Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

VMware 6V0-21.25 Exam - Topic 9 Question 9 Discussion

What of the following is true regarding Distributed Firewall logging?
D) Logging can be enabled on per rule basis
A) Broadcom recommends logging all the DFW rules, as it does not have any CPU overhead
B) VMware Cloud Foundation logging tools are the only supported remote log server supported
C) The Firewall logs are first sent to the management plane to sanitize any Personally Identifiable Information

VMware 6V0-21.25 Exam - Topic 9 Question 9 Discussion

Actual exam question for VMware's 6V0-21.25 exam
Question #: 9
Topic #: 9
[All 6V0-21.25 Questions]

What of the following is true regarding Distributed Firewall logging?

Show Suggested Answer Hide Answer
Suggested Answer: D

Logging is critical for security operations and compliance, but it must be managed carefully. In vDefend, logging is exceptionally granular: it is enabled on a strict per-rule basis.

Why Option D is true and Option A is false: If an administrator enabled logging globally for every single rule (including high-volume infrastructure traffic like DNS or basic allowed web traffic), the ESXi hosts would generate a massive flood of syslog traffic. This causes significant CPU overhead, network congestion, and fills up log server storage rapidly. Best practice is to only enable logging on 'Drop/Deny' rules, or on specific 'Allow' rules governing highly critical applications.

(Option B is false because standard syslog protocols are used, supporting third-party tools like Splunk or QRadar. Option C is false because the ESXi host sends syslogs directly to the logging server; hair-pinning logs through the Management Plane would cause an architecture bottleneck).


Contribute your Thoughts:

0/2000 characters
Cherelle
3 days ago
A sounds good too, but I doubt no CPU overhead.
upvoted 0 times
...
Mila
9 days ago
I agree, D seems practical. Easier to manage.
upvoted 0 times
...
Jenise
14 days ago
I think D is true. Logging per rule makes sense.
upvoted 0 times
...
Reita
19 days ago
Logging all rules sounds like it could slow things down, not sure about that.
upvoted 0 times
...
Ty
24 days ago
I think the logs do get sanitized first, right?
upvoted 0 times
...
Ryann
29 days ago
Wait, are VMware tools really the only option?
upvoted 0 times
...
Laurena
1 month ago
Totally agree, logging per rule is super useful!
upvoted 0 times
...
Lizbeth
1 month ago
I heard Broadcom suggests logging all DFW rules.
upvoted 0 times
...
Lawrence
1 month ago
I definitely remember that logging can be configured per rule, so I'm leaning towards option D being the right answer.
upvoted 0 times
...
Tesha
2 months ago
I feel like we covered something about the management plane sanitizing logs, so option C might be a possibility, but I can't recall the details.
upvoted 0 times
...
Tuyet
2 months ago
I'm not entirely sure, but I remember something about Broadcom and logging recommendations; maybe option A is correct?
upvoted 0 times
...
Geraldo
2 months ago
I think option D sounds familiar since we discussed enabling logging on specific rules during our practice sessions.
upvoted 0 times
...

Save Cancel