The Power BI data analyst delivers actionable insights by
leveraging available data and applying domain expertise. The Power BI data
analyst collaborates with key stakeholders across verticals to identify business
requirements, cleans and transforms the data, and then designs and builds data
models by using Power BI. The Power BI data analyst provides meaningful business
value through easy-to-comprehend data visualizations, enables others to perform
self-service analytics, and deploys and configures solutions for consumption.
Candidates for this exam should be proficient using Power Query and writing
expressions by using DAX.
Exam PL-300: Microsoft Power BI Data Analyst
Languages: English
Retirement date: none
This exam measures your ability to accomplish the following technical tasks:
prepare the data; model the data; visualize and analyze the data; and deploy and
maintain assets.
Skills measured Prepare the data (15-20%)
Model the data (30-35%)
Visualize and analyze the data (25-30%)
Deploy and maintain assets (20-25%)
NOTE: The bullets that appear below each of the skills measured are intended to
illustrate how we are assessing that skill. This list is NOT definitive or
exhaustive.
NOTE: Most questions cover features that are General Availability (GA). The exam
may contain questions on Preview features if those features are commonly used.
Prepare the Data (15-20%)
Get data from different data sources identify and connect to a data source
change data source settings
select a shared dataset or create a local dataset
select a storage mode
use Microsoft Dataverse
change the value in a parameter
connect to a data flow
Clean, transform, and load the data profile the data
resolve inconsistencies, unexpected or null values, and data quality issues
identify and create appropriate keys for joins
evaluate and transform column data types
shape and transform tables
combine queries
apply user-friendly naming conventions to columns and queries
configure data loading
resolve data import errors
Model the Data (30—35%)
Design a data model
define the tables
configure table and column properties
design and implement role-playing dimensions
define a relationship's cardinality and cross-filter direction
design a data model that uses a star schema
create a common date table
Develop a data model
create calculated tables
create hierarchies
create calculated columns
implement row-level security roles
use the Q&A feature
Create model calculations by using DAX create basic measures by using DAX
use CALCULATE to manipulate filters
implement Time Intelligence using DAX
replace implicit measures with explicit measures
use basic statistical functions
create semi-additive measures
use quick measures
Optimize model performance remove unnecessary rows and columns
identify poorly performing measures, relationships, and visuals
reduce cardinality levels to improve performance
Visualize and Analyze the Data (25—30%)
Create reports
add visualization items to reports
choose an appropriate visualization type
format and configure visualizations
use a custom visual
apply and customize a theme
configure conditional formatting
apply slicing and filtering
configure the report page
use the Analyze in Excel feature
choose when to use a paginated report
Create dashboards manage tiles on a dashboard
configure mobile view
use the Q&A feature
add a Quick Insights result to a dashboard
apply a dashboard theme
pin a live report page to a dashboard
Enhance reports for usability and storytelling
configure bookmarks
create custom tooltips
edit and configure interactions between visuals
configure navigation for a report
apply sorting
configure Sync Slicers
group and layer visuals by using the selection pane
drilldown into data using interactive visuals
export report data
design reports for mobile devices
Identify patterns and trends
use the Analyze feature in Power BI
identify outliers
choose between continuous and categorical axes
use groupings, binnings, and clustering
use AI visuals
use the Forecast feature
create reference lines by using the Analytics pane
Deploy and Maintain Assets (20—25%)
Manage files and datasets
identify when a gateway is required
configure a dataset scheduled refresh
configure row-level security group membership
provide access to datasets
manage global options for files
Manage workspaces create and configure a workspace
assign workspace roles
configure and update a workspace app
publish, import, or update assets in a workspace
apply sensitivity labels to workspace content
configure subscriptions and data alerts
promote or certify Power BI content
Exam Description: Implementing Cisco Enterprise Network Core Technologies v1.0 (ENCOR 350-401)
is a 120-minute exam associated with the CCNP and CCIE Enterprise
Certifications. This exam tests a candidate's knowledge of implementing core
enterprise network technologies including dual stack (IPv4 and IPv6)
architecture, virtualization, infrastructure, network assurance, security and
automation. The course, Implementing Cisco Enterprise Network Core Technologies,
helps candidates to prepare for this exam.
The following topics are general guidelines for the content likely to be
included on the exam. However, other related topics may also appear on any
specific delivery of the exam. To better reflect the contents of the exam and
for clarity purposes, the guidelines below may change at any time without
notice.
15% 1.0 Architecture 1.1 Explain the different design principles used in an enterprise
network
1.1.a Enterprise network design such as Tier 2, Tier 3, and Fabric Capacity
planning
1.1.b High availability techniques such as redundancy, FHRP, and SSO
1.2 Analyze design principles of a WLAN deployment
1.2.a Wireless deployment models (centralized, distributed, controller-less,
controller based, cloud, remote branch)
1.2.b Location services in a WLAN design
1.3 Differentiate between on-premises and cloud infrastructure deployments
1.4 Explain the working principles of the Cisco SD-WAN solution
1.4.a SD-WAN control and data planes elements
1.4.b Traditional WAN and SD-WAN solutions
1.5 Explain the working principles of the Cisco SD-Access solution
1.5.a SD-Access control and data planes elements
1.5.b Traditional campus interoperating with SD-Access
1.6 Describe concepts of wired and wireless QoS
1.6.a QoS components
1.6.b QoS policy
1.7 Differentiate hardware and software switching mechanisms
1.7.a Process and CEF
1.7.b MAC address table and TCAM
1.7.c FIB vs. RIB
10% 2.0 Virtualization
2.1 Describe device virtualization technologies
2.1.a Hypervisor type 1 and 2
2.1.b Virtual machine
2.1.c Virtual switching
2.2 Configure and verify data path virtualization technologies
2.2.a VRF
2.2.b GRE and IPsec tunneling
2.3 Describe network virtualization concepts
2.3.a LISP
2.3.b VXLAN
30% 3.0 Infrastructure
3.1 Layer 2
3.1.a Troubleshoot static and dynamic 802.1q trunking protocols
3.1.b Troubleshoot static and dynamic EtherChannels
3.1.c Configure and verify common Spanning Tree Protocols (RSTP and MST)
3.2 Layer 3
3.2.a Compare routing concepts of EIGRP and OSPF (advanced distance vector
vs. link state, load balancing, path selection, path operations, metrics)
3.2.b Configure and verify simple OSPF environments, including multiple
normal areas, summarization, and filtering (neighbor adjacency,
point-to-point and broadcast network types, and passive interface)
3.2.c Configure and verify eBGP between directly connected neighbors (best
path selection algorithm and neighbor relationships)
3.3 Wireless
3.3.a Describe Layer 1 concepts, such as RF power, RSSI, SNR, interference
noise, band and channels, and wireless client devices capabilities
3.3.b Describe AP modes and antenna types
3.3.c Describe access point discovery and join process (discovery
algorithms, WLC selection process)
3.3.d Describe the main principles and use cases for Layer 2 and Layer 3
roaming
3.3.e Troubleshoot WLAN configuration and wireless client connectivity
issues
3.4 IP Services
3.4.a Describe Network Time Protocol (NTP)
3.4.b Configure and verify NAT/PAT
3.4.c Configure first hop redundancy protocols, such as HSRP and VRRP
3.4.d Describe multicast protocols, such as PIM and IGMP v2/v3
10% 4.0 Network Assurance 4.1 Diagnose network problems using tools such as debugs, conditional
debugs, trace route, ping, SNMP, and syslog
4.2 Configure and verify device monitoring using syslog for remote logging
4.3 Configure and verify NetFlow and Flexible NetFlow
4.4 Configure and verify SPAN/RSPAN/ERSPAN
4.5 Configure and verify IPSLA
4.6 Describe Cisco DNA Center workflows to apply network configuration,
monitoring, and management
4.7 Configure and verify NETCONF and RESTCONF
20% 5.0 Security 5.1 Configure and verify device access control
5.1.a Lines and password protection
5.1.b Authentication and authorization using AAA
5.2 Configure and verify infrastructure security features
5.2.a ACLs
5.2.b CoPP
5.3 Describe REST API security
5.4 Configure and verify wireless security features
5.4.a EAP
5.4.b WebAuth
5.4.c PSK
5.5 Describe the components of network security design
5.5.a Threat defense
5.5.b Endpoint security
5.5.c Next-generation firewall
5.5.d TrustSec, MACsec
5.5.e Network access control with 802.1X, MAB, and WebAuth
15% 6.0 Automation
6.1 Interpret basic Python components and scripts
6.2 Construct valid JSON encoded file
6.3 Describe the high-level principles and benefits of a data modeling
language, such as YANG
6.4 Describe APIs for Cisco DNA Center and vManage
6.5 Interpret REST API response codes and results in payload using Cisco DNA
Center and RESTCONF
6.6 Construct EEM applet to automate configuration, troubleshooting, or data
collection
6.7 Compare agent vs. agentless orchestration tools, such as Chef, Puppet,
Ansible, and SaltStack
QUESTION 1 What is the difference between a RIB and a FIB?
A. The FIB is populated based on RIB content.
B. The RIB maintains a mirror image of the FIB.
C. The RIB is used to make IP source prefix-based switching decisions.
D. The FIB is where all IP routing information is stored.
Answer: A
QUESTION 2 Which QoS component alters a packet to change the way that traffic is
treated in the network?
A. policing
B. classification
C. marking
D. shaping
Answer: C
QUESTION 3 Which statement about Cisco Express Forwarding is true?
A. The CPU of a router becomes directly involved with packet-switching
decisions.
B. It uses a fast cache that is maintained in a router data plane.
C. It maintains two tables in the data plane: the FIB and adjacency table.
D. It makes forwarding decisions by a process that is scheduled through the IOS
scheduler.
Answer: C
QUESTION 4 What is a benefit of deploying an on-premises infrastructure versus a cloud
infrastructure deployment?
A. ability to quickly increase compute power without the need to install
additional hardware
B. less power and cooling resources needed to run infrastructure on-premises
C. faster deployment times because additional infrastructure does not need to be
purchased
D. lower latency between systems that are physically located near each other
Candidates for this exam implement solutions that provide insights
into customer profiles and that track engagement activities to help improve
customer experiences and increase customer retention.
Candidates should have firsthand experience with Dynamics 365 Customer Insights
and one or more additional Dynamics 365 apps, Power Query, Microsoft Dataverse,
Common Data Model, and Microsoft Power Platform. They should also have direct
experience with practices related to privacy, compliance, consent, security,
responsible AI, and data retention policy.
Candidates need experience with processes related to KPIs, data retention,
validation, visualization, preparation, matching, fragmentation, segmentation,
and enhancement. They should have a general understanding of Azure Machine
Learning, Azure Synapse Analytics, and Azure Data Factory.
Important
NOTE: Passing score: 700. Learn more about exam scores here. Beta exams are not
scored immediately because we are gathering data on the quality of the questions
and the exam. Learn more about the value and importance of beta exams.
Part of the requirements for: Microsoft Certified: Customer Data Platform
Specialty
Related exams: none
Important: See details
Go to Certification Dashboard
Languages: English
Retirement date: none
This exam measures your ability to accomplish the following technical tasks:
design Customer Insights solutions; ingest data into Customer Insights; create
customer profiles by unifying data; implement artificial intelligence
predictions in Customer Insights; configure measures and segments; configure
third-party connections; and administer Customer Insights.
Skills measured
Design Customer Insights solutions (5-10%)
Ingest data into Customer Insights (10-15%)
Create customer profiles by unifying data (20-25%)
Implement AI predictions in Customer Insights (10-15%)
Configure measures and segments (15-20%)
Configure third-party connections (10-15%)
Administer Customer Insights (5-10%)
NOTE: Passing score: 700. Learn more about exam scores here.
Audience Profile
Candidates for this exam implement solutions that provide insights into customer
profiles and that track engagement activities to help improve customer
experiences and increase customer retention.
Candidates should have firsthand experience with Dynamics 365 Customer Insights
and one or more additional Dynamics 365 apps, Power Query, Microsoft Dataverse,
Common Data Model, and Microsoft Power Platform. They should also have direct
experience with practices related to privacy, compliance, consent, security,
responsible AI, and data retention policy. Candidates need experience with
processes related to KPIs, data retention, validation, visualization,
preparation, matching, fragmentation, segmentation, and enhancement. They should
have a general understanding of Azure Machine Learning, Azure Synapse Analytics,
and Azure Data Factory.
Skills Measured NOTE: The bullets that follow each of the skills measured are intended to
illustrate how we are assessing that skill. This list is NOT definitive or
exhaustive.
NOTE: Most questions cover features that are general availability (GA). The exam
may contain questions on Preview features if those features are commonly used.
Design Customer Insights solutions (5-10%)
Describe Customer Insights describe audience insights components, including entities, relationships,
activities, measures, and segments
analyze Customer Insights data by using Azure Synapse Analytics
describe the process for consuming engagement insights data in audience
insights
describe support for near real-time updates
describe support for enrichment
Describe use cases for Customer Insights describe use cases for audience insights
differentiate between audience insights and engagement insights
describe use cases for creating reports by using Customer Insights
describe use cases for extending Customer Insights by using Microsoft Power
Platform components
describe use cases for Customer Insights APIs
Ingest data into Customer Insights (10-15%)
Connect to data sources determine which data sources to use
determine whether to use the managed data lake or an organization’s data lake
connect to Microsoft Dataverse
connect to Common Data Model folders
ingest data from Azure Synapse Analytics
ingest data by using Azure Data Factory pipelines
Transform, cleanse, and load data by using Power Query select tables and columns
resolve data inconsistencies, unexpected or null values, and data quality
issues
evaluate and transform column data types
apply data shape transformations to tables
Configure incremental refreshes for data sources
identify data sources that support incremental updates
identify capabilities and limitations for scheduled refreshes
configure scheduled refreshes and on-demand refreshes
trigger refreshes by using Power Automate or the Customer Insights API
Create customer profiles by unifying data (20-25%)
Implement mapping select Customer Insights entities and attributes for matching
select attribute types
Implement matching specify a match order for entities
define match rules
configure normalization options
differentiate between low, medium, high, exact, and custom precision methods
configure deduplication
run a match process and review results
Implement merges
specify the order of fields for merged tables
combine fields into a merged field
separate fields from a merged field
exclude fields from a merge
run a merge and review results
Configure search and filter indexes define which fields should be searchable
define filter options for fields
define indexes
Configure relationships and activities
create and manage relationships
create activities by using a new or existing relationship
manage activities
Implement AI predictions in Customer Insights (10-15%)
Configure prediction models configure and evaluate the customer churn models, including the
transactional churn and subscription churn models
configure and evaluate the product recommendation model
configure and evaluate the customer lifetime value model
Impute missing values by using predictions describe processes for predicting missing values
implement the missing values feature
Implement machine learning models describe prerequisites for using custom Azure Machine Learning models in
Customer Insights
implement workflows that consume machine learning models
manage workflows for custom machine learning models
Configure measures and segments (15-20%)
Create and manage measures describe the different types of measures
create a measure
create a measure by using a template
configure measure calculations
modify dimensions
Create segments describe methods for creating segments, including blank segments
create a segment from customer profiles, measures, or AI predictions
find similar customers
Find suggested segments describe how the system suggests segments for use
create a segment from a suggestion
configure refreshes for suggestions
Create segment insights
configure overlap segments
configure differentiated segments
analyze insights
Configure third-party connections (10-15%)
Configure connections and exports configure a connection for exporting data
create a data export
schedule a data export
Export data to Dynamics 365 Marketing or Dynamics 365 Sales
identify prerequisites for exporting data from Customer Insights
create connections between Customer Insights and Dynamics 365 apps
define which segments to export
export a Customer Insights segment into Dynamics 365 Marketing as a marketing
segment
export a Customer Insights profile into Dynamics 365 Marketing for customer
journey orchestration
export a Customer Insights segment into Dynamics 365 Sales as a marketing list
Display Customer Insights data from within Dynamics 365 apps identify Customer Insights data that can be displayed within Dynamics 365
apps
configure the Customer Card Add-in for Dynamics 365 apps
identify permissions required to implement the Customer Card Add-in for
Dynamics 365 apps
Administer Customer Insights (5-10%)
Create and configure environments identify who can create environments
differentiate trial and production environments
manage existing environments
describe available roles
configure user permissions and guest user permissions
Manage system refreshes differentiate between system refreshes and data source refreshes
describe refresh policies
configure a system refresh schedule
monitor and troubleshoot refreshes
QUESTION 1
You are a Customer Data Platform Specialist. You need to create relationships to connect entities so that they
can be further used in defining segments and measures by the marketing team.
Which three relationship types are available in audience insights?
Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
A. Non-editable system relationships, created by the system as part of the data unification process
B. Non-editable system relationships, which are created automatically from ingesting data sources
C. Editable inherited relationships, created by the system as part of the data unification process
D. Editable custom relationships, created and configured by users
E. Non-editable inherited relationships, which are created automatically from ingesting data sources
QUESTION 2
You are a Customer Data Platform Specialist. Your company operates mainly in the business-to-business
(B2B) space.
The chief marketing officer (CMO) asks you to implement audience insights and ensure that it can handle the
company's B2B scenarios and data.
Which statement is correct when considering audience insights for business accounts versus individual
consumers?
A. The out-of-the-box product recommendation prediction model is available for business accounts.
B. Data ingestion features are different for business accounts and individual customers.
C. Some enrichment types are available only for individual customer scenarios, while others are exclusively
available for business accounts.
D. Business accounts and individual consumers share the same audience insights environment.
QUESTION 3
You are a Customer Data Platform Specialist. Your company's chief marketing officer (CMO) learns about
Dynamics 365 Customer Insights engagement insights capability. Your CMO wants to understand how
engagement insights can be used to enhance audience insights.
Which two statements describe the benefits of engagement insights? Each correct answer presents part of the
solution.
NOTE: Each correct selection is worth one point.
A. It allows you to collect, measure, and understand customer behavior on your website.
B. It allows you to create new customer profiles within engagement insights that can be exported to audience
insights.
C. It allows you to send new customer leads directly to a marketing automation platform.
D. It allows you to link audience insights and engagement insights environments to enable bidirectional data
flow.
Exam ID : HPE2-T37
Exam type : Web based
Exam duration : 1 hour
Exam length : 40 questions
Passing score : 70%
Delivery language's : English
Register for this Exam You need an HPE Learner ID and a Pearson VUE login and password.
No reference material is allowed at the testing site. This exam may contain beta
test items for experimental purposes.
Exam description
This certification tests candidates' knowledge and skills on designing,
deploying, and operating the HPE OneView management suite as the management and
provisioning control plane for HPE products and solutions.
Ideal candidate for this exam HPE customers, partners, and employees who
configure, implement, support, and use OneView to manage HPE Hybrid IT
solutions. The minimally qualified candidate will have basic industry standard
storage, server and networking skills. They will have familiarity with the HPE
Hybrid IT product portfolio.
Exam contents This exam has 40 questions. Here are types of questions to expect: Matching
Multiple choice (multiple responses)
Multiple choice (single response)
Drag-and-drop
Point and click
Advice to help you take this exam Complete the training and review all course materials and documents before
you take the exam.
Use HPE Press study guides and additional reference materials; study guides,
practice tests, and HPE books.
Exam items are based on expected knowledge acquired from job experience, an
expected level of industry standard knowledge, or other prerequisites (events,
supplemental materials, etc.).
Successful completion of the course or study materials alone, does not ensure
you will pass the exam.
Percentage of Exam
2% Describe industry standard data center infrastructure management technologies
13% Describe HPE OneView and its elements and positioning for customer business
outcomes
15% Architect and design a data center management solution using the HPE OneView
27% Install and configure HPE OneView and related elements
24% Provision Hybrid IT infrastructure using HPE OneView
11% Manage and report on Hybrid IT infrastructure using HPE OneView
8% Monitor and troubleshoot common Hybrid IT infrastructure issues using HPE
OneView
QUESTION 1 Your customer asks you if it possible to perform HPE Synergy initial setup
remotely.
How should you respond?
A. Remote HPE Synergy setup is possible if HPE Composer 2 is used and a DHCP
server is available in the management network
B. HPE Synergy can be configured remotely through a secure connection to the FLM
if this option was enabled in the factory
C. HPE Synergy cannot be deployed remotely, as initial setup must be performed
using a local console connection
D. Remote HPE Synergy installation can be done only if an additional set of the
services was purchased together with hardware platform
Answer: B
QUESTION 2 Your customer built a server profile for HPE Synergy Gen10 server and
configured boot mode to Legacy BIOS.
Which feature is not available for this Compute Module?
A. Boot from SAN
B. Secure boot
C. Workload profile
D. BIOS management
Answer: A
QUESTION 3 How can your customer implement HPE OneView so that it can be used to manage
an HPE ProLiant server and HPE BladeSystem?
A. As a virtual appliance running on the supported hypervisor
B. As an application running on the server with CentOS Linux system
C. As an application running on the server with Windows system
D. As a physical appliance based on HPE ProLiant 360 Gen10
Fortinet NSE 7 - OT Security 6.4
Exam series: NSE7_OTS-6.4
Number of questions: 35
Exam time: 60 minutes
Language: English
Product version: FortiOS 6.4
Status: Available
NSE 7 Network Security Architect—OT Security
NSE 7 Certification The Fortinet Network Security Architect designation identifies your advanced
skills in deploying, administering, and troubleshooting Fortinet security
solutions. We recommend this certification for network and security
professionals who are involved in the advanced administration and support of
security infrastructures using Fortinet solutions. Visit the Fortinet NSE
Certification Program page for information about certification requirements.
Fortinet NSE 7—OT Security 6.4 The Fortinet NSE 7—OT Security 6.4 exam is part of the NSE 7 Network
Security Architect program, and recognizes the successful candidate’s knowledge
of and expertise with the Fortinet products in an OT environment.
The exam tests applied knowledge of the design, implementation, operation, and
integration of an OT security
solution comprising FortiOS 6.4.3, FortiAnalyzer 6.4.3, FortiSIEM 5.3.1, and
FortiNAC 8.5.
Audience The Fortinet NSE 7—OT Security 6.4 exam is intended for network and security
professionals responsible for designing and implementing infrastructure
containing many Fortinet devices.
Exam Details Exam name Fortinet NSE 7—OT Security 6.4
Exam series NSE7_OTS-6.4
Time allowed 60 minutes
Exam Description
Exam questions 35 multiple-choice questions
Scoring Pass or fail, a score report is available from your Pearson VUE account
Language English
Product version FortiOS 6.4.3, FortiAnalyzer 6.4.3, FortiSIEM 5.3.1, FortiNAC
8.5
Exam Topics
Successful candidates have applied knowledge and skills in the following areas
and tasks:
* Asset Management
* Explain the OT architecture with Fortinet products
* Configure the security fabric for OT network
* Implement device detection with FortiGate
* Explain network visibility with FortiNAC
* Network access control
* Explain role-based authentication
* Apply authentication to control access to devices
* Explain industrial Ethernet protocols
* Explain internal segmentation implementation for OT networks
* Protecting OT network
* Identify industrial protocols and signatures
* Implement IPS to secure OT networks
* Implement application control for industrial applications
* Monitoring and risk assessment
* Implement logging and monitoring with FortiAnalyzer and FortiSIEM
* Explain FortiSIEM rules and incidents
* Customize and generate reports with FortiAnalyzer and FortiSIEM
* Build OT security dashboard with FortiSIEM
Training Resources
The following resources are recommended for attaining the knowledge and skills
that are covered on the exam. The recommended training is available as a
foundation for exam preparation. In addition to training, candidates are
strongly encouraged to have hands-on experience with the exam topics and
objectives.
Other Resources
* FortiOS Administration Guide 6.4.3
* FortiOS CLI Reference 6.4.3
* FortiAnalyzer Administration Guide 6.4.3
* FortiSIEM User Guide 5.3.1
* FortiNAC Administration and Operation Guide 8.5
Experience l Familiarity with design, implementation, and integration of the Fortinet
solution in an OT infrastructure
Exam Sample Questions A set of sample questions is available from the NSE Training Institute.
These questions sample the exam content in question type and content scope.
However, the questions do not necessarily represent all the exam content, nor
are they intended to assess an individual’s readiness to take the certification
exam.
See the NSE Training Institute for the course that includes the sample
questions.
Examination Policies and Procedures The NSE Training Institute recommends that candidates review exam policies
and procedures before registering for the exam. Access important information on
the Program Policies page, and find answers to common questions on the
FAQ page.
QUESTION 1
What are two benefits of a Nozomi integration with FortiNAC? (Choose two.)
A. Enhanced point of connection details
B. Direct VLAN assignment
C. Adapter consolidation for multi-adapter hosts
D. Importation and classification of hosts
QUESTION 2
Which three criteria can a FortiGate device use to look for a matching firewall policy to process traffic?
(Choose three.)
A. Services defined in the firewall policy.
B. Source defined as internet services in the firewall policy
C. Lowest to highest policy ID number
D. Destination defined as internet services in the firewall policy
E. Highest to lowest priority defined in the firewall policy
EXAM NUMBER : 2V0-81.20
PRODUCT : NSX-T Data Center 3.0, Workspace ONE 20.X, VMware Carbon Black Cloud
EXAM LANGUAGE : English
Associate Certifications : VCP-SEC 2021
EXAM OVERVIEW : This exam tests a candidate's knowledge of VMware's security solutions and
the candidate's ability to administer the security features and functions of NSX-T
Data Center, Workspace ONE, and VMware Carbon Black Cloud.
Exam Info Duration : 130 minutes
Number of Questions : 70
Passing Score : 300 Learn more
Format : Multiple Choice, Multiple Choice Multiple Selection, Drag and Drop,
Matching
Exam Details: (Last Updated: 10/7/2020) The Professional VMware Security exam (2V0-81.20)
which leads to VMware Certified Professional – Security 2021 certification is a
70-itemexam, with a passing score of 300 using a scaled scoring method.
Candidates are given 130 minutes to complete the exam, which includes adequate
time to complete the exam for non-native English speakers.
Exam Delivery : This is a proctored exam delivered through Pearson VUE. For more
information, visit the Pearson VUE website.
Certification Information : For details and a complete list of requirements and recommendations for
attainment, please reference the VMware Education Services –Certification
website.
Minimally Qualified : Candidate The minimally qualified candidate (MQC) possesses knowledge of
vSphere, networking, and endpoint security. The MQC can explain VMware Security
key features and functionality. The MQC can describe VMware's Security
architecture concepts. The MQC can explain the primary security features of
VMware Carbon Black Cloud, NSX-T Data Center, and Workspace ONE, and how these
VMware products interoperate with each other to deliver an intrinsic security
solution. The MQC can describe use cases for VMware Security to others. The MQC
has a minimum of 6 months hands-on experience configuring and managing VMware
Security solutions and 1 year of experience working directly with VMware Carbon
Black Cloud, NSX-T Data Center, and Workspace ONE. The MQC must possess all the
knowledge contained in the sections included in this exam.
Exam Sections: VMware exam blueprint sections are now standardized to the seven sections
below, some of which may NOT be included in the final exam blueprint depending
on the exam objectives.
Section 1 – Architecture and Technologies
Section 2 – Products and Solutions
Section 3 – Planning and Designing
Section 4 – Installing, Configuring, and Setup
Section 5 – Performance-tuning, Optimization, and Upgrades
Section 6 – Troubleshooting and Repairing
Section 7 – Administrative and Operational Tasks
If a section does not have testable objectives in this version of
the exam, it will be noted below, accordingly. The objective numbering may be
referenced in your score report at the end of your testing event for further
preparation should a retake of the exam be necessary.
Sections Included in this Exam
Section 1 – There are no testable objectives for this section.
Section 2 – There are no testable objectives for this section.
Section 3 – There are no testable objectives for this section.
Section 4 – Installing, Configuring, and Setting
Objective 4.1 – Configure firewall rules to enable and secure
Workspace ONE Components
Objective 4.2 –Configure and manage security groups and security policies in
Carbon Black
Objective 4.3 –Configure compliance policies and profiles in Workspace ONE UEM
Objective 4.4 –Configure access policies in Workspace ONE Access
Objective 4.5 –Configure and administer endpoint management
Objective 4.6 –Deploy CB Defense sensors to endpoints
Objective 4.7 –Configure and administer identity providers in Workspace ONE
Access
Objective 4.8 –Configure and administer authentication methods in Workspace
ONE Access
Objective 4.9 –Deploy and configure NSX-T
Objective 4.10 –Outline the installation and preparation workflow of NSX-T
data center
Objective 4.11 –Configure and manage firewalls rules for NSX-T
Objective 4.12 –Connect NSX-T Manager to User Directory for user based
firewall rules
Objective 4.13 –Configure and manage security groups and security policies in
NSX-T
Objective 4.14 –Install and configure Guest Introspection agent components in
VMTools
Section 5 –
Section 6 – Troubleshooting and Repairing
Objective 6.1 –Compare and contrast tools available for
troubleshooting (vRNI vs NSX Intelligence)
Objective 6.2 –Troubleshoot common NSX component issues
Objective 6.2.1 –Troubleshoot common NSX installation and
configuration issues
Objective 6.2.2 –Troubleshoot common NSX firewall policy issues
Objective 6.3 –Troubleshoot common Carbon Black issues
Objective 6.4 –Troubleshoot Workspace ONE issues around endpoint security
Objective 6.5 –Troubleshoot connectivity issues
Objective 6.6 –Troubleshoot multi-cloud security issues
Objective 6.7 –Troubleshoot common physical infrastructure issues
Section 7 – Administrative and Operational Tasks
Objective 7.1 – Identify data center traffic flows
Objective 7.2 – Identify automation mechanisms for security policy
configuration
Objective 7.3 – Manage firewall policies
Objective 7.4 – Monitor security for compliance and regulation assurance
Objective 7.5 – Manage security policies for business continuity and disaster
recovery
Objective 7.6 – Perform patch management in Workspace ONE
Objective 7.7 – Manage access policies for Single Sign-On and third party
Identity Provider federation
Recommended Courses NSX-T Data Center Install, Config, Manage [3.X]
Workspace ONE Deploy and Manage [20.X]]
VMware Carbon Black Cloud Audit and Remediation
VMware Carbon Black Cloud Endpoint Standard
VMware Carbon Black Cloud Enterprise EDR
References*
In addition to the recommended courses, item writers used the following
references for information when writing exam questions. It is recommended that
you study the reference content as you prepare to take the exam, in addition to
any recommended training.
QUESTION 1
Which file can be used to validate repcli authentication was enabled for Carbon Black Cloud?
A. C:\Program Files\Confer\repcii.ini
B. C:\Program Files\Confer\config.ini
C. C:\Program Files\Confer\cfg.ini
D. C:\Program Files\Confer\cli.ini
Answer: A
QUESTION 2
Which is the correct Distinguished Name for connecting NSX-T Data Center to Active Directory,
if your
directory name is corp. local?
A. corp. local
B. DC=corp. local
C. DC=corp, DC=local
D. DC=local, DC=corp
Answer: C
QUESTION 3
What are two valid time limit selections when creating a Last Seen compliance policy in Workspace ONE
UEM? (Choose two.)
A. Hours
B. Minutes
C. Days
D. Weeks
E. Months
Answer: B,C
QUESTION 4
Which is true about Time-Based Firewall Policy rules?
A. Time-Based policy rules apply only to the NSX Distributed Firewall.
B. Time-Based policy rules apply to the NSX Gateway and Distributed Firewall.
C. Time-Based policy rules can only be used one time for NSX Gateway Firewall.
D. Time-Based policy rules apply only to the NSX Gateway Firewall.
Candidates for this exam should have subject matter expertise in planning,
implementing, and maintaining Azure networking solutions, including hybrid
networking, connectivity, routing, security, and private access to Azure
services.
Candidates for this exam should also have expert Azure administration skills, in
addition to extensive experience and knowledge of networking, hybrid
connections, and network security.
Part of the requirements for: Microsoft Certified: Azure Network Engineer
Associate
Related exams: none
Important: See details
Go to Certification Dashboard
Exam AZ-700: Designing and Implementing Microsoft Azure Networking Solutions
Languages: English
Retirement date: none
This exam measures your ability to accomplish the following technical tasks:
design, implement, and manage hybrid networking; design and implement core
networking infrastructure; design and implement routing; secure and monitor
networks; and design and implement private access to Azure Services.
Skills measured
Design, implement, and manage hybrid networking (10-15%)
Design and implement core networking infrastructure (20-25%)
Design and implement routing (25-30%)
Secure and monitor networks (15-20%)
Design and implement Private access to Azure Services (10-15%)
Related certifications
There may be certifications and prerequisites related to "Exam AZ-700: Designing
and Implementing Microsoft Azure Networking Solutions"
Microsoft Certified: Azure Network Engineer Associate
Related certification Candidates for the Azure Network Engineer Associate certification should
have subject matter expertise in planning, implementing, and maintaining Azure
networking solutions, including hybrid networking, connectivity, routing,
security, and private access to Azure services.
Exam resources : Training and certification guide
Explore all certifications in a concise training and certifications guide.
Certification poster
Check out an overview of fundamentals, role-based and specialty certifications.
Exam Replay
See two great offers to help boost your odds of success. Support for
certification exams
Get help through Microsoft Certification support forums. A forum moderator will
respond in one business day, Monday-Friday. Certification dashboard
Review and manage your scheduled appointments, certificates, and transcripts.
Request accommodations
Learn more about requesting an accommodation for your exam.
Audience Profile
Candidates for this exam should have subject matter expertise in planning,
implementing, and maintaining Azure networking solutions, including hybrid
networking, connectivity, routing, security, and private access to Azure
services.
Responsibilities for the Azure Network Engineer include recommending, planning,
and implementing Azure networking solutions. Professionals in this role manage
the solution for performance, resiliency, scale, and security. They deploy
networking solutions by using the Azure Portal and other methods, including
PowerShell, Azure Command-Line Interface (CLI), and Azure Resource Manager
templates (ARM templates). The Azure Network Engineer works with solution
architects, cloud administrators, security engineers, application developers,
and DevOps engineers to deliver Azure solutions.
Candidates for this exam should have expert Azure administration skills, in
addition to extensive experience and knowledge of networking, hybrid
connections, and network security.
Skills Measured NOTE: The bullets that follow each of the skills measured are intended to
illustrate how we’re assessing that skill. This list is not definitive or
exhaustive.
NOTE: Most questions cover features that are General Availability (GA). The exam
may contain questions on Preview features, if those features are commonly used.
Design, Implement, and Manage Hybrid Networking (10–15%)
Design, implement, and manage a site-to-site VPN connection design a site-to-site VPN connection for high availability
select an appropriate virtual network (VNet) gateway SKU
identify when to use policy-based VPN versus route-based VPN
create and configure a local network gateway
create and configure an IPsec/IKE policy
create and configure a virtual network gateway
diagnose and resolve VPN gateway connectivity issues
Design, implement, and manage a point-to-site VPN connection
select an appropriate virtual network gateway SKU
plan and configure RADIUS authentication
plan and configure certificate-based authentication
plan and configure OpenVPN authentication
plan and configure Azure Active Directory (Azure AD) authentication
implement a VPN client configuration file
diagnose and resolve client-side and authentication issues
Design, implement, and manage Azure ExpressRoute
choose between provider and direct model (ExpressRoute Direct)
design and implement Azure cross-region connectivity between multiple
ExpressRoute locations
select an appropriate ExpressRoute SKU and tier
design and implement ExpressRoute Global Reach
design and implement ExpressRoute FastPath
choose between private peering only, Microsoft peering only, or both
configure private peering
configure Microsoft peering
create and configure an ExpressRoute gateway
connect a virtual network to an ExpressRoute circuit
recommend a route advertisement configuration
configure encryption over ExpressRoute
implement Bidirectional Forwarding Detection
diagnose and resolve ExpressRoute connection issues
Design and Implement Core Networking Infrastructure (20–25%)
Design and implement private IP addressing for VNets create a VNet
plan and configure subnetting for services, including VNet gateways, private
endpoints, firewalls, application gateways, and VNet-integrated platform
services
plan and configure subnet delegation
Design and implement name resolution design public DNS zones
design private DNS zones
design name resolution inside a VNet
configure a public or private DNS zone
link a private DNS zone to a VNet
Design and implement cross-VNet connectivity design service chaining, including gateway transit
design VPN connectivity between VNets
implement VNet peering
Design and implement an Azure Virtual WAN architecture
design an Azure Virtual WAN architecture, including selecting SKUs and
services
connect a VNet gateway to Azure Virtual WAN
create a hub in Virtual WAN
create a network virtual appliance (NVA) in a virtual hub
configure virtual hub routing
create a connection unit Design and Implement Routing (25–30%) Design, implement, and manage VNet routing design and implement user-defined routes (UDRs)
associate a route table with a subnet
configure forced tunneling
diagnose and resolve routing issues
Design and implement an Azure Load Balancer
choose an Azure Load Balancer SKU (Basic versus Standard)
choose between public and internal
create and configure an Azure Load Balancer (including cross-region)
implement a load balancing rule
create and configure inbound NAT rules
create explicit outbound rules for a load balancer
Design and implement Azure Application Gateway
recommend Azure Application Gateway deployment options
choose between manual and autoscale
create a back-end pool
configure health probes
configure listeners
configure routing rules
configure HTTP settings
configure Transport Layer Security (TLS)
configure rewrite policies
Implement Azure Front Door
choose an Azure Front Door SKU
configure health probes, including customization of HTTP response codes
configure SSL termination and end-to-end SSL encryption
configure multisite listeners
configure back-end targets
configure routing rules, including redirection rules
Implement an Azure Traffic Manager profile configure a routing method (mode)
configure endpoints
create HTTP settings
Design and implement an Azure Virtual Network NAT
choose when to use a Virtual Network NAT
allocate public IP or public IP prefixes for a NAT gateway
associate a Virtual Network NAT with a subnet
Secure and Monitor Networks (15–20%)
Design, implement, and manage an Azure Firewall deployment design an Azure Firewall deployment
create and implement an Azure Firewall deployment
configure Azure Firewall rules
create and implement Azure Firewall Manager policies
create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN
hub
integrate an Azure Virtual WAN hub with a third-party NVA
Implement and manage network security groups (NSGs) create an NSG
associate an NSG to a resource
create an application security group (ASG)
associate an ASG to a NIC
create and configure NSG rules
interpret NSG flow logs
validate NSG flow rules
verify IP flow
Implement a Web Application Firewall (WAF) deployment
configure detection or prevention mode
configure rule sets for Azure Front Door, including Microsoft managed and user
defined
configure rule sets for Application Gateway, including Microsoft managed and
user defined
implement a WAF policy
associate a WAF policy
Monitor networks configure network health alerts and logging by using Azure Monitor
create and configure a Connection Monitor instance
configure and use Traffic Analytics
configure NSG flow logs
enable and configure diagnostic logging
configure Azure Network Watcher
Design and Implement Private Access to Azure Services (10–15%)
Design and implement Azure Private Link service and Azure Private Endpoint create a Private Link service
plan private endpoints
create private endpoints
configure access to private endpoints
integrate Private Link with DNS
integrate a Private Link service with on-premises clients
Design and implement service endpoints create service endpoints
configure service endpoint policies
configure service tags
configure access to service endpoints
Configure VNet integration for dedicated platform as a service (PaaS)
services configure App Service for regional VNet integration
configure Azure Kubernetes Service (AKS) for regional VNet integration
configure clients to access App Service Environment
QUESTION 1 You need to configure GW1 to meet the network security requirements for the
P2S VPN users.
Which Tunnel type should you select in the Point-to-site configuration settings
of GW1?
A. IKEv2 and OpenVPN (SSL)
B. IKEv2
C. IKEv2 and SSTP (SSL)
D. OpenVPN (SSL)
E. SSTP (SSL)
Correct Answer: D
QUESTION 2 Your company has a single on-premises datacenter in New York. The East US
Azure region has a peering
location in New York.
The company only has Azure resources in the East US region.
You need to implement ExpressRoute to support up to 1 Gbps. You must use only
ExpressRoute Unlimited
data plans. The solution must minimize costs.
Which type of ExpressRoute circuits should you create?
A. ExpressRoute Local
B. ExpressRoute Direct
C. ExpressRoute Premium
D. ExpressRoute Standard
Correct Answer: A
QUESTION 3 You are planning an Azure Point-to-Site (P2S) VPN that will use OpenVPN.
Users will authenticate by an on-premises Active Directory domain.
Which additional service should you deploy to support the VPN authentication?
A. an Azure key vault
B. a RADIUS server
C. a certification authority
D. Azure Active Directory (Azure AD) Application Proxy
Correct Answer: B
QUESTION 4 You plan to configure BGP for a Site-to-Site VPN connection between a
datacenter and Azure.
Which two Azure resources should you configure? Each correct answer presents a
part of the solution.
(Choose two.)
NOTE: Each correct selection is worth one point.
A. a virtual network gateway
B. Azure Application Gateway
C. Azure Firewall
D. a local network gateway
E. Azure Front Door