Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

VMware 6V0-21.25 Exam - Topic 7 Question 2 Discussion

Which of the following make up the Network Detection and Response capabilities of VMware vDefend? (Select all that apply)
A) Malware events and B) Threat detection events and C) Anomaly events
D) Encryption/Decryption events

VMware 6V0-21.25 Exam - Topic 7 Question 2 Discussion

Actual exam question for VMware's 6V0-21.25 exam
Question #: 2
Topic #: 7
[All 6V0-21.25 Questions]

Which of the following make up the Network Detection and Response capabilities of VMware vDefend? (Select all that apply)

Show Suggested Answer Hide Answer
Suggested Answer: A, B, C

VMware vDefend NDR relies on a diverse set of telemetry to build a comprehensive picture of an attack campaign. Its core correlation capabilities are built by ingesting three specific types of security events from the distributed data center:

Anomaly Events (Option C): Fed by the Network Traffic Analysis (NTA) engine, looking for behavioral deviations like DGA or unusual data exfiltration.

Threat Detection Events (Option B): Fed by the Intrusion Detection and Prevention Systems (IDS/IPS), looking for known exploit signatures traversing the network.

Malware Events (Option A): Fed by the Distributed and Gateway Malware Prevention engines, looking for malicious file transfers and sandbox detonations.

Encryption/Decryption events (Option D) are related to TLS Proxy/Inspection capabilities and do not constitute the foundational threat event categories ingested by the NDR correlation engine.


Contribute your Thoughts:

0/2000 characters
I practiced a similar question last week, and I think it was about the same capabilities. I’m leaning towards A, B, and C being correct.
upvoted 0 times
...
Jose
5 days ago
I feel like malware events and anomaly events were mentioned in the study materials, but I can't recall if encryption/decryption events are included.
upvoted 0 times
...
Chara
10 days ago
I think I remember that threat detection events are definitely part of vDefend's capabilities, but I'm not sure about the others.
upvoted 0 times
...
Orville
15 days ago
I’m leaning towards A, B, and C being correct, but I’m not confident about D. It seems more related to data security than detection.
upvoted 0 times
...
Vilma
2 months ago
I practiced a similar question last week, and I think B and C were included in that one too.
upvoted 0 times
...
Angelyn
2 months ago
I feel like threat detection events and anomaly events are both key components, but I can't recall if encryption/decryption events fit in there.
upvoted 0 times
...
Virgie
2 months ago
I think I remember that malware events are definitely part of it, but I'm not sure about the others.
upvoted 0 times
...

Save Cancel