VCP-SEC practice questions
Broadcom · VCP-SEC · 300 questions
This practice test covers the VMware Certified Professional – Security (VCP-SEC) certification exam. Test your knowledge across all domains and topics outlined in the official exam guide.
This course contains the use of artificial intelligence.
About the VCP-SEC exam
This exam has been retired and can no longer be taken by new candidates. The questions below remain useful as subject-matter practice.
- Format
- Retired - no longer attainable by new candidates
Exam details published by the vendor, checked 25 August 2026. Vendors change fees and formats without notice — confirm on the vendor's own page before you book.
Practice Quizzes
Test your knowledge with standard 20-question practice sets.
Quiz 1
Quiz 2
Quiz 3
Quiz 4
Quiz 5
Quiz 6
Quiz 7
Quiz 8
Quiz 9
Quiz 10
Quiz 11
Quiz 12
Quiz 13
Quiz 14
Quiz 15
Browse by Domain
Study specific topics at your own pace.
Installing, Configuring, and Setup · 150 questions
- After a perimeter firewall change, city permitting portal administrators can no longer open the Workspace ONE UEM console from the civic jump network. Which change re-enables the console without weakening the edge?
- A county library kiosk VLAN must enroll devices in Workspace ONE UEM through AirWatch Cloud Connector but must not browse the open internet. Which firewall design meets both goals?
- A transit authority places Workspace ONE Access behind the civic DMZ. How should the security administrator enable the Access connector without exposing it to untrusted networks?
- Public-health clinic Windows laptops fail Intelligent Hub install after the edge starts denying certificate-revocation lookups and CDN fetches. What should the administrator change?
- Parks and recreation staff administer Workspace ONE UEM from a VDI jump box. Which administrative-access design is appropriate?
- A water utility must enroll corporate laptops in Workspace ONE while keeping SCADA historian hosts isolated. What firewall stance should the security administrator take?
- Court records staff need Workspace ONE Tunnel so a case-management app can reach the records VLAN. Which component-firewall approach is correct?
- A school-district AirWatch Cloud Connector can no longer bind to Active Directory after a new host firewall is applied. Which rule restores directory integration securely?
- City 911 CAD workstations need Intelligent Hub, and the SOC still wants Workspace ONE traffic logged. What should the administrator do after the perimeter change?
- A housing-authority Secure Email Gateway for Workspace ONE must accept ActiveSync only from enrolled devices. How should the administrator enable that path?
- An elections office publishes a citizen-facing website on the same DMZ as Workspace ONE Access. How should the security administrator place Access and the UEM API?
- City Finance laptops need stricter Carbon Black Cloud prevention than Parks laptops. Which configuration applies the right control to each population?
- New library staff PCs check into Carbon Black Cloud but match no sensor-group criteria. What policy assignment should the administrator expect?
- A county assessor line-of-business tax application is terminated by Carbon Black Cloud. What is the correct policy change?
- Public-works rugged tablets run a GPS tool that Carbon Black Cloud still blocks after an event-reporting exclusion is added. Which change actually lets the tool run?
- A utilities SOC must block USB mass storage on plant-floor PCs and allow it on helpdesk PCs. How should that be enforced in Carbon Black Cloud?
- Courts want ransomware-like behavior set to Terminate, while clerks' machines stay at Alert for a week. What should the administrator configure?
- The city has a SHA-256 hash for a known-good permitting installer that Carbon Black Cloud currently treats as unknown. Where should the administrator record it so the installer can run?
- Transit bus-yard kiosks must not run unknown binaries. Which Carbon Black Cloud control meets that intent?
- After school-district lab PCs are added to a new Carbon Black Cloud sensor group, they keep the old policy. What should the administrator inspect first?
- Public-health non-persistent VDI desktops need Carbon Black Cloud protection and must still launch the published EHR client. What is the right setup?
- The city SOC enables the host-based firewall in Carbon Black Cloud policy for remote assessor laptops. How should that control be understood?
- Parks seasonal hires should receive a looser Carbon Black Cloud policy, and full-time staff should stay on a strict one, including when a seasonal account later becomes full-time. Which grouping method scales?
- Library tablets must be encrypted and on a supported OS or they must lose Hub applications. What Workspace ONE UEM object implements that outcome?
- County building inspectors' phones need the field SSID and must not allow USB file transfer. How should those settings be delivered?
- A school district issues supervised iPads to minors and must disable the App Store and the camera. Which control places those device restrictions?
- City attorneys must receive a VPN profile only while their phones remain compliant, and jailbroken devices must lose that tunnel. What should the administrator configure?
- Public-works rugged Android devices must keep a required safety application installed. How should the administrator enforce that requirement?
- Health-clinic Windows laptops must run BitLocker, and any laptop with encryption off must fail compliance. Which configuration meets that requirement?
- Elections poll tablets must authenticate to the civic WLAN with 802.1X certificates. Where should the administrator deploy that device identity?
- Transit dispatch phones that fail passcode complexity should receive an email and then an enterprise wipe after a grace period. Which compliance design matches that response?
- Parks BYOD phones and city-owned phones must receive different restriction profiles. How should the administrator target those payloads?
- Court-owned iPhones must not back case photos up to iCloud. Which control enforces that restriction?
- A city UEM compliance policy tests compromised status for jailbreak or root. What should the administrator do with devices that fail that test?
- County ERP in Workspace ONE Access must require both a compliant device and membership in the ERP Active Directory group. Which configuration meets that requirement?
- Library patrons must never single sign-on to the staff-only ILS administration app, even when the kiosk is enrolled in UEM. What should the administrator configure?
- City finance SaaS from home must step up authentication, while the on-campus corporate VLAN may use a lighter method. Which Access feature implements that split?
- 911 supervisors open the CAD web application from unmanaged home PCs. What should the Workspace ONE Access policy require?
- Public-health nurses on mobile use Intelligent Hub as the client. How should the administrator order Access policy rules so Hub still evaluates device posture?
- Parks seasonal kiosks should launch only a timekeeping application and must not inherit payroll and HR. Which Access design meets that requirement?
- City attorneys must use certificate or Mobile SSO for the matter-management application, and password fallback must be disabled. What should the administrator change?
- The school-district student application catalog must fail closed when UEM compliance cannot be read. How should the Access policy treat unknown device posture?
- Water-utility contractors may reach a vendor portal only during business hours. Which control sets that window for the SaaS identity flow?
- Elections staff who launch an application from a risky network should see a deny with a custom message. Which control provides that user-facing response?
- City employees see applications in Intelligent Hub that they cannot open. What should the administrator treat as two separate controls?
- The county issues rugged Android devices to animal-control officers. What is the first Workspace ONE endpoint-management step?
- City helpdesk must remotely lock a lost building-inspector tablet. Which action should they use?
- Library Windows PCs should auto-enroll through well-known MDM or drop-ship provisioning. What should the administrator enable?
- Transit wants one targeting object for Android, city-owned, Transportation organization group devices. What should the administrator create?
- Public-health wants Intelligent Hub as the only self-service catalog on clinic devices. Which configuration achieves that?
- Parks seasonal iPhones issued to summer rangers must leave Workspace ONE automatically when the season ends. Which control should the security administrator configure?
- Court-owned MacBooks must escrow FileVault recovery material and remain under supervised management. Which approach meets that requirement?
- The city SOC needs a dashboard of managed endpoints that failed Workspace ONE compliance. Which view should the administrator use?
- Water-utility contractors bring personal Android phones that need city email without IT owning the personal OS. Which enrollment path should the administrator enable?
- A school district wants classroom iPads that many students share during the day. How should the administrator enroll them in Workspace ONE UEM?
- 911 CAD laptops must remain in a locked organization group that help-desk child administrators cannot move. Which control enforces that?
- The city must put Carbon Black Cloud prevention on Windows staff laptops already managed by Workspace ONE UEM. What is the correct sensor path?
- County librarian Macs on macOS 12 and later install the Carbon Black Cloud sensor, but the sensor stays degraded until a system extension is approved. What should the administrator push with the sensor?
- Transit fare-box management VMs run Linux and need Carbon Black Cloud. Which package should the administrator deploy?
- Public-works kiosks never have an interactive user at install time. How should the administrator deploy the CB Defense sensor?
- School-lab non-persistent VDI desktops refresh from a golden image each night. How should the CB Defense sensor be deployed so it survives that cycle?
- City inspectors' Windows laptops should land in the Carbon Black Inspectors sensor group on first check-in, based on Active Directory OU. What must be in place before mass deployment?
- Courts firewalls deny all outbound traffic except an allowlist of SaaS destinations. Sensors will appear offline after install unless which step happens first?
- Water-utility guest VMs on ESXi already have VMware Tools with Guest Introspection. The security team still needs Carbon Black prevention on those workloads. What should the administrator deploy?
- Parks issues seasonal Chromebooks that must be managed, but Carbon Black Cloud does not provide a Defense sensor for Chrome OS. What should the administrator do?
- City staff have been uninstalling the CB Defense sensor from their laptops. Which control should the administrator enable?
- 911 CAD servers need a Carbon Black Cloud workload sensor. The cluster cannot take a simultaneous reboot at shift change. How should the administrator proceed?
- County staff must sign in to Workspace ONE Access with existing Active Directory credentials. What should the administrator configure first?
- The city must federate Workspace ONE Access to a statewide Microsoft Entra ID tenant using SAML. Which configuration is correct?
- Library staff authenticate with Active Directory while volunteers use a separate local or social identity provider. How should Access be set up?
- Schools want the first successful login from the statewide identity provider to create the Workspace ONE Access user automatically. Which feature should the administrator enable?
- Water-utility Workspace ONE Access must bind to on-premises Active Directory. How should the directory connection be built?
- Courts want Workspace ONE Access to use OpenID Connect against a statewide identity platform. Which settings belong on the Access identity-provider object?
- City staff suddenly fail Workspace ONE Access login after the statewide identity provider rotated certificates. What should the administrator update?
- Parks contractors must sign in through a separate identity provider and must not be able to reset city Active Directory passwords. How should the administrator design that identity provider?
- An elections office needs a handful of local break-glass accounts in Workspace ONE Access while regular staff already authenticate through the county enterprise identity provider. How should the security administrator configure identity providers?
- Public-health wants Workspace ONE UEM and Workspace ONE Access to target the same Active Directory groups for enrollment and Hub access. What should the administrator do so Access policies do not drift from UEM?
- City staff iPhones should open Hub apps with Mobile SSO and no extra password prompt. Which Workspace ONE Access configuration is required for that path?
- County field inspectors on Android must sign in to Hub with Mobile SSO using a device certificate. What should the administrator configure?
- Library Windows PCs receive client certificates from Workspace ONE UEM and must use those certificates to reach Hub. How should certificate-based authentication be set up in Access?
- A 911 CAD web app still requires RSA SecurID for a small vendor group. Where should the security administrator add that token path?
- School staff must use password plus a built-in one-time passcode when they open Hub apps from home. What should the administrator configure?
- Water-utility domain-joined PCs on campus should reach Hub with Windows SSO and no extra prompt. Which Access method belongs on that path?
- The city must stop password authentication on the finance Hub app but still allow password on the cafeteria menu app. What is the correct Access change?
- Parks visitor kiosks have no keyboard, so staff cannot enter OTP codes. How should the kiosk Access policy be built?
- Courts want Hub access only when the device is UEM-compliant, not after an Active Directory password alone. What should be added to the Access authentication chain?
- Transit helpdesk can reset AD passwords, so password alone is too weak for a VPN-like SaaS app in Hub. What should the administrator require?
- Elections break-glass accounts authenticate with password on the built-in Access identity provider and must work only from the jump network. How should that password path be scoped?
- The city is standing up NSX-T for civic datacenter security. How should NSX-T Manager be deployed for production?
- County compute clusters must enforce NSX distributed firewall. What prepares the ESXi hosts for that?
- Transit needs north-south gateway firewall at the civic perimeter, not only east-west host filtering. What must be deployed?
- A library workload VLAN must become an NSX object so security groups and tags can consume it. What should the administrator create?
- Water-utility compute hosts need overlay for distributed firewall and Guest Introspection, while Edge uplinks need VLAN connectivity to the civic core. How should transport zones be assigned?
- City DFW rules stay unrealized after objects are created. The inventory shows no security license applied. What should the administrator do first?
- Courts security groups must use vSphere VM names, tags, and clusters. NSX inventory is empty of those objects. What is missing?
- The school district wants distributed firewall only on the prepared student-info clusters, not citywide on day one. How should DFW be enabled?
- Public-health north-south firewall tests fail because the Edge uplink still has IPv6 enabled and the civic ISP is IPv4-only. What should be configured?
- Parks is adding a DR site that needs its own NSX-T security fabric. The requirement is local distributed firewall, not a multi-site routing design. How should NSX-T be deployed there?
- The 911 compute cluster will carry Geneve overlay, but the N-VDS still uses a 1500-byte MTU. What should be configured before relying on later DFW or Traceflow results?
- The city wants NSX-T distributed firewall in production. A contractor proposes writing DFW rules before Managers, licensing, or transport nodes exist. What install order should the administrator follow?
- A county deploys NSX-T Managers for the civic datacenter but skips DNS and NTP. Cluster formation later fails with name-resolution and time-skew errors. What missing preparation step should the security administrator complete?
- Transit applies a transport-node profile to the ESXi clusters that will host fare-system VMs, but no IP pools exist for tunnel endpoints. Overlay transport nodes fail to come up. What should the administrator add in the NSX-T preparation workflow?
- A library vCenter certificate is untrusted when NSX Manager tries to add it as a compute manager, so clusters and VMs never appear for security grouping. What should the administrator fix in the install workflow?
- Water-utility ESXi hosts are below the NSX-T 3.0 support matrix, and transport-node installation is about to start on the SCADA compute cluster. What should the administrator do first?
- After the courts NSX Manager cluster forms, the install checklist still has no NSX backup configured. What should the security administrator include as part of standing up NSX-T?
- A school district deploys NSX Edge nodes for gateway firewall before uplink pNICs and VLAN trunks exist on the top-of-rack switches. North-south traffic never leaves the Edges. What should have been sequenced first in the preparation workflow?
- A city wants Distributed Firewall in default-deny, but some transport nodes are not yet Up and inventory groups are not built. What should the administrator do during the install workflow?
- Parks cloned nested-lab tiny NSX Managers into production for a civic cluster count far larger than the lab. What should the administrator have done during the deploy workflow?
- After first boot of the 911 NSX Managers, the install checklist requires SSH and API access only from jump hosts. How should the administrator treat that requirement?
- A city needs east-west isolation between permitting web VMs and tax database VMs that share the same NSX segment. Which firewall should the administrator configure?
- County guest Wi-Fi VMs must not talk to court case-management VMs, and both can land on the same overlay transport. What control should the administrator use?
- Transit publishes a citizen trip-planner app north-south to the Internet. Where should the administrator place the primary Internet-facing firewall rules?
- A library after-hours batch job should be allowed only during a nightly window. What is the correct NSX-T firewall approach?
- A water-utility operator finds HTTP and SSH mixed on unexpected ports between historian VMs, so TCP/80 alone is not a reliable allow. What should the administrator use in Distributed Firewall?
- Courts require emergency deny rules that always evaluate first during an incident. Where should the administrator put those rules?
- School student VDI desktops may browse only allowlisted FQDNs. Which NSX-T firewall control matches that requirement?
- A city administrator creates a Distributed Firewall rule, but it never enforces on hosts. What should be checked first?
- Parks wants ICMP allowed for monitoring between environments but must not allow RDP. What should the administrator write?
- Public-health EHR VMs need logging whenever Distributed Firewall denies traffic. What should the administrator enable?
- On elections night a Distributed Firewall rule has inverted source and destination members, so poll-book VMs are blocked incorrectly. What is the correct administrative fix?
- 911 voice VMs were added to the Distributed Firewall exclusion list by mistake, so micro-segmentation never applies. Adding more gateway firewall rules does not fix east-west on the same segment. What should the administrator do?
- A city wants Active Directory group-based firewall for finance users on VDI. What must the administrator configure first for Identity Firewall?
- County Identity Firewall events never update for VDI logons. NSX Manager already has an LDAP connection, but Guest Introspection is missing on the VDI cluster. What should the administrator enable?
- A library will use LDAPS to the civic domain controller for NSX Identity Firewall. What should the administrator import into NSX Manager?
- Transit wants nested Active Directory groups as Identity Firewall sources for fare-system VDI. A technician suggests flattening the same groups in Carbon Black Cloud instead. What should the administrator verify?
- A water utility wants Identity Firewall user-based rules on Windows VDI but must not enable them on Linux historian hosts. How should IDFW be turned on?
- Court clerks who join Active Directory in the morning still cannot reach the case-management segment until the next day because NSX-T user mappings stay stale. What should the administrator do?
- A school district connects NSX-T Manager to Workspace ONE Access so civic admins can sign in. Teachers still need Active Directory group-based distributed firewall rules on student VDI. What should the administrator configure next?
- Parks seasonal contractors live in a separate Active Directory forest, and Identity Firewall rules must use those contractor groups. What should the administrator configure?
- Public health must immediately stop a terminated analyst’s Active Directory group from reaching the EHR segment between virtual machines. What should the administrator configure?
- City NSX Manager is bound to Active Directory, but Identity Firewall cannot enumerate finance users because the LDAP service account has no read permission on the user OU. What should the administrator fix first?
- A county tags new tax-system VMs with app=tax and env=prod and wants those VMs to inherit distributed firewall policy when they are cloned. What should the administrator build?
- Transit placed fare-collection on a known set of NSX-T segments and wants DFW policy to follow those segments as VMs are added. What should the administrator use?
- A library needs one NSX group of Active Directory patrons for Identity Firewall and a separate group of catalog VMs for ordinary distributed firewall rules. How should the groups be defined?
- A water utility wants a default-deny stance inside the historian application rather than one data-center-wide rule. What should the administrator configure?
- Courts must keep production case-management VMs from talking to the test cluster even if an Application-category rule later allows the same ports. Where should the prod-versus-test separation be placed?
- A school VDI security group unexpectedly includes the golden-image VM because that template shares the same NSX tag as the floating desktops. What should the administrator do first?
- A city badge printer sits on a physical VLAN and cannot receive an NSX VM tag, but firewall policy must still include it. How should the administrator add the printer?
- Parks clones a production DFW policy onto the disaster-recovery cluster but keeps the same production group names, and the cloned rules still match production members. What should the administrator change?
- Public health wants every VM whose name starts with ehr- in one NSX security group, but also wants membership that survives a later rename. What should the administrator recommend?
- An elections office wants one NSX group for the tabulation application and another for the election-night zone, then DFW rules that mean tabulation-app inside that zone. What construct should the administrator use?
- A 911 computer-aided dispatch policy is applied to a cluster-based security group that accidentally includes the NSX Edge VMs. What should the administrator do?
- A city needs Guest Introspection on VDI guests so Identity Firewall and file introspection can see in-guest events. Staff are about to push only a Carbon Black MSI. What should be installed for Guest Introspection?
- A county partner endpoint-protection service deployment shows Down even though the service VMs exist. The protected workloads are powered off and have no Guest Introspection policy. What does healthy GI require?
- Transit has NSX-T on the cluster, but fare-system guests still run an old VMware Tools build that never installed Guest Introspection drivers. What should the administrator do?
- A library wants antivirus scanning offloaded from catalog VMs to an NSX Guest Introspection partner service VM. What should the administrator deploy?
- A water utility wants Identity Firewall user mapping on Linux historian VMs as well as Windows engineering desktops. Some Linux builds are not on the NSX-T support matrix. What should the administrator do?
- Courts vMotion a protected VM to a cluster that has NSX-T but no Guest Introspection partner service VMs, and GI health goes down. What should the administrator do before expecting health Up?
- A school wants newly cloned student desktops to be Guest Introspection-ready at first boot instead of waiting for a post-clone Tools install. What should be baked into the golden image?
- Public health needs both partner antivirus offload through NSX Guest Introspection and Carbon Black Cloud prevention on the same EHR VMs. Staff believe the Thin Agent replaces the CB Defense sensor. What should be installed?
Administrative and Operational Tasks · 75 questions
- A city permitting web VM talks to a tax database VM on an NSX-T overlay. How should the administrator classify that conversation when choosing a firewall?
- County residents reach a published permitting HTTPS VIP from the internet. How should the administrator classify that flow for firewall placement?
- Two transit fare-collection VMs share the same NSX-T overlay segment. What is true about east-west inspection?
- A library security administrator needs the actual path of a catalog-search VM to a payment VM, including Distributed Firewall drops. Which approach identifies the flow?
- A water-utility OT historian VM must reach a jump box and must never traverse citizen Wi-Fi. What should the administrator do first when grouping that conversation?
- Courts administrators notice vMotion of a case-management VM during host maintenance. Where should they classify that traffic when writing Distributed Firewall application policy?
- A school-clinic VDI desktop reaches the district EHR as the logged-on nurse, not as a service account. How should that flow be identified for NSX-T controls?
- Parks backup VMs stream to a physical backup grid that is not an NSX-T overlay workload. Why must the administrator identify that flow?
- Public-health clinic VMs resolve names and sync time to shared DNS and NTP servers. In which Distributed Firewall thinking should those flows be classified?
- On election night, almost all extra traffic is citizen HTTPS to the results website, with little VM-to-VM chatter. Where should the administrator size firewall monitoring and logging for that spike?
- The 911 SOC must protect CAD-to-radio-gateway traffic before writing Distributed Firewall rules. What identification step comes first?
- The city wants every new VM tagged app=erp to receive Distributed Firewall policy without a weekly ticket. Which automation mechanism should the administrator use?
- County administrators review NSX Intelligence policy recommendations for a permitting application and accept them into Distributed Firewall. What is that action?
- Transit CI pipelines must push NSX-T groups and firewall policy without an operator clicking hundreds of rules. Which mechanism should they use?
- Library automation updates NSX-T security tags from the CMDB with PowerCLI or Ansible. What is the security-policy automation mechanism?
- Water-utility workstations in an OT Active Directory OU must receive a Carbon Black Cloud policy automatically. Which mechanism does that?
- Courts tablets in a child organization group should receive a compliance profile as soon as they enroll. Which Workspace ONE UEM automation mechanism assigns that payload?
- Schools want Workspace ONE Access authentication policies left untouched while group entitlements to the gradebook app update from Active Directory. What should be automated?
- Parks uses vRealize Automation to stamp NSX-T security tags when a new recreation VM is provisioned. Why does that keep Distributed Firewall true?
- A public-health script proposal would disable Distributed Firewall through the API on a cron so nightly batch jobs always succeed. What should the administrator do?
- After a city change ticket is approved, ServiceNow writes a member into an NSX-T group through the Policy API. How should that be classified?
- County operators see Distributed Firewall rules with zero hit counts for months. What is the operational management action during a change window?
- Transit vendors need weekend access to a fare API for a cutover. How should the administrator manage that allow?
- A library validated Distributed Firewall policy in test and must apply the same intent in production. What is the preferred promotion method?
- Water-utility leadership wants the Distributed Firewall default action flipped from the current setting. How should the administrator treat that change?
- During an audit month, courts must prove Environment-category Distributed Firewall denials on case-management VMs without flooding the SIEM for the rest of the year. What operational step should the administrator take?
- A school district enables Application default-deny on student-information VMs. DNS and Active Directory then fail even though Infrastructure allows for DNS and LDAP already exist. An intern proposes moving Infrastructure below Application. What should the operator do?
- Parks publishes a citizen reservation app. Gateway firewall and Distributed Firewall both have overlapping TCP 443 allows for the same conversation, and hit counts are confusing. How should the administrator document the two planes to avoid double-shadow?
- Public-health clinic staff save a new Distributed Firewall section for immunization VMs, but realized rules on the transport nodes still match the previous policy. What publish discipline should the administrator follow?
- On election night, threat intel flags a command-and-control network talking to a results-app group. Security needs a fast Distributed Firewall block that must not live forever. How should the Emergency category be used?
- City backup appliances were added to the NSX-T Distributed Firewall exclusion list after jobs failed. What ongoing management should the administrator apply to that list?
- 911 computer-aided dispatch uses a shared NSX-T service object named civic-https that many Distributed Firewall rules reference. A technician edits the object to add TCP 8443. What must the administrator consider before publishing?
- County is about to rewrite Environment Distributed Firewall policy for tax VMs. What should the administrator do first as part of managing that policy?
- City auditors ask for proof that staff laptops are encrypted and Carbon Black Cloud sensors are in prevention. Which evidence set meets regulation assurance?
- County court case files require Workspace ONE Access to admit only UEM-compliant devices. How should the administrator monitor that access path continuously?
- Transit fare-collection VMs handle cardholder-like data. Auditors want assurance that east-west isolation on those segments is actually enforced. What should the administrator monitor?
- A library grants Carbon Black Cloud bypass permissions for a catalog vendor tool. How should the administrator keep those prevention exceptions from rotting?
- A water utility must prove OT historian VMs stay in a Distributed Firewall group separate from citizen portal VMs for NERC-like separation evidence. What should the administrator produce?
- A school district must show that student-information endpoints stay patched as a regulation control for student PII systems. Which monitoring source is the right compliance signal?
- Parks staff tablets drop Workspace ONE UEM enrollment but still try to open the reservation admin app through Access. How should the administrator treat that unmanaged drift?
- Public-health wants one assurance pipeline that correlates NSX-T denials, Carbon Black Cloud detections, and UEM compliance. What should the administrator enable?
- After election night, the clerk must prove only the election-staff Active Directory group reached the results application. Which evidence is identity-aware?
- City council asks whether production Distributed Firewall still defaults to deny. What should the administrator show?
- 911 is in a CJIS-style audit. A technician offers last quarter's lab screenshots as encryption, sensor, and firewall evidence. What should the administrator submit instead?
- County fails over permitting VMs to a disaster-recovery NSX-T fabric. Recovered VMs match no security groups and hit default-deny. What should have been replicated to the DR site?
- City EHR VMs recover with Site Recovery Manager. The draft runbook says power on the VMs first and apply NSX-T security policy later. What should the administrator change?
- Transit fails laptops and VDI clones to a disaster-recovery site. Carbon Black Cloud sensors check in as offline and stay on stale prevention policy. What DR security step is required?
- Library Workspace ONE Access is SaaS. After failover, staff authentication fails because Access network ranges still list only the production egress NAT. What should the administrator update?
- Water-utility Site Recovery Manager recovery places OT jump boxes on a disaster-recovery cluster that also hosts citizen portal VMs. What must the administrator preserve?
- Courts Identity Firewall rules depend on Guest Introspection. A disaster-recovery test recovers case-management VMs, but user-based rules never hit because Guest Introspection is not deployed on the DR cluster. What should be added to DR prep?
- A school district already snapshots vCenter as part of cyber-recovery. Which additional control-plane backup keeps NSX-T firewall policy recoverable after a Manager disaster?
- Parks ransomware recovery restores POS and reservation VMs that must stay isolated until they are verified clean. Which combined-stack action matches the security BC/DR runbook?
- Public-health's disaster runbook assumes the statewide SAML identity provider may be unavailable. How should the administrator pre-stage Workspace ONE Access for that failure?
- An elections warm-site uses different vCenter tags than production. Recovered results VMs sit in empty security groups. What should the administrator document before the next failover test?
- During a 911 failover test, an operator proposes putting restored CAD VMs on the Distributed Firewall exclusion list so recovery is faster. What should the administrator do?
- City Windows laptops must receive security patches under the VMware Security operational model. Which patch source should the administrator use?
- A county must patch Windows devices used by building inspectors without interrupting daytime field work. Which Workspace ONE assignment is appropriate?
- A public library must keep Chrome and Firefox current on staff PCs without treating those updates as Windows OS patches. Which Workspace ONE action is correct?
- Transit rugged Windows tablets on buses must not install patches while vehicles are in revenue service. How should the administrator schedule the update?
- A water utility wants security patches on OT-adjacent Windows jump boxes only after a small test ring succeeds. Which Workspace ONE rollout is appropriate?
- Courts require that Windows devices missing a critical security patch lose SSO to case-management apps. How should the administrator enforce that?
- A school district must push a security iPadOS update to classroom iPads. Which product should the administrator use?
- Parks Windows devices remain in a pending-reboot patch state after a security update. What should the administrator do first?
- A public-health line-of-business application conflicts with one Windows KB. How should the administrator handle the exclusion?
- 911 CAD thick-clients will receive a Workspace ONE patch during a change window. Carbon Black Cloud sensors are in prevention. What should the administrator do unless the vendor documents a conflict?
- City Hub must single-sign-on staff into Microsoft 365 and a state SaaS portal using a third-party identity provider. Which objects should the administrator manage?
- A county is adding a new statewide SAML identity provider and must keep the current IdP online during migration. How should the administrator cut over?
- Library volunteers authenticate with a third-party social identity provider that must never single-sign-on to the finance application. What should the administrator configure?
- Transit staff SSO to the scheduling portal starts failing as the SAML signing certificate approaches expiry. What operational action should the administrator take?
- A water utility requires multifactor authentication at the statewide identity provider and a compliant enrolled device before SCADA-adjacent web tools open. How should the administrator layer those controls?
- After the courts case-management URL changes, SP-initiated and IdP-initiated SSO both fail. Which Workspace ONE Access objects should the administrator update?
- Just-in-time provisioning from the statewide identity provider creates Access accounts for every student, flooding the school-district directory. What should the administrator tighten?
- Parks wants shorter idle SSO sessions to the point-of-sale back-office application. Where should the administrator change session lifetime?
- The public-health third-party identity provider is down, and clinic administrators still need a governed sign-in path from the civic jump network. What should the administrator have ready?
- On elections night, SSO to the results dashboard must require a compliant city device and membership in the state identity-provider group ElectionWorkers. What should the administrator verify?
Troubleshooting and Repairing · 75 questions
- A city SOC wants recommended Distributed Firewall allow lists from live east-west overlay flows among permitting VMs. Which tool should the administrator use first to generate those DFW recommendations?
- A county permit-desk packet drop might be the physical top-of-rack switch or the NSX overlay. Which tool should the administrator use to trace underlay plus overlay path together?
- A library needs application discovery that includes physical badge printers as well as NSX-backed VMs. Which tool maps those mixed physical and virtual application boundaries?
- A transit agency already runs NSX-T 3.x and needs east-west grouping visuals inside NSX Manager for bus-dispatch VMs. Where should the administrator open that view?
- A water-utility security admin must pick one tool to plan micro-segmentation from NSX flows and a different tool to troubleshoot a VLAN mismatch on a Cisco top-of-rack switch. How should those jobs map?
- Court case-management VMs are tagged, and the administrator wants an exported Distributed Firewall allow list from observed east-west flows among those VMs. Which workflow is correct?
- A school-district path from a campus NSX segment to a second-site student-information VM crosses a WAN circuit. Which tool can include those WAN and physical hops that NSX Intelligence will not model the same way?
- A city has NSX Manager but never deployed the NSX Intelligence appliance. Analysts open Manager expecting flow recommendations. What should the administrator conclude?
- Parks concession POS VMs sit on NSX overlay, and the administrator only needs to know which overlay workloads talked to those VMs this week. What is the appropriate tool choice?
- A 911 dispatch team wants flow and security-path visibility for CAD VMs but opens vRealize Operations VM-health dashboards. Which correction is right?
- County ESXi transport-node install stays stuck because the NSX VIB depot is unreachable from the host. What should the administrator check first?
- After one NSX Manager node reboot, the city Manager cluster VIP stops answering from the civic jump network. What should the administrator inspect?
- A transit NSX Edge shows Down after a datacenter change, and the uplink VLAN was never allowed on the trunk or PortGroup. What should the administrator fix?
- After a vCenter certificate rotation, the library NSX compute manager shows Disconnected and inventory of catalog VMs stops updating. What should the administrator do?
- A water-utility ESXi host shows Unknown realization for Distributed Firewall, and new SCADA-segment rules never appear on the host. What should the administrator check?
- Court catalog TEP overlay ping fails after the VDS MTU was left at 1500. Which change restores overlay connectivity?
- A school-district Distributed Firewall allow never hits because the student-information VM sits on a VLAN port group that is not prepared for NSX. What should the administrator do first?
- A city permitting allow exists in Distributed Firewall, but a higher Emergency deny matches first and hit counts never increment on the allow. What should the administrator do?
- A county DFW rule uses an NSX group that shows zero members after clerks renamed VMs and reapplied tags in vCenter. What should the administrator inspect first?
- Transit north-south gateway firewall policy looks correct in NSX Manager, but the Edge datapath does not have the rule and permit-desk NAT traffic is unfiltered. What should the administrator check?
- A library Distributed Firewall rule uses an L7 context profile for HTTP, but the catalog flow is TLS-encrypted and application-id never matches. What should the administrator understand?
- A water-utility time-based Distributed Firewall allow for a vendor window never turns on, because NSX Manager is in UTC and staff scheduled the window in local time. What should the administrator fix?
- A parks IDFW allow for the POS console never matches because the signed-in user is a local Windows account, not an Active Directory user. What should the administrator conclude?
- A public-health lab VM was placed on the Distributed Firewall exclusion list during troubleshooting and never returned. New DFW rules do nothing on that VM. What should the administrator do?
- An elections-night Distributed Firewall allow for precinct printers looks correct, but the IP set used in the rule is a single mistyped /32 instead of the printer range. What should the administrator do?
- A 911 CAD packet log in NSX-T shows dispatcher-to-records traffic hitting only the default drop. Operations confirms that flow is required. What should the security administrator change next?
- City inspector laptops with CB Defense sensors sit behind a new outbound web proxy and now show Offline in Carbon Black Cloud. The laptops are not NSX-T workloads. What should the security administrator do first?
- County assessor macOS endpoints show the Carbon Black Cloud sensor as Degraded after a macOS upgrade. System extensions are not approved. What restores protection?
- Transit bus-yard endpoints have Carbon Black Cloud sensors installed, but prevention never applies. Group criteria never match, and someone deleted the Standard policy. What should the security administrator restore first?
- Library helpdesk analysts can see Carbon Black Cloud alerts but cannot isolate a compromised kiosk. NSX-T is not in the kiosk path. What should the security administrator fix?
- A water-utility golden image for historian jump VMs was cloned with the Carbon Black Cloud sensor still registered. Only one of many clones appears in the console. What is the correct repair?
- A courts e-filing desktop app is terminated by Carbon Black Cloud. SOC confirms the policy’s core prevention is working as designed against unknown binaries. What should the security administrator do?
- School-district Windows sensors are several versions behind and miss a current Carbon Black Cloud prevention capability. VMware Tools is already current. How should the security administrator upgrade protection?
- Parks kiosk Windows Firewall is blocking Carbon Black Cloud sensor processes after a hardening GPO. The kiosks show Offline. What should the security administrator allow?
- Public-health analysts cannot run Live Query / Audit and Remediation on a subset of clinics. Endpoint Standard sensors are online. What should the security administrator verify first?
- City permitting Windows 10 laptops roll back the Carbon Black Cloud sensor install. Setup logs show a missing Visual C++ redistributable and a non-admin user context. What restores a successful install?
- An elections laptop still has the Carbon Black Cloud sensor installed after a lab test, but prevention is off and the console shows bypass or deregistered. What should the security administrator do?
- 911 CAD VMs have Carbon Black Cloud workload sensors, but automatic policy from vCenter tags never applies. UEM smart groups are healthy. What should the security administrator check?
- County iPhones are enrolled and compliant in Workspace ONE UEM, but Workspace ONE Access still denies apps with “device not compliant.” Carbon Black Cloud policy is unrelated. What should the security administrator check first?
- City Hub staging barcodes enroll new inspector Android devices into the wrong Organization Group, so security profiles never land. NSX-T is not in the path. What should the security administrator fix?
- Library Android tablets never form a work profile during Workspace ONE UEM enrollment. The gateway firewall already allows the UEM FQDNs. What should the security administrator check?
- Transit iOS restriction profiles fail to install on operator iPhones. Payload signing looks valid, but the MDM APNs certificate is expired. What restores profile delivery?
- Water-utility Windows laptops refuse Workspace ONE UEM MDM enrollment and report an existing third-party MDM authority. What should the security administrator do first?
- Courts attorneys cannot start the Workspace ONE Tunnel app; UEM shows the iPads non-compliant for missing passcode. The Tunnel server is healthy. What should the security administrator do first?
- School iPads flag as compromised (jailbreak) after a test IPA, so compliance fails. Identity Firewall is not involved. What should the security administrator do?
- Parks 802.1X certificate profiles fail because SCEP to the civic CA never completes. Carbon Black Cloud is healthy. What should the security administrator debug?
- Public-health Adaptive Access always fail-opens device posture after the Access connector VM is powered off. UEM still shows devices compliant. What restores posture-based denials?
- City SEG blocks Exchange from a laptop that UEM shows as compliant. The device token on SEG is stale. Distributed firewall is not in the mail path. What should the security administrator do?
- Elections iPad restriction profiles never apply. The assigned smart group criterion is Platform = Android. What should the security administrator fix?
- 911 Windows laptops received the Workspace ONE UEM BitLocker payload, but encryption compliance still fails because the recovery key did not escrow. What should the security administrator check?
- City kiosks on a guest VLAN with a walled garden show CB Defense sensors Offline and Intelligent Hub cannot enroll, even though NSX-T identity firewall groups look healthy. What should the security administrator open first?
- After a county perimeter firewall change, NSX-T Manager shows the vCenter compute manager as down and transport-node preparation stalls, while overlay VMs still enforce east-west Distributed Firewall. What should the administrator restore?
- A transit Workspace ONE Access connector stays disconnected from the Access tenant after the city proxy began SSL inspection. Outbound TCP 443 from the connector VM is permitted. What should the administrator check next?
- Library overlay VMs lose DNS after a resolver outage, and NSX-T FQDN-based Distributed Firewall context profiles stop matching even though IP/port rules still hit. What should the administrator restore first?
- Water-utility ESXi hosts and NSX-T Edge nodes are configured to send syslog to a SIEM, but no events arrive after a network change. Some nodes use UDP 514 and others use TLS TCP 6514. What should the administrator test first?
- Parks Endpoint Protection via Guest Introspection shows partner service VMs unhealthy. Transport nodes are prepared and Distributed Firewall Application policy is unchanged, but the service insertion network cannot ping the partner SVM. What should the administrator fix first?
- Public-health Workspace ONE UEM cannot reach the on-premises CA or LDAP after a datacenter ACL change. The cloud UEM console itself is healthy. What should the administrator trace?
- City laptops on VPN show Carbon Black Cloud sensors Offline. The split-tunnel include list carries only RFC1918, and a VPN client firewall drops non-tunneled destinations that are not listed. Carbon Black Cloud FQDNs were never added. What should the administrator change?
- Elections NSX Intelligence no longer publishes Distributed Firewall recommendations. The Intelligence appliance is powered on, but it cannot reach the NSX-T Managers on the management network. What should the administrator restore?
- A county on-premises NSX-T Manager cluster has tight Distributed Firewall policy. Workloads in a VMware Cloud SDDC with its own NSX-T instance remain any-any. An engineer added those cloud VMs to an on-premises NSX group. What should the administrator conclude?
- A city Carbon Black Cloud org lists only on-premises endpoints. Azure IaaS VMs that run the same line-of-business apps never appear, even though NSX-T Distributed Firewall is healthy in the on-premises SDDC. What should the administrator do?
- Transit Workspace ONE Access policies that should restrict a cloud SaaS to the operations network now match any after the agency moved those operators onto a public-cloud desktop pool. The pool egresses through a new NAT prefix that was never added as an Access network range. What should the administrator update?
- A water-utility uses a public-cloud directory as the Workspace ONE Access identity provider, while NSX-T identity firewall still binds on-premises Active Directory. The same operator is in SCADA-Operators in AD and scada-ops in the cloud directory, so Access and IDFW disagree on who may reach a jump VM. What should the administrator do?
- School-issued laptops are Intelligent Hub managed. Teachers roam into a cloud VDI desktop that is not an NSX-T prepared workload. Staff report Hub still blocks SaaS when compliance fails, and they expect the on-premises Distributed Firewall to follow the laptop into the cloud VDI. What should the administrator explain?
- Parks disaster-recovery VMs in a public-cloud region show Carbon Black Cloud sensors Offline. On-premises sensors are fine. The region's cloud security groups allow only management RDP and SSH and never listed CBC SaaS FQDNs. What should the administrator update?
- Public-health on-premises NSX-T uses a default-deny Distributed Firewall. The agency's cloud SDDC still has any-any on its NSX-T instance. Auditors ask why production-like workloads are wide open in the cloud. What should the administrator flag?
- City Workspace ONE Access uses a hybrid LDAP bind from the cloud tenant through ExpressRoute to on-premises domain controllers. After a WAN flap, directory sync fails. An engineer wants to regenerate IdP metadata immediately. What should the administrator check first?
- County overlay workloads black-hole large packets after a ToR change. Geneve-encapsulated frames are dropped, and NSX-T security looks down even though Manager and Distributed Firewall rules are unchanged. Underlay MTU on the new ToR is 1500. What should the administrator fix?
- Transit north-south traffic never hits the NSX-T gateway firewall after a core-switch change. East-west Distributed Firewall still works. The Edge uplink VLAN is missing from the physical trunk toward the Edge host. What should the administrator fix?
- A library ESXi host's overlay TEP flaps, and Distributed Firewall realization on that host flaps with it. vmkping to other TEPs drops whenever one member of the physical NIC team errors. What should the administrator inspect first?
- Water-utility NSX-T overlay on a VLAN goes silent after a spanning-tree reconvergence. The LAN team reports that VLAN in a Blocking state on the ToR toward the transport nodes. Distributed Firewall configuration is unchanged. What should the administrator do?
- Courts NSX-T Manager syslog and Carbon Black Cloud check-ins through an on-premises proxy both stall after a core hardware firewall change. Overlay east-west Distributed Firewall still hits. Packet captures stop at the core firewall, which now rate-limits and ACLs those destinations. What should the administrator identify?
- A school IDF access switch enters a PoE reboot loop, taking down the management VLAN for a small vSphere cluster. NSX-T Manager cannot reach those hosts, and an operator starts deleting Distributed Firewall rules to un-stick the cluster. What should the administrator do?
- Parks on-premises DNS appliances fail. Workspace ONE Access connector sync, Carbon Black Cloud sensor name resolution, and NSX-T FQDN-based Distributed Firewall all break in the same window. Three product teams want to rebuild their stacks. What should the administrator restore first?
- The 911 center's GPS NTP clock fails. Within hours, Workspace ONE Access tokens, TLS certificates on NSX-T Manager, and identity-firewall time windows all skew. Operators propose rewriting IDFW groups. What should the administrator restore?
These questions are original practice material and are NOT actual exam questions or brain-dump content. All vendor marks are trademarks of their respective owners. This site is not affiliated with, endorsed by, or sponsored by Broadcom.