Exam 3V0-12.26 Topic 1 Question 42 Discussion

Actual exam question for VMware's 3V0-12.26 exam
Question #: 42
Topic #: 1
A national cyber-defense enterprise operates a VMware Cloud Foundation (VCF) environment with strict organization isolation based solely on Virtual Private Cloud (VPC) constructs. They have been recently audited, and some new requirements were presented:
* Zero lateral movement between VPCs at both Layer 2 and Layer 3.
* No shared security objects between tenants.
* Strict identity-based access segregation for all VCF Automation API consumers.
* All enforcement must remain local to each VPC.
Which two design decisions correctly address the design trait of security based on the new requirements?
(Choose two.)

Suggested Answer: B,C Vote an answer

B addresses the network-isolation requirement by keeping security-policy enforcement within the individual VPC boundary . VMware VPCs are designed as isolated networking and security domains in which tenant administrators can maintain VPC-specific firewall and networking policies. NSX VPC security provides distributed firewalling and microsegmentation close to workload interfaces, allowing east-west traffic to be restricted without depending on a shared tenant security object. Broadcom describes VPC administrators ' network and security policies as contained within their VPC and not affecting other VPCs. ( VMware Blogs ) C addresses identity isolation. VCF Automation organizations provide independent administrative and access- control boundaries, and each organization can configure its Identity Provider connection and organization- specific users/groups . This enables API consumers to authenticate within the appropriate organizational identity scope instead of sharing credentials or tenant identities.
A introduces shared provider-managed security constructs, conflicting with the no-shared-security-objects requirement. D concerns IP-address efficiency rather than zero-trust enforcement. E introduces shared routing infrastructure and depends on route filtering rather than enforcing isolation directly at each VPC boundary.
Study Guide References/Topics: VCF VPC Security Architecture; VPC Isolation; Distributed Firewall and Microsegmentation; VCF Automation Organizations; IAM and Identity Provider Integration; Zero-Trust Tenant Design.

by Barlow at Oct 05, 2026, 12:32 PM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10