A parks department onboards contractor tablets into the fabric and must ensure they cannot reach finance servers. Which policy approach best expresses that least-privilege intent?
Select an answer to reveal the explanation.
Short Explanation
Contractors need park apps, not the finance vault. Give their devices a restricted SGT and write group policy that says that tag cannot talk to finance server tags. Least privilege becomes a clear group-to-group rule instead of a scavenger hunt through IP ACLs.
Full Explanation
Group-based policy uses SGTs to authorize east-west and client-to-server flows independent of frequent IP renumbering. Assigning contractors a restricted SGT and denying that group’s access to finance server SGTs enforces least privilege inside the fabric. Putting contractors in the finance VN or flooding their prefixes everywhere works against segmentation goals.