Free 3V0-42.20 Exam Braindumps (page: 4)

Page 4 of 15

An architect is helping an organization with the Logical Design of an NSX-T Data Center solution. This information was gathered during the Assessment Phase:
-NSX-T will span across two sites for disaster recovery.
-Public Load Balancer VIP should be accessible from a secondary site.
-Distributed Firewall Policies should be available at a secondary site.
-Routing capabilities should be maintained after failure.
-NAT capabilities are required.

Which two selections should the architect include in their design? (Choose two.)

  1. Use of the same ISPs across sites.
  2. Use two separate ISPs across sites.
  3. Use MTU to 1550 between sites.
  4. Set MTU to 1550 between sites.
  5. Use IP sets or groups to configure DFW rules.

Answer(s): A,E


Reference:

https://www.vmware.com/content/dam/digitalmarketing/vmware/en/pdf/products/nsx/vmware-multi-site-solutions-cross-vcenter-nsx-design-guide.pdf



An architect is helping an organization with the Conceptual Design of an NSX-T Data Center solution. Which risk is documented by an architect? (Choose the best answer.)

  1. The security team has a firewall communication matrix documented.
  2. The team is not trained for NSX-T but have a very strong experience with vSphere.
  3. Open communication between different application tiers is not allowed.
  4. Aggregate N-S throughput at any given time should be at least 10G.

Answer(s): B



An architect is helping an organization with the Logical Design of an NSX-T Data Center solution. This information was gathered during the Assessment Phase:

-Data between two networks connected over a public network needs to be encrypted.
-Certificate authentication is required.
-Dynamic route learning is preferred.

Which selection should the architect include in their design? (Choose the best answer.)

  1. Deploy a Tier-0 gateway in Active/Standby mode. Configure policy-based IPSec VPN with SHA512 with RSA as the hash algorithm.
  2. Deploy a Tier-0 gateway in Active/Active mode. Configure route-based IPSec VPN with SHA512 with RSA as the hash algorithm.
  3. Deploy a Tier-0 gateway in Active/Standby mode. Configure route-based IPSec VPN with SHA512 with RSA as the hash algorithm.
  4. Deploy a Tier-0 gateway in Active/Active mode. Configure policy-based IPSec VPN with SHA512 with RSA as the hash algorithm.

Answer(s): C



An architect is helping an organization with the Physical Design of an NSX-T Data Center solution. This information was gathered during a workshop:
-Migrating existing data center to KVM hosts.
-Redundancy and high availability are required.
-No component can be a single point of failure.

Which selection should the architect recommend? (Choose the best answer.)

  1. Linux Bridge redundancy with Active/Active Mode and multiple pNICs with necessary binding
  2. Linux Bridge redundancy with Active/Active Mode and single pNIC with static binding
  3. vSS/vDS in Active/Standby Mode with necessary binding
  4. vSS/vDS in Active/Active Mode with necessary pNICS and required binding modes

Answer(s): C



Page 4 of 15



Post your Comments and Discuss VMware 3V0-42.20 exam with other Community members:

vp commented on November 14, 2023
C is the answer
Anonymous
upvote