Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

VMware 6V0-21.25 Exam - Topic 9 Question 9 Discussion

What of the following is true regarding Distributed Firewall logging?
D) Logging can be enabled on per rule basis
A) Broadcom recommends logging all the DFW rules, as it does not have any CPU overhead
B) VMware Cloud Foundation logging tools are the only supported remote log server supported
C) The Firewall logs are first sent to the management plane to sanitize any Personally Identifiable Information

VMware 6V0-21.25 Exam - Topic 9 Question 9 Discussion

Actual exam question for VMware's 6V0-21.25 exam
Question #: 9
Topic #: 9
[All 6V0-21.25 Questions]

What of the following is true regarding Distributed Firewall logging?

Show Suggested Answer Hide Answer
Suggested Answer: D

Logging is critical for security operations and compliance, but it must be managed carefully. In vDefend, logging is exceptionally granular: it is enabled on a strict per-rule basis.

Why Option D is true and Option A is false: If an administrator enabled logging globally for every single rule (including high-volume infrastructure traffic like DNS or basic allowed web traffic), the ESXi hosts would generate a massive flood of syslog traffic. This causes significant CPU overhead, network congestion, and fills up log server storage rapidly. Best practice is to only enable logging on 'Drop/Deny' rules, or on specific 'Allow' rules governing highly critical applications.

(Option B is false because standard syslog protocols are used, supporting third-party tools like Splunk or QRadar. Option C is false because the ESXi host sends syslogs directly to the logging server; hair-pinning logs through the Management Plane would cause an architecture bottleneck).


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel