Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

VMware 6V0-21.25 Exam - Topic 8 Question 13 Discussion

Which of the following must be done in order to detect DNS anomalies with NTA? (Select all that apply)
C) Configure a L7 APPID DNS rule allow rule
A) Do nothing, it works out of the box
B) Configure a L4 TCP/UDP port 53 allow rule
D) Enable the DNS Tunneling and DGA detectors

VMware 6V0-21.25 Exam - Topic 8 Question 13 Discussion

Actual exam question for VMware's 6V0-21.25 exam
Question #: 13
Topic #: 8
[All 6V0-21.25 Questions]

Which of the following must be done in order to detect DNS anomalies with NTA? (Select all that apply)

Show Suggested Answer Hide Answer
Suggested Answer: C

Network Traffic Analysis (NTA) relies heavily on understanding the context and payload of network communications, not just the ports they use. If you simply create a standard Layer 4 firewall rule allowing TCP/UDP port 53 (Option B), the firewall will let the traffic pass without deep inspection.

To detect advanced DNS anomalies (like DNS Tunneling, where attackers hide data inside DNS queries, or DGA), the NTA engine must be able to read the actual DNS query strings. By configuring a Layer 7 APPID rule specifically for DNS (Option C), you force the vDefend architecture to send that traffic through the Deep Packet Inspection (DPI) engine. This DPI visibility is an absolute prerequisite for the NTA detectors to successfully analyze the DNS payload for malicious patterns.


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel