2V0-641 VMware Certified Professional 6 – Network Virtualization Beta

Page 1   
Question 1

-- Exhibit --


-- Exhibit --
An NSX administrator creates the NSX network in the exhibit.
What destination IP address will Host-A use when sending a VXLAN frame to Host-B?

  • A. The IP address of one of Host-B's new vmkernel ports created during host configuration.
  • B. The IP address of Host-B's management vmkernel port, which is also the VTEP IP address.
  • C. The IP address of Host-B's NSX Controller. The NSX Controller forwards the VXLAN frame to Host-B.
  • D. The IP address Host-B provided to Host-A during VXLAN tunnel setup negotiations.


Answer : A

Question 2

-- Exhibit --


-- Exhibit --
An administrator has configured an NSX network as shown in the Exhibit.
Both VM-A and VM-B use the same Distributed Router for their default gateway.
Based on the exhibit, if VM-A sends a packet to VM-B,what happens to the packet before it
reaches VM-B?

  • A. Distributed Router in Host-A receives the packet from VM-A and forwards it to Logical Switch 7775 in Host-B, via a VXLAN frame, which delivers it to VM-B.
  • B. Logical Switch 7321 in Host-A receives the packet inside a frame from VM-A and forwards it to Logical Switch 7775 in Host-B, via a VXLAN frame, which delivers it to VM-B.
  • C. Distributed Router in Host-A receives the packet from VM-A and forwards it to Logical Switch 7321 in Host-B, via a VXLAN frame, which delivers it to Logical Switch 7775 before it is delivered to VM-B.
  • D. Logical Switch 7321 in Host-A receives the packet from VM-A and forwards it to the Distributed Router in Host-B, which passes it along to Logical Switch 7775 in Host-B before it is delivered to VM-B.


Answer : A

Question 3

-- Exhibit --


-- Exhibit --
The Exhibit shows two possible physical network architectures. Each architecture provides
a means in dealing with the pictured failure.
Based on the exhibit, which architecture provides the highest degree of connectivity in the
event of the pictured failure?

  • A. Both designs will provide the same percentage of connectivty in times of failure.
  • B. Neither design is properly architected to work around the displayed failure.
  • C. Diagram A's architecture will provide the highest percentage of connectivity in times of failure.
  • D. Diagram B's architecture will provide the highest percentage of connectivity in times of failure.


Answer : D

Question 4

Which two options are valid SpoofGuard operational modes? (Choose two.)

  • A. Allow Local Address as Valid Address in This Namespace
  • B. Allow and Approve DHCP Requests Regardless of Enabled Mode
  • C. Automatically Trust IP Assignments on Their First Use
  • D. Manually Inspect and Approve All IP Assignments Before Use


Answer : C,D

Question 5

Which option is VMware's best practice for the deployment of NSX Manager and NSX
Controller components?

  • A. Deploy the NSX Manager and NSX Controller components to a management cluster.
  • B. Deploy the NSX Manager component to a management cluster and the NSX Controller components to a resource cluster.
  • C. Deploy the NSX Controller components to a management cluster and the NSX Manager component to a resource cluster.
  • D. Deploy the NSX Manager and NSX Controller components to a resource cluster.


Answer : A

Question 6

Which two actions take place when an active NSX Edge instance fails? (Choose two.)

  • A. Once the original NSX Edge instance is recovered, it preempts the other NSX Edge instance and takes over the active role.
  • B. The standby NSX Edge instance becomes the active instance and requests routing updates from the routing neighbors.
  • C. Once the original NSX Edge instance is recovered, the NSX Manager attempts to place it on a different host from the other NSX Edge instance.
  • D. The standby NSX Edge instance becomes the active instance and retains any routing neighbor adjacencies.


Answer : C,D

Question 7

What is the packet size of the VXLAN standard test packet when using the Ping test on the
logical switches?

  • A. 1500
  • B. 1550
  • C. 1575
  • D. 1600


Answer : B

Question 8

A vSphere administrator deploys the NSX Edge Load Balancer in Inline mode. Which is not
a requirement for the Load Balancer to operate correctly?

  • A. Perform Source NAT on the traffic from the clients.
  • B. Connect the Load Balancer directly to the same subnet as the VMs that are part of the Server Pool.
  • C. Perform Destination NAT on the traffic from the clients.
  • D. Point the virtual machines in the Server Pool to the Load Balancer as their default gateway.


Answer : A

Question 9

An administrator has deployed NSX in an environment containing a mix of vSphere 5
hosts. The implementation includes the Distributed Firewall Service, but the administrator
finds that rules are not being applied to all affected virtual machines.
What two conditions would cause this behavior? (Choose two.)

  • A. Some hosts have not been prepared for NSX.
  • B. Only ESXi 5.5 and later hosts can push the rules to the virtual machines.
  • C. Only ESXi 5.1 and later hosts can push the rules to the virtual machines.
  • D. Some hosts are blocking the port used for rule distribution.


Answer : A,C

Question 10

An administrator needs to perform a configuration backup of NSX. From which two
locations can this task be performed? (Choose two.)

  • A. Directly on the NSX Manager
  • B. From the vSphere Web Client
  • C. Using the NSX API
  • D. Directly on each NSX Controller


Answer : A,C

Question 11

A user needs to be given the ability to make configuration changes on a specific NSX Edge
device. What role and scope could be used to meet this requirement?

  • A. NSX Administrator role and Limit Access scope
  • B. Security Administrator role and Limit Access scope
  • C. NSX Administrator role and No restriction scope
  • D. Security Administrator role and No restriction scope


Answer : B

Question 12

-- Exhibit --


-- Exhibit --
An administrator configures an NSX network as shown in the Exhibit.
Both VM-A and VM-B use the same Distributed Router for their default gateway. VM-B
receives an IP message from VM-A.
Based on the exhibit, what is the source MAC address of the IP message received by VM-
B?

  • A. VM-B's default gateway's MAC address.
  • B. VM-A's MAC address.
  • C. VM-A's default gateway's MAC address.
  • D. Logical Switch 7321's MAC address


Answer : A

Question 13

Which two statements are true regarding Layer 2 VPNs? (Choose two.)

  • A. Layer 2 VPNs are used to securely extend Ethernet segments over an untrusted medium.
  • B. The NSX Edge Service Gateway can form a Layer 2 VPN with a standards-compliant physical appliance.
  • C. The Distributed Router can form a Layer 2 VPN to another Distributed Router or NSX Edge Service Gateway.
  • D. Layer 2 VPNs require the two VPN endpoints be in the same Layer 2 segment.


Answer : A,B

Question 14

Which is not a prerequisite to upgrade vCloud Network and Security Virtual Wires to
Logical Switches?

  • A. vCloud Network and Security Manager has been upgraded to NSX Manager.
  • B. vShield Data Security has been uninstalled.
  • C. NSX Controllers have been deployed.
  • D. The NSX Manager has been configured with the same IP as the vCloud Network and Security Manager.


Answer : C

Question 15

Which component provides for installation of NSX hypervisor kernel components and user
world agents?

  • A. NSX Controller
  • B. NSX Edge Virtual Appliance
  • C. NSX Manager
  • D. vRealize Automation


Answer : C

Page 1