com through the internal DNS servers 10.0.0.53 and 10.0.1.53, and every other name through the organization's public resolvers. An NSX DNS forwarder attached to T1-Dev will be the workloads' only DNS server.
Which two zone configurations does the forwarder need?
(Choose two.)
a) An FQDN DNS zone for corp.example.com that lists the public resolvers
b) A default DNS zone that lists 10.0.0.53 and 10.0.1.53
c) A default DNS zone that lists the organization's public resolvers
d) A second FQDN zone that matches every other domain and lists the public resolvers
e) An FQDN DNS zone for corp.example.com that lists 10.0.0.53 and 10.0.1.53
04. Tier-0-Core was built greenfield as a stateful Active-Active gateway on Edge cluster EC-A, with an interface group for its uplinks. Two Tier-1 gateways that link to Tier-0-Core are now being created:
Tier-1-Scale will run in stateful Active-Active mode.
Tier-1-Legacy will run its services in Active Standby mode.
Where must each Tier-1 gateway be hosted?
a) Both on EC-A, alongside Tier-0-Core
b) Tier-1-Scale on a different Edge cluster, Tier-1-Legacy on EC-A
c) Tier-1-Scale on EC-A, Tier-1-Legacy on a different Edge cluster
d) Both on a second Edge cluster, keeping EC-A for Tier-0-Core alone
05. In VPC web-prod, inside Project Sales, a team lead must be able to add subnets for new application tiers. Security policy in the VPC is owned by a separate team, and the lead must not be able to change it.
Which role assignment meets the requirement?
a) Network Admin on the web-prod VPC
b) VPC Admin role on the web-prod VPC
c) Project Admin role on Project Sales
d) Network Operator on the web-prod VPC
06. An administrator has just created an overlay segment named web-prod in NSX. It is in the overlay transport zone used by a vSphere cluster whose hosts are already prepared as transport nodes on a VDS. A virtual machine in that cluster must now be connected to web-prod.
What is the next step?
a) Create a distributed port group named web-prod on the VDS in vCenter and connect the virtual machine to it
b) Select web-prod, which appears as a port group on the VDS, on the virtual machine's network adapter
c) Register the virtual machine's host with NSX Manager again so it learns about the new segment
d) Connect web-prod to a Tier-1 gateway so the segment is published to vCenter
07. Edge cluster EC-01 contains four NSX Edge VMs: two Medium and two Large. To raise north-south throughput, the team has racked two bare-metal servers that are ready to become NSX Edge transport nodes, and wants them carrying traffic this quarter.
How should the bare-metal Edge nodes be deployed?
a) Add both to EC-01 after resizing its four VMs to Large, so every member matches
b) Add each node to EC-01 and to a new cluster, so either cluster can place gateways on it
c) Add both to EC-01 beside the VMs, since mixed sizes already coexist there
d) Create a separate Edge cluster that contains only the two bare-metal nodes
08. Tier-0-Branch runs Active-Active with uplinks on two Edge nodes, EN-1 and EN-2, and BGP to the fabric. No NAT, VPN, DNS forwarder, HA VIP or service interface is configured on it. A new requirement adds a route-based IPSec VPN that terminates on this Tier-0, and the gateway and its router links to existing Tier-1 gateways must stay in place.
Which sequence delivers the VPN?
a) Configure the IPSec VPN first, then remove EN-2's uplinks and change the HA mode to Active Standby
b) Remove EN-2's uplinks, change the HA mode to Active Standby, add EN-2's uplinks back, then configure the VPN
c) Change the HA mode to Active Standby with both Edge nodes' uplinks in place, then configure the VPN
d) Configure the IPSec VPN on a new Distributed Only Tier-1 gateway linked to Tier-0-Branch
09. A small proof-of-concept environment will be added as a location to an NSX Federation for a three-month trial. Its NSX Manager runs as one node, and the team wants to avoid deploying more appliances for the trial. A reviewer points out that production locations run three NSX Manager nodes behind a cluster VIP.
What does the proof-of-concept location need before it is added?
a) Its single NSX Manager node, with a cluster VIP configured
b) Its single NSX Manager node, with no cluster VIP, since a VIP needs three nodes
c) Its single NSX Manager node, registered through the trial domain's vCenter
d) Two more NSX Manager nodes, since every location needs three
10. VPCs in a Project use a centralized external connection from the Project's Transit Gateway to a Tier-0 gateway that peers with two fabric routers over BGP. Packets from workloads on Public VPC subnets leave through the Tier-0, but the fabric routers hold no routes for those Public subnets, so no replies or inbound corporate sessions reach them. The Tier-0's route redistribution currently includes only its own connected interfaces and segments.
Which change restores reachability to the Public subnets from the corporate network?
a) Assign an External IP to each workload on the Public subnets
b) Enable advertisement of all connected segments and service ports on a Tier-1 linked to the Tier-0
c) Add Transit Gateway Static to the Tier-0 route redistribution so its BGP peers learn the VPC subnets
d) Enable Default Outbound NAT in the VPC connectivity profile