Question 1 of 30
In a data center environment utilizing VMware NSX, a network engineer is tasked with designing a multi-tier application architecture that requires secure communication between the web, application, and database tiers. The engineer decides to implement micro-segmentation to enhance security. Given the following requirements: the web tier must communicate with the application tier over HTTP and HTTPS, the application tier must communicate with the database tier over a custom TCP port, and all other traffic should be denied. Which of the following configurations best achieves this while ensuring that the security policies are efficiently managed and applied?
Create security groups for each tier, define the necessary rules for inter-tier communication, and apply these rules using NSX Distributed Firewall (DFW) policies.
Implement a single security group for all tiers and allow all traffic between them, then apply a blanket deny rule for external traffic.
Use NSX Edge Services Gateway to manage traffic between tiers and apply security policies at the edge, allowing only specific protocols.
Configure VLANs for each tier and rely on traditional firewall rules to manage inter-tier communication.

Preparing for CISCO 300-630 Implementing Cisco Application Centric Infrastructure - Advanced (DCACIA)? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free