Administrative and Operational Tasks
VCP-SEC · 75 questions
- A city permitting web VM talks to a tax database VM on an NSX-T overlay. How should the administrator classify that conversation when choosing a firewall?
- County residents reach a published permitting HTTPS VIP from the internet. How should the administrator classify that flow for firewall placement?
- Two transit fare-collection VMs share the same NSX-T overlay segment. What is true about east-west inspection?
- A library security administrator needs the actual path of a catalog-search VM to a payment VM, including Distributed Firewall drops. Which approach identifies the flow?
- A water-utility OT historian VM must reach a jump box and must never traverse citizen Wi-Fi. What should the administrator do first when grouping that conversation?
- Courts administrators notice vMotion of a case-management VM during host maintenance. Where should they classify that traffic when writing Distributed Firewall application policy?
- A school-clinic VDI desktop reaches the district EHR as the logged-on nurse, not as a service account. How should that flow be identified for NSX-T controls?
- Parks backup VMs stream to a physical backup grid that is not an NSX-T overlay workload. Why must the administrator identify that flow?
- Public-health clinic VMs resolve names and sync time to shared DNS and NTP servers. In which Distributed Firewall thinking should those flows be classified?
- On election night, almost all extra traffic is citizen HTTPS to the results website, with little VM-to-VM chatter. Where should the administrator size firewall monitoring and logging for that spike?
- The 911 SOC must protect CAD-to-radio-gateway traffic before writing Distributed Firewall rules. What identification step comes first?
- The city wants every new VM tagged app=erp to receive Distributed Firewall policy without a weekly ticket. Which automation mechanism should the administrator use?
- County administrators review NSX Intelligence policy recommendations for a permitting application and accept them into Distributed Firewall. What is that action?
- Transit CI pipelines must push NSX-T groups and firewall policy without an operator clicking hundreds of rules. Which mechanism should they use?
- Library automation updates NSX-T security tags from the CMDB with PowerCLI or Ansible. What is the security-policy automation mechanism?
- Water-utility workstations in an OT Active Directory OU must receive a Carbon Black Cloud policy automatically. Which mechanism does that?
- Courts tablets in a child organization group should receive a compliance profile as soon as they enroll. Which Workspace ONE UEM automation mechanism assigns that payload?
- Schools want Workspace ONE Access authentication policies left untouched while group entitlements to the gradebook app update from Active Directory. What should be automated?
- Parks uses vRealize Automation to stamp NSX-T security tags when a new recreation VM is provisioned. Why does that keep Distributed Firewall true?
- A public-health script proposal would disable Distributed Firewall through the API on a cron so nightly batch jobs always succeed. What should the administrator do?
- After a city change ticket is approved, ServiceNow writes a member into an NSX-T group through the Policy API. How should that be classified?
- County operators see Distributed Firewall rules with zero hit counts for months. What is the operational management action during a change window?
- Transit vendors need weekend access to a fare API for a cutover. How should the administrator manage that allow?
- A library validated Distributed Firewall policy in test and must apply the same intent in production. What is the preferred promotion method?
- Water-utility leadership wants the Distributed Firewall default action flipped from the current setting. How should the administrator treat that change?
- During an audit month, courts must prove Environment-category Distributed Firewall denials on case-management VMs without flooding the SIEM for the rest of the year. What operational step should the administrator take?
- A school district enables Application default-deny on student-information VMs. DNS and Active Directory then fail even though Infrastructure allows for DNS and LDAP already exist. An intern proposes moving Infrastructure below Application. What should the operator do?
- Parks publishes a citizen reservation app. Gateway firewall and Distributed Firewall both have overlapping TCP 443 allows for the same conversation, and hit counts are confusing. How should the administrator document the two planes to avoid double-shadow?
- Public-health clinic staff save a new Distributed Firewall section for immunization VMs, but realized rules on the transport nodes still match the previous policy. What publish discipline should the administrator follow?
- On election night, threat intel flags a command-and-control network talking to a results-app group. Security needs a fast Distributed Firewall block that must not live forever. How should the Emergency category be used?
- City backup appliances were added to the NSX-T Distributed Firewall exclusion list after jobs failed. What ongoing management should the administrator apply to that list?
- 911 computer-aided dispatch uses a shared NSX-T service object named civic-https that many Distributed Firewall rules reference. A technician edits the object to add TCP 8443. What must the administrator consider before publishing?
- County is about to rewrite Environment Distributed Firewall policy for tax VMs. What should the administrator do first as part of managing that policy?
- City auditors ask for proof that staff laptops are encrypted and Carbon Black Cloud sensors are in prevention. Which evidence set meets regulation assurance?
- County court case files require Workspace ONE Access to admit only UEM-compliant devices. How should the administrator monitor that access path continuously?
- Transit fare-collection VMs handle cardholder-like data. Auditors want assurance that east-west isolation on those segments is actually enforced. What should the administrator monitor?
- A library grants Carbon Black Cloud bypass permissions for a catalog vendor tool. How should the administrator keep those prevention exceptions from rotting?
- A water utility must prove OT historian VMs stay in a Distributed Firewall group separate from citizen portal VMs for NERC-like separation evidence. What should the administrator produce?
- A school district must show that student-information endpoints stay patched as a regulation control for student PII systems. Which monitoring source is the right compliance signal?
- Parks staff tablets drop Workspace ONE UEM enrollment but still try to open the reservation admin app through Access. How should the administrator treat that unmanaged drift?
- Public-health wants one assurance pipeline that correlates NSX-T denials, Carbon Black Cloud detections, and UEM compliance. What should the administrator enable?
- After election night, the clerk must prove only the election-staff Active Directory group reached the results application. Which evidence is identity-aware?
- City council asks whether production Distributed Firewall still defaults to deny. What should the administrator show?
- 911 is in a CJIS-style audit. A technician offers last quarter's lab screenshots as encryption, sensor, and firewall evidence. What should the administrator submit instead?
- County fails over permitting VMs to a disaster-recovery NSX-T fabric. Recovered VMs match no security groups and hit default-deny. What should have been replicated to the DR site?
- City EHR VMs recover with Site Recovery Manager. The draft runbook says power on the VMs first and apply NSX-T security policy later. What should the administrator change?
- Transit fails laptops and VDI clones to a disaster-recovery site. Carbon Black Cloud sensors check in as offline and stay on stale prevention policy. What DR security step is required?
- Library Workspace ONE Access is SaaS. After failover, staff authentication fails because Access network ranges still list only the production egress NAT. What should the administrator update?
- Water-utility Site Recovery Manager recovery places OT jump boxes on a disaster-recovery cluster that also hosts citizen portal VMs. What must the administrator preserve?
- Courts Identity Firewall rules depend on Guest Introspection. A disaster-recovery test recovers case-management VMs, but user-based rules never hit because Guest Introspection is not deployed on the DR cluster. What should be added to DR prep?
- A school district already snapshots vCenter as part of cyber-recovery. Which additional control-plane backup keeps NSX-T firewall policy recoverable after a Manager disaster?
- Parks ransomware recovery restores POS and reservation VMs that must stay isolated until they are verified clean. Which combined-stack action matches the security BC/DR runbook?
- Public-health's disaster runbook assumes the statewide SAML identity provider may be unavailable. How should the administrator pre-stage Workspace ONE Access for that failure?
- An elections warm-site uses different vCenter tags than production. Recovered results VMs sit in empty security groups. What should the administrator document before the next failover test?
- During a 911 failover test, an operator proposes putting restored CAD VMs on the Distributed Firewall exclusion list so recovery is faster. What should the administrator do?
- City Windows laptops must receive security patches under the VMware Security operational model. Which patch source should the administrator use?
- A county must patch Windows devices used by building inspectors without interrupting daytime field work. Which Workspace ONE assignment is appropriate?
- A public library must keep Chrome and Firefox current on staff PCs without treating those updates as Windows OS patches. Which Workspace ONE action is correct?
- Transit rugged Windows tablets on buses must not install patches while vehicles are in revenue service. How should the administrator schedule the update?
- A water utility wants security patches on OT-adjacent Windows jump boxes only after a small test ring succeeds. Which Workspace ONE rollout is appropriate?
- Courts require that Windows devices missing a critical security patch lose SSO to case-management apps. How should the administrator enforce that?
- A school district must push a security iPadOS update to classroom iPads. Which product should the administrator use?
- Parks Windows devices remain in a pending-reboot patch state after a security update. What should the administrator do first?
- A public-health line-of-business application conflicts with one Windows KB. How should the administrator handle the exclusion?
- 911 CAD thick-clients will receive a Workspace ONE patch during a change window. Carbon Black Cloud sensors are in prevention. What should the administrator do unless the vendor documents a conflict?
- City Hub must single-sign-on staff into Microsoft 365 and a state SaaS portal using a third-party identity provider. Which objects should the administrator manage?
- A county is adding a new statewide SAML identity provider and must keep the current IdP online during migration. How should the administrator cut over?
- Library volunteers authenticate with a third-party social identity provider that must never single-sign-on to the finance application. What should the administrator configure?
- Transit staff SSO to the scheduling portal starts failing as the SAML signing certificate approaches expiry. What operational action should the administrator take?
- A water utility requires multifactor authentication at the statewide identity provider and a compliant enrolled device before SCADA-adjacent web tools open. How should the administrator layer those controls?
- After the courts case-management URL changes, SP-initiated and IdP-initiated SSO both fail. Which Workspace ONE Access objects should the administrator update?
- Just-in-time provisioning from the statewide identity provider creates Access accounts for every student, flooding the school-district directory. What should the administrator tighten?
- Parks wants shorter idle SSO sessions to the point-of-sale back-office application. Where should the administrator change session lifetime?
- The public-health third-party identity provider is down, and clinic administrators still need a governed sign-in path from the civic jump network. What should the administrator have ready?
- On elections night, SSO to the results dashboard must require a compliant city device and membership in the state identity-provider group ElectionWorkers. What should the administrator verify?