Identify two requirements for deploying an NSX Virtual Routing and Forwarding (VRF) gateway with BGP. (Choose two.)
Answer : BE
The administrator must configure Border Gateway Protocol (BGP) on the Tier-0 Gateway to establish neighbor relationships with upstream routers.
Which two statements describe the Border Gateway Routing Protocol (BGP) configuration on a Tier-0 Gateway? (Choose two.)
Answer : AB
An administrator is tasked to configure NSX Federation between separate VMware Cloud Foundation (VCF) Fleets.
Which requirement must all sites meet before being added to a Global Manager (GM) for NSX Federation?
Answer : C
DRAG DROP -
An administrator is attempting to confirm the successful transmission between an internal VM to an external destination.
An ICMP request packet is being sent from Sa-transit-web-01 to the Student Desktop in the diagram.
Drag and Drop the commands output into their appropriate originating NSX object.
Answer :
An administrator has been tasked with providing a networking solution including a Source and Destination NAT for a single Tenant.
The tenant is using Centralized Connectivity with a Tier-0 Gateway named Ten-A-Tier-0 supported by an Edge cluster in Active Active mode. The NAT solution must be available for multiple subnets within the Tenant space. The administrator chooses to deploy a Tier-1 Gateway to implement the NAT solution.
How would the administrator complete the task?
Answer : D
An administrator notices that BGP is established, but no routes are advertised from the VPC Transit Gateway to the router. The administrator runs this command: get logical-router <SR-tier0-gw-> route bgp and observed there are 0 routes being advertised.
What must the administrator do to get routes to be advertised?
Answer : C
An administrator is troubleshooting BGP flapping in an VMware Cloud Foundation 9 environment. A Tier-0 Gateway is running in Active/Active mode with two Edge nodes. BFD is enabled on the eBGP sessions to the upstream routers. Each Edge node uses its own uplink IP for BGP. After some network maintenance, one BGP session starts flapping every few minutes. The other BGP sessions stay stable.
On the affected Edge node, the command get bfd-sessions shows:
State: Down -
Diag: Detect Time Expired -
Symptoms:
The upstream router also shows the BFD session as Down with Control Detection Time Expired.
There are no interface errors, no packet loss for normal traffic, and clearing the BFD session temporarily brings it back up - but it flaps again after few minutes.
What is the root cause?
Answer : D
An administrator is upgrading an existing VMware Cloud Foundation (VPC) environment. An NSX Edge Cluster is required to support north-south traffic for a workload domain.
How would the administrator initiate the edge cluster deployment?
Answer : A
A sovereign cloud provider has a VMware Cloud Foundation (VCF) stretched Workload Domain across two data centers (AZ1 and AZ2), where site connectivity via layer-3 is provided by the underlay.
The following NSX details are included in the design:
Each site must host its own local NSX Edge Cluster for availability zones.
Tier-0 gateways must be configured in active/active mode with BGP ECMP to local top of rack switches.
Inter-site Edge TEP traffic must not cross the inter-DC link.
SDDC Manager is used to automate NSX deployment.
During deployment of the Edge Cluster for AZ2, the SDDC Manager workflow fails because the Edge transport nodes TEP IPs are not reachable from the ESX transport nodes.
Which step ensures correct Edge Cluster deployment in multi-site stretched domains?
Answer : D
An administrator has a VMware Cloud Foundation (VCF) instance. A critical NSX security update has been released by Broadcom.
How can the administrator install the NSX update?
Answer : B
An administrator is investigating packet loss reported by workloads connected to VXLAN segments in an NSX environment. Initial checks confirm: that all VMs are powered on
VXLAN Segments IDs are consistent across transport nodes, and visible to all hosts physical switch configurations are correct.
Which two NSX tools can be used to troubleshoot packet loss on VXLAN Segments? (Choose two.)
Answer : CD
An administrator changed the SFTP server used for scheduled NSX Manager backups. The backup jobs now fail with the error Host KEY Verification Failed. The connectivity and credentials are correct.
How would an administrator resolve the error?
Answer : A
An administrator is troubleshooting BGP connectivity issue on a Tier-0 Gateway (Active/Active).
The Tier-0 has the following configuration:
Uplink VLAN 2711 → 172.25.100.0/24
Uplink VLAN 2712 → 172.25.101.0/24
BGP neighbors configured: 172.25.100.1 and 172.25.101.1
A single static default route (0.0.0.0/0) exists with next-hop 172.25.100.1
Symptoms observed on both Edge Nodes:
Get BGP neighbors → both neighbors stuck in Idle (Connect) – "No route to peer"
Ping to 172.25.100.1 and 172.25.101.1 succeeds from the Edge nodes
Get route shows the default route present only on VLAN 2712 interface (fp-eth1), missing on VLAN 2711 (fp-eth0)
What is the root cause of both BGP sessions remaining in Idle state?
Answer : B
HOTSPOT -
The network team has decided to use a single Edge Cluster to provide Tier-0 A/ A Gateway routing and Tier-1 Gateway A/S services.
The active Tier-1 with a Gateway Firewall service is on EN2.
Which highlighted options will show the ECMP paths used by that Tier-1 GFW?
Answer :
An administrator is onboarding a secondary site Local Manager to the Global Manager (GM). The site has existing tier-0 and tier-1 gateways configured locally. The GM prompts you to import these objects.
What happens when you import these local networking objects into Federation?
Answer : B
Have any questions or issues ? Please dont hesitate to contact us