An administrator is creating a Dynamic Address Group (DAG) that should include all servers tagged with 'web' and 'prod'. The firewall is configured to use a VMware NSX-T service manager for tag registration. Which configuration is required to ensure the DAG is populated correctly?
A Dynamic Address Group uses a match filter to include members based on tags. To include only servers that have both 'web' and 'prod' tags, the filter must use the 'and' operator, such as 'web' and 'prod'. This ensures that only addresses with both tags are included. The DAG must also be configured to use the appropriate source, such as the NSX-T service manager, but the filter is the key to correct membership.
Why this answer
To create a Dynamic Address Group that includes only servers with both 'web' and 'prod' tags, the administrator must configure the DAG with a match filter that uses the 'and' operator between the tags. This ensures that only addresses that have both tags are included. The DAG must also be linked to the NSX-T service manager as the source of tags, but the filter logic is critical for correct membership.
Exam trap
The trap here is using an 'or' operator instead of 'and', which would include servers with either tag rather than both, leading to a broader group than intended.