A single Hyper-V host with one physical NIC runs VMs for two tenants (TenantA and TenantB). All VMs must access the external network, TenantA VMs must be isolated from TenantB at Layer 2, and you must block one VM in TenantA from reaching the public IP 203.0.113.10. What two configurations should you implement?
Choose an answer
Tap an option to check your answer.
Correct answer: Create one external virtual switch and assign different VLAN IDs to TenantA and TenantB VM network adapters., Configure a port ACL on the specific VM’s virtual network adapter to Deny outbound traffic To-Address 203.0.113.10..
Why this is the answer
To allow all VMs to access the external network, an external virtual switch is necessary. Assigning different VLAN IDs to TenantA and TenantB VM network adapters isolates them at Layer 2, fulfilling the tenant isolation requirement. Configuring a port ACL on the specific VM's virtual network adapter to deny outbound traffic to 203.0.113.10 directly addresses the need to block that VM from reaching a specific public IP. Creating private virtual switches would prevent external network access for the VMs. Using an internal virtual switch would also prevent direct external network access without additional routing. DHCP guard is unrelated to network isolation or blocking specific IP access.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed