Troubleshooting and Repairing
VCP-SEC · 75 questions
- A city SOC wants recommended Distributed Firewall allow lists from live east-west overlay flows among permitting VMs. Which tool should the administrator use first to generate those DFW recommendations?
- A county permit-desk packet drop might be the physical top-of-rack switch or the NSX overlay. Which tool should the administrator use to trace underlay plus overlay path together?
- A library needs application discovery that includes physical badge printers as well as NSX-backed VMs. Which tool maps those mixed physical and virtual application boundaries?
- A transit agency already runs NSX-T 3.x and needs east-west grouping visuals inside NSX Manager for bus-dispatch VMs. Where should the administrator open that view?
- A water-utility security admin must pick one tool to plan micro-segmentation from NSX flows and a different tool to troubleshoot a VLAN mismatch on a Cisco top-of-rack switch. How should those jobs map?
- Court case-management VMs are tagged, and the administrator wants an exported Distributed Firewall allow list from observed east-west flows among those VMs. Which workflow is correct?
- A school-district path from a campus NSX segment to a second-site student-information VM crosses a WAN circuit. Which tool can include those WAN and physical hops that NSX Intelligence will not model the same way?
- A city has NSX Manager but never deployed the NSX Intelligence appliance. Analysts open Manager expecting flow recommendations. What should the administrator conclude?
- Parks concession POS VMs sit on NSX overlay, and the administrator only needs to know which overlay workloads talked to those VMs this week. What is the appropriate tool choice?
- A 911 dispatch team wants flow and security-path visibility for CAD VMs but opens vRealize Operations VM-health dashboards. Which correction is right?
- County ESXi transport-node install stays stuck because the NSX VIB depot is unreachable from the host. What should the administrator check first?
- After one NSX Manager node reboot, the city Manager cluster VIP stops answering from the civic jump network. What should the administrator inspect?
- A transit NSX Edge shows Down after a datacenter change, and the uplink VLAN was never allowed on the trunk or PortGroup. What should the administrator fix?
- After a vCenter certificate rotation, the library NSX compute manager shows Disconnected and inventory of catalog VMs stops updating. What should the administrator do?
- A water-utility ESXi host shows Unknown realization for Distributed Firewall, and new SCADA-segment rules never appear on the host. What should the administrator check?
- Court catalog TEP overlay ping fails after the VDS MTU was left at 1500. Which change restores overlay connectivity?
- A school-district Distributed Firewall allow never hits because the student-information VM sits on a VLAN port group that is not prepared for NSX. What should the administrator do first?
- A city permitting allow exists in Distributed Firewall, but a higher Emergency deny matches first and hit counts never increment on the allow. What should the administrator do?
- A county DFW rule uses an NSX group that shows zero members after clerks renamed VMs and reapplied tags in vCenter. What should the administrator inspect first?
- Transit north-south gateway firewall policy looks correct in NSX Manager, but the Edge datapath does not have the rule and permit-desk NAT traffic is unfiltered. What should the administrator check?
- A library Distributed Firewall rule uses an L7 context profile for HTTP, but the catalog flow is TLS-encrypted and application-id never matches. What should the administrator understand?
- A water-utility time-based Distributed Firewall allow for a vendor window never turns on, because NSX Manager is in UTC and staff scheduled the window in local time. What should the administrator fix?
- A parks IDFW allow for the POS console never matches because the signed-in user is a local Windows account, not an Active Directory user. What should the administrator conclude?
- A public-health lab VM was placed on the Distributed Firewall exclusion list during troubleshooting and never returned. New DFW rules do nothing on that VM. What should the administrator do?
- An elections-night Distributed Firewall allow for precinct printers looks correct, but the IP set used in the rule is a single mistyped /32 instead of the printer range. What should the administrator do?
- A 911 CAD packet log in NSX-T shows dispatcher-to-records traffic hitting only the default drop. Operations confirms that flow is required. What should the security administrator change next?
- City inspector laptops with CB Defense sensors sit behind a new outbound web proxy and now show Offline in Carbon Black Cloud. The laptops are not NSX-T workloads. What should the security administrator do first?
- County assessor macOS endpoints show the Carbon Black Cloud sensor as Degraded after a macOS upgrade. System extensions are not approved. What restores protection?
- Transit bus-yard endpoints have Carbon Black Cloud sensors installed, but prevention never applies. Group criteria never match, and someone deleted the Standard policy. What should the security administrator restore first?
- Library helpdesk analysts can see Carbon Black Cloud alerts but cannot isolate a compromised kiosk. NSX-T is not in the kiosk path. What should the security administrator fix?
- A water-utility golden image for historian jump VMs was cloned with the Carbon Black Cloud sensor still registered. Only one of many clones appears in the console. What is the correct repair?
- A courts e-filing desktop app is terminated by Carbon Black Cloud. SOC confirms the policy’s core prevention is working as designed against unknown binaries. What should the security administrator do?
- School-district Windows sensors are several versions behind and miss a current Carbon Black Cloud prevention capability. VMware Tools is already current. How should the security administrator upgrade protection?
- Parks kiosk Windows Firewall is blocking Carbon Black Cloud sensor processes after a hardening GPO. The kiosks show Offline. What should the security administrator allow?
- Public-health analysts cannot run Live Query / Audit and Remediation on a subset of clinics. Endpoint Standard sensors are online. What should the security administrator verify first?
- City permitting Windows 10 laptops roll back the Carbon Black Cloud sensor install. Setup logs show a missing Visual C++ redistributable and a non-admin user context. What restores a successful install?
- An elections laptop still has the Carbon Black Cloud sensor installed after a lab test, but prevention is off and the console shows bypass or deregistered. What should the security administrator do?
- 911 CAD VMs have Carbon Black Cloud workload sensors, but automatic policy from vCenter tags never applies. UEM smart groups are healthy. What should the security administrator check?
- County iPhones are enrolled and compliant in Workspace ONE UEM, but Workspace ONE Access still denies apps with “device not compliant.” Carbon Black Cloud policy is unrelated. What should the security administrator check first?
- City Hub staging barcodes enroll new inspector Android devices into the wrong Organization Group, so security profiles never land. NSX-T is not in the path. What should the security administrator fix?
- Library Android tablets never form a work profile during Workspace ONE UEM enrollment. The gateway firewall already allows the UEM FQDNs. What should the security administrator check?
- Transit iOS restriction profiles fail to install on operator iPhones. Payload signing looks valid, but the MDM APNs certificate is expired. What restores profile delivery?
- Water-utility Windows laptops refuse Workspace ONE UEM MDM enrollment and report an existing third-party MDM authority. What should the security administrator do first?
- Courts attorneys cannot start the Workspace ONE Tunnel app; UEM shows the iPads non-compliant for missing passcode. The Tunnel server is healthy. What should the security administrator do first?
- School iPads flag as compromised (jailbreak) after a test IPA, so compliance fails. Identity Firewall is not involved. What should the security administrator do?
- Parks 802.1X certificate profiles fail because SCEP to the civic CA never completes. Carbon Black Cloud is healthy. What should the security administrator debug?
- Public-health Adaptive Access always fail-opens device posture after the Access connector VM is powered off. UEM still shows devices compliant. What restores posture-based denials?
- City SEG blocks Exchange from a laptop that UEM shows as compliant. The device token on SEG is stale. Distributed firewall is not in the mail path. What should the security administrator do?
- Elections iPad restriction profiles never apply. The assigned smart group criterion is Platform = Android. What should the security administrator fix?
- 911 Windows laptops received the Workspace ONE UEM BitLocker payload, but encryption compliance still fails because the recovery key did not escrow. What should the security administrator check?
- City kiosks on a guest VLAN with a walled garden show CB Defense sensors Offline and Intelligent Hub cannot enroll, even though NSX-T identity firewall groups look healthy. What should the security administrator open first?
- After a county perimeter firewall change, NSX-T Manager shows the vCenter compute manager as down and transport-node preparation stalls, while overlay VMs still enforce east-west Distributed Firewall. What should the administrator restore?
- A transit Workspace ONE Access connector stays disconnected from the Access tenant after the city proxy began SSL inspection. Outbound TCP 443 from the connector VM is permitted. What should the administrator check next?
- Library overlay VMs lose DNS after a resolver outage, and NSX-T FQDN-based Distributed Firewall context profiles stop matching even though IP/port rules still hit. What should the administrator restore first?
- Water-utility ESXi hosts and NSX-T Edge nodes are configured to send syslog to a SIEM, but no events arrive after a network change. Some nodes use UDP 514 and others use TLS TCP 6514. What should the administrator test first?
- Parks Endpoint Protection via Guest Introspection shows partner service VMs unhealthy. Transport nodes are prepared and Distributed Firewall Application policy is unchanged, but the service insertion network cannot ping the partner SVM. What should the administrator fix first?
- Public-health Workspace ONE UEM cannot reach the on-premises CA or LDAP after a datacenter ACL change. The cloud UEM console itself is healthy. What should the administrator trace?
- City laptops on VPN show Carbon Black Cloud sensors Offline. The split-tunnel include list carries only RFC1918, and a VPN client firewall drops non-tunneled destinations that are not listed. Carbon Black Cloud FQDNs were never added. What should the administrator change?
- Elections NSX Intelligence no longer publishes Distributed Firewall recommendations. The Intelligence appliance is powered on, but it cannot reach the NSX-T Managers on the management network. What should the administrator restore?
- A county on-premises NSX-T Manager cluster has tight Distributed Firewall policy. Workloads in a VMware Cloud SDDC with its own NSX-T instance remain any-any. An engineer added those cloud VMs to an on-premises NSX group. What should the administrator conclude?
- A city Carbon Black Cloud org lists only on-premises endpoints. Azure IaaS VMs that run the same line-of-business apps never appear, even though NSX-T Distributed Firewall is healthy in the on-premises SDDC. What should the administrator do?
- Transit Workspace ONE Access policies that should restrict a cloud SaaS to the operations network now match any after the agency moved those operators onto a public-cloud desktop pool. The pool egresses through a new NAT prefix that was never added as an Access network range. What should the administrator update?
- A water-utility uses a public-cloud directory as the Workspace ONE Access identity provider, while NSX-T identity firewall still binds on-premises Active Directory. The same operator is in SCADA-Operators in AD and scada-ops in the cloud directory, so Access and IDFW disagree on who may reach a jump VM. What should the administrator do?
- School-issued laptops are Intelligent Hub managed. Teachers roam into a cloud VDI desktop that is not an NSX-T prepared workload. Staff report Hub still blocks SaaS when compliance fails, and they expect the on-premises Distributed Firewall to follow the laptop into the cloud VDI. What should the administrator explain?
- Parks disaster-recovery VMs in a public-cloud region show Carbon Black Cloud sensors Offline. On-premises sensors are fine. The region's cloud security groups allow only management RDP and SSH and never listed CBC SaaS FQDNs. What should the administrator update?
- Public-health on-premises NSX-T uses a default-deny Distributed Firewall. The agency's cloud SDDC still has any-any on its NSX-T instance. Auditors ask why production-like workloads are wide open in the cloud. What should the administrator flag?
- City Workspace ONE Access uses a hybrid LDAP bind from the cloud tenant through ExpressRoute to on-premises domain controllers. After a WAN flap, directory sync fails. An engineer wants to regenerate IdP metadata immediately. What should the administrator check first?
- County overlay workloads black-hole large packets after a ToR change. Geneve-encapsulated frames are dropped, and NSX-T security looks down even though Manager and Distributed Firewall rules are unchanged. Underlay MTU on the new ToR is 1500. What should the administrator fix?
- Transit north-south traffic never hits the NSX-T gateway firewall after a core-switch change. East-west Distributed Firewall still works. The Edge uplink VLAN is missing from the physical trunk toward the Edge host. What should the administrator fix?
- A library ESXi host's overlay TEP flaps, and Distributed Firewall realization on that host flaps with it. vmkping to other TEPs drops whenever one member of the physical NIC team errors. What should the administrator inspect first?
- Water-utility NSX-T overlay on a VLAN goes silent after a spanning-tree reconvergence. The LAN team reports that VLAN in a Blocking state on the ToR toward the transport nodes. Distributed Firewall configuration is unchanged. What should the administrator do?
- Courts NSX-T Manager syslog and Carbon Black Cloud check-ins through an on-premises proxy both stall after a core hardware firewall change. Overlay east-west Distributed Firewall still hits. Packet captures stop at the core firewall, which now rate-limits and ACLs those destinations. What should the administrator identify?
- A school IDF access switch enters a PoE reboot loop, taking down the management VLAN for a small vSphere cluster. NSX-T Manager cannot reach those hosts, and an operator starts deleting Distributed Firewall rules to un-stick the cluster. What should the administrator do?
- Parks on-premises DNS appliances fail. Workspace ONE Access connector sync, Carbon Black Cloud sensor name resolution, and NSX-T FQDN-based Distributed Firewall all break in the same window. Three product teams want to rebuild their stacks. What should the administrator restore first?
- The 911 center's GPS NTP clock fails. Within hours, Workspace ONE Access tokens, TLS certificates on NSX-T Manager, and identity-firewall time windows all skew. Operators propose rewriting IDFW groups. What should the administrator restore?