Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

VMware 6V0-21.25 Exam - Topic 7 Question 2 Discussion

Which of the following make up the Network Detection and Response capabilities of VMware vDefend? (Select all that apply)
A) Malware events and B) Threat detection events and C) Anomaly events
D) Encryption/Decryption events

VMware 6V0-21.25 Exam - Topic 7 Question 2 Discussion

Actual exam question for VMware's 6V0-21.25 exam
Question #: 2
Topic #: 7
[All 6V0-21.25 Questions]

Which of the following make up the Network Detection and Response capabilities of VMware vDefend? (Select all that apply)

Show Suggested Answer Hide Answer
Suggested Answer: A, B, C

VMware vDefend NDR relies on a diverse set of telemetry to build a comprehensive picture of an attack campaign. Its core correlation capabilities are built by ingesting three specific types of security events from the distributed data center:

Anomaly Events (Option C): Fed by the Network Traffic Analysis (NTA) engine, looking for behavioral deviations like DGA or unusual data exfiltration.

Threat Detection Events (Option B): Fed by the Intrusion Detection and Prevention Systems (IDS/IPS), looking for known exploit signatures traversing the network.

Malware Events (Option A): Fed by the Distributed and Gateway Malware Prevention engines, looking for malicious file transfers and sandbox detonations.

Encryption/Decryption events (Option D) are related to TLS Proxy/Inspection capabilities and do not constitute the foundational threat event categories ingested by the NDR correlation engine.


Contribute your Thoughts:

0/2000 characters
Roslyn
4 days ago
Agreed, D doesn't fit.
upvoted 0 times
...
Jess
9 days ago
D seems out of place.
upvoted 0 times
...
Dominga
14 days ago
Yeah, I feel like A is also relevant.
upvoted 0 times
...
Eura
19 days ago
I think it's B and C for sure.
upvoted 0 times
...
Burma
25 days ago
I agree, C makes sense for anomaly detection!
upvoted 0 times
...
Evette
30 days ago
Wait, are we sure about C? Seems off.
upvoted 0 times
...
Karl
1 month ago
Yup, A, B, and C are correct!
upvoted 0 times
...
Hana
1 month ago
I thought D was included too?
upvoted 0 times
...
Shantay
2 months ago
A, B, and C are definitely part of it.
upvoted 0 times
...
Argelia
2 months ago
I’m a bit confused about this one. I thought encryption/decryption was more related to data security than detection and response.
upvoted 0 times
...
Leoma
2 months ago
I practiced a similar question last week, and I think it was about the same capabilities. I’m leaning towards A, B, and C being correct.
upvoted 0 times
...
Jose
2 months ago
I feel like malware events and anomaly events were mentioned in the study materials, but I can't recall if encryption/decryption events are included.
upvoted 0 times
...
Chara
2 months ago
I think I remember that threat detection events are definitely part of vDefend's capabilities, but I'm not sure about the others.
upvoted 0 times
...
Orville
2 months ago
I’m leaning towards A, B, and C being correct, but I’m not confident about D. It seems more related to data security than detection.
upvoted 0 times
...
Vilma
4 months ago
I practiced a similar question last week, and I think B and C were included in that one too.
upvoted 0 times
...
Angelyn
4 months ago
I feel like threat detection events and anomaly events are both key components, but I can't recall if encryption/decryption events fit in there.
upvoted 0 times
...
Virgie
4 months ago
I think I remember that malware events are definitely part of it, but I'm not sure about the others.
upvoted 0 times
...

Save Cancel