ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your team is building a new multitenant IaaS cloud on VMware vSphere 7 that will use NSX-T Data Center for software-defined networking. Tenants may bring overlapping RFC 1918 address spaces, so the design must isolate each tenant's east-west traffic while scaling far beyond the 4,094-VLAN limit of IEEE 802.1Q-all without requiring any changes to the existing physical switches. Which NSX-T feature best meets these requirements?
Creating NSX-T overlay segments that use Geneve encapsulation and 24-bit VNIs for each tenant
Extending traditional 802.1Q VLAN trunks across the top-of-rack physical switches
Implementing private VLANs (PVLANs) on the vSphere distributed virtual switch
Building GRE tunnels between tenant gateways on the perimeter firewall
NSX-T implements an overlay network by encapsulating each tenant's Layer-2 Ethernet frames inside Geneve-encapsulated packets that traverse the underlying IP fabric. Each logical switch (segment) is identified by a 24-bit Virtual Network Identifier (VNI), allowing for about 16 million isolated Layer-2 broadcast domains-well beyond the 4,094-VLAN ceiling. Because the physical switches forward only IP/UDP traffic, no VLAN or other configuration changes are needed in the underlay. Standard VLAN trunking and PVLANs remain limited by the 12-bit VLAN ID space, and GRE tunnels on perimeter firewalls do not provide the required intra-host east-west isolation within the hypervisor.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Geneve encapsulation in NSX-T?
Open an interactive chat with Bash
What is RFC 1918 address space?
Open an interactive chat with Bash
Why are VLANs limited to 4,094 identifiers in 802.1Q?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Platform & Infrastructure Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .