試験3V0-21.25 トピック3 問題46 スレッド
VMware 3V0-21.25のリアル試験問題集
問題 #: 46
トピック #: 3
問題 #: 46
トピック #: 3
A design requirement for a new VCF 9.0 deployment specifies that all tenant network traffic must be inspected by a centralized firewall appliance located in a "Security" VPC before reaching the internet.
Which NSX VPC feature should be used to support this "Service Chaining" requirement?
Which NSX VPC feature should be used to support this "Service Chaining" requirement?
おすすめの解答:B 解答を投票する
To support centralized security inspection or "Service Chaining" in VCF 9.0, administrators leverage the routing flexibility of the NSX VPC. By configuring Static Routes within the tenant VPC, the administrator can override the default system-generated path to the internet. Specifically, the "0.0.0.0/0" (Default Route) can be pointed to the Interface IP of a security appliance or a load balancer residing within a shared or dedicated Security VPC. This forces all egress traffic from the application VPC to transit through the security layer for deep packet inspection or logging before the Transit Gateway forwards it to the external network.
While the Distributed Firewall (Option C) provides micro-segmentation, it does not redirect traffic to external appliances; only custom routing logic-managed through the VPC's routing table-can satisfy the requirement for centralized service insertion in a multi-VPC regional design.
While the Distributed Firewall (Option C) provides micro-segmentation, it does not redirect traffic to external appliances; only custom routing logic-managed through the VPC's routing table-can satisfy the requirement for centralized service insertion in a multi-VPC regional design.
秋元** 2026-07-21 03:35:52
コメント
他人の解答コメントを賛成するのも、その解答に一票を入れることになります。したがって、すでに同じ意見の投票コメントが存在する場合、新規コメントをする代わりに賛成することもできます。
コメントを通報する
コメント中
今すぐ 新規登録 / ログイン (無料です)。