300-206 Free Dumps Study Materials
Question 9: In which two ways can you isolate and secure multiple tenants in a virtualized data center?
(Choose two.)
A. Deploy VRF-Lite to provide Layer 3 isolation.
B. Implement LUN masking to provide compute separation at Layer 2.
C. Assign VLANs to tenant servers to logically separate Layer 3 domains.
D. Implement redundant ASAs at the perimeter to provide per-tenant firewalling.
E. Group vNICs with VMware vCenter to provide port profile isolation at Layer 2.
Correct Answer: C,E
Explanation
Explanation/Reference
Secure Isolation-In a multi-tenant environment, the ability to securely contain and isolate tenant
traffic is a fundamental requirement, protecting tenant resources and providing risk mitigation in the
event that a specific tenant's privacy is breached. Like availability, isolation mechanisms are applied
in a multi-layered fashion in order to implement the requisite infrastructure protection and security
zoning policies on a per-tenant basis. In practice, techniques fall into two categories of physical and
logical isolation mechanisms. However, VMDC analysis focuses mainly on logical mechanisms. These
include various L2 and L3 mechanisms, such as multiple vNICs (i.e., for specific control or data traffic),
802.1q VLANs, MPLS VRFs, VSANs, combined with access control mechanisms (i.e., RBAC and
directory services, IPSec or SSL VPNs), and packet filtering and firewall policies.
https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Data_Center/VMDC/2-
2/design_guide/vmdcDesign22/VMDC_2-2_DG_1.html