Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
A Solutions Architect is helping an organization with the multi-location design of an NSX solution.
This information was gathered during a design workshop:
No Jumbo Frames allowed on the WAN
Simple DR solution with no fabric nor vCenter requirements
GDPR requirements (Management Plane distributed in each location)
What should the architect recommend be configured in the NSX environment?
NSX Multisite for Compliance & Distributed Management (Correct Answer - B):
NSX Multisite supports deployments without requiring centralized management (NSX Federation).
Since GDPR requires data locality, separate NSX Managers per site help comply with data protection laws.
No Jumbo Frames requirement indicates transport overlays are not required, making Multisite a better fit than NSX Federation.
Incorrect Options:
(A - NSX Federation):
Federation requires Global Manager, which is not needed for a simple DR solution.
(C - Active/Active Tier-0 Gateway):
Active/Active Tier-0 is a routing decision, not a multi-location design strategy.
(D - IPSec VPN):
IPSec VPN is not sufficient for multi-site management.
VMware NSX 4.x Reference:
NSX Multisite vs. Federation Architecture Guide
GDPR Compliance with NSX Multisite Best Practices
A Solutions Architect has been tasked with designing a comprehensive security policy methodology for a large financial institution. The institution has multiple departments and requires strict segregation of network traffic to ensure data confidentiality and regulatory compliance. The security policy should provide granular control over network traffic and enforce consistent security measures across the entire infrastructure.
Which feature of the NSX security policy should the architect recommend to achieve regulatory compliance for the financial institution?
Micro-Segmentation for Granular Security (Correct Answer - C):
Micro-segmentation in NSX-T enables granular firewall policies at the workload level, ensuring strict segregation of traffic across different departments.
It allows zero trust security, ensuring only authorized communications occur between workloads, reducing attack surfaces.
This is particularly critical for financial institutions that need regulatory compliance (e.g., PCI-DSS, GDPR, ISO 27001).
Incorrect Options:
(A - Intrusion Detection & Prevention - IDS/IPS):
IDS/IPS provides threat detection, but it does not segment workloads or enforce access control.
(B - Identity-Based Firewalling):
NSX Identity Firewall (IDFW) can be useful for user-based policies but is not a replacement for network segmentation.
(D - Network Introspection):
NSX Network Introspection is used for third-party security integrations, not as a primary segmentation strategy.
VMware NSX 4.x Reference:
VMware NSX-T Security Reference Guide
Micro-Segmentation Best Practices in NSX-T
A global bank has decided to overhaul its network infrastructure and adopt VMware NSX to enhance security and streamline management. The bank handles sensitive financial data and has a massive customer base, making it a potential target for cyber threats. Therefore, security is of paramount importance in this project.
A Network Solutions Architect is tasked with developing an NSX security design that incorporates security policy methodologies and adheres to NSX security best practices. They must ensure the micro-segmentation of network components, implement distributed firewalling, and create security policies that align with the bank's data protection requirements.
When considering NSX security VMware practices for the bank's deployment, what aspect is essential for enhancing the security posture?
Implementing a Zero Trust Model at the Workload Level (Correct Answer C):
Micro-segmentation and NSX Distributed Firewall (DFW) allow enforcement of security policies at the workload level.
This ensures that even if one workload is compromised, lateral movement is restricted.
Incorrect Options:
(A - Avoiding Distributed Firewalls) This contradicts NSX best practices. DFW is a core security feature that minimizes attack surfaces.
(B - Gateway-Level Security Only) A gateway firewall alone cannot enforce granular micro-segmentation.
(D - Single Large Segment) This increases the blast radius and is against Zero Trust principles.
VMware NSX 4.x Reference:
VMware NSX-T Security Reference Guide
Zero Trust Security Model in NSX-T
How can a multi-tier architecture benefit a customer's design?
Multi-Tier Architecture & Stateful Services (Correct Answer - A):
In NSX-T, a multi-tier architecture consists of Tier-0 (T0) and Tier-1 (T1) Gateways, allowing better control and placement of stateful services such as:
Load Balancers (LBs)
NAT (Network Address Translation)
Firewall Rules (DFW, Gateway FW)
VPN Services
Tier-1 Gateways can be configured to handle stateful services, while Tier-0 Gateways focus on routing North-South traffic efficiently.
Incorrect Options:
(B - Cost-Effective for Simple Networks):
Multi-tier architecture is not necessarily cost-effective for simple networks. Instead, a single-tier deployment might be more suitable.
(C - Simplifies Network Topology by Consolidation):
Multi-tier segregates services rather than consolidating them. It separates East-West and North-South traffic flows for better performance.
(D - Eliminates the Need for EVPN):
Ethernet VPN (EVPN) is a control plane solution for VXLAN overlay networks, mainly used in multi-site or multi-data center deployments. It is independent of the multi-tier architecture.
VMware NSX 4.x Reference:
VMware NSX-T Multi-Tier Design Guide
NSX-T Data Center Routing and Gateway Configuration Best Practices
A large multinational company is expanding its data center due to increased demand for online services.
The company is considering shifting from an NSX Edge VM design to a bare-metal NSX Edge design to accommodate new hardware acquisitions and maximize performance.
Which is a potential benefit for the company in shifting from an NSX Edge VM design to a bare-metal NSX Edge design?
Performance Benefits of Bare-Metal NSX Edge (Correct Answer - A):
Bare-metal NSX Edge Nodes provide higher performance by eliminating the virtualization overhead associated with Edge VMs running inside ESXi/KVM hosts.
This increases throughput and reduces latency, making it ideal for high-bandwidth applications (e.g., Load Balancing, VPN, and NAT).
Incorrect Options:
(B - More VLANs):
The number of VLANs is not limited by the NSX Edge type. VLAN scalability depends on physical network design.
(C - Automatic Stateful Service Distribution):
Stateful services (NAT, FW, LB, VPN) do not auto-distribute. Stateful HA must be manually configured.
(D - Eliminates Stateful Services):
Stateful services (e.g., NAT, Load Balancer, Firewall) are still required, regardless of Edge deployment mode.
VMware NSX 4.x Reference:
VMware NSX-T Bare-Metal Edge Deployment Guide
NSX-T Edge Node Performance Optimization
A financial institution is looking to improve their existing virtual environment with a focus on increasing security to protect sensitive dat
a. The firm has a single data center and is concerned about lateral movement of threats within the network. They are particularly interested in utilizing VMware NSX to implement segmentation and adopt a Zero Trust security model.
Which of the following would be part of the optimal recommended design, utilizing a firewall?
NSX Distributed Firewall for Zero Trust Security (Correct Answer - B):
NSX Distributed Firewall (DFW) provides micro-segmentation at the vNIC level to enforce Zero Trust policies.
Each application runs on its own NSX Overlay Network, preventing lateral movement of threats.
Application-specific segmentation ensures granular control and compliance with regulatory standards (PCI-DSS, GDPR).
Incorrect Options:
(A - Gateway Firewall on Overlay Networks):
The Gateway Firewall controls North-South traffic, but DFW is required for East-West security.
(C & D - VLAN-Backed Networks Instead of Overlays):
VLANs are limited in scalability compared to overlay networks, reducing segmentation flexibility.
VMware NSX 4.x Reference:
NSX-T Distributed Firewall and Micro-Segmentation Guide
Zero Trust Security Model Implementation in NSX
Exam domains verified against: Official VMware 3V0-42.23 exam guide, last checked October 2026.
This section contains no testable objectives for this exam.
Recognize main NSX architecture elements including management clusters, management plane, control plane, and data plane components. Understand NSX Manager sizing options and cluster design decisions including enterprise versus service provider deployment models.
Sample question from this domain above: Q4
Apply design frameworks and project methodologies to create conceptual, logical, and physical designs for NSX deployments. Evaluate customer requirements and constraints to design NSX Edge clusters, logical switching, logical routing, security policies, network services, physical infrastructure, and multi-location Federation architectures.
This section contains no testable objectives for this exam.
This section contains no testable objectives for this exam.
Common questions about the exam itself