Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Nutanix NCP-NS Exam - Topic 1 Question 12 Discussion

An administrator recently deployed a new set of virtual machines... 3-tier web application... restricted as follows:Only application VMs can talk to database VMs on port 3306Frontend VMs should only communicate with application VMs on port 8080Which action will correctly create and configure the Security Policies in Nutanix Flow to satisfy this task?
D) Create categories for each tier then define an Application Policy allowing specific ports between them.
A) Create VLANs for each tier and configure ACLs to restrict communication.
B) Create IP-based rules for each VM category within a Security Policy.
C) Configure a global 'Allow All' Security Policy and rely on guest OS firewalls for tier-based restrictions.

Nutanix NCP-NS Exam - Topic 1 Question 12 Discussion

Actual exam question for Nutanix's NCP-NS exam
Question #: 12
Topic #: 1
[All NCP-NS Questions]

An administrator recently deployed a new set of virtual machines... 3-tier web application... restricted as follows:

Only application VMs can talk to database VMs on port 3306

Frontend VMs should only communicate with application VMs on port 8080

Which action will correctly create and configure the Security Policies in Nutanix Flow to satisfy this task?

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

0/2000 characters
Goldie
3 days ago
Isn't it surprising how many people overlook security policies in setups like this?
upvoted 0 times
...
Bobbye
8 days ago
VLANs could work, but I prefer the clarity of option D.
upvoted 0 times
...
Alethea
14 days ago
Wait, option C? Relying on guest OS firewalls? That seems risky.
upvoted 0 times
...
Princess
19 days ago
Definitely agree with option D, sounds like the right approach!
upvoted 0 times
...
Yaeko
24 days ago
I think option B makes the most sense for IP-based rules.
upvoted 0 times
...
Ma
29 days ago
I definitely remember that allowing all traffic globally isn't secure, so C seems wrong. D sounds like it could be the right way to go.
upvoted 0 times
...
Sheridan
1 month ago
I feel like using VLANs and ACLs could work, but I don't recall if that approach is necessary for this scenario.
upvoted 0 times
...
Tommy
1 month ago
I practiced a similar question where IP-based rules were emphasized, so B might be the right answer here.
upvoted 0 times
...
Billy
1 month ago
I think I remember that creating categories for each tier is important, but I'm not sure if D is the best choice.
upvoted 0 times
...

Save Cancel