A municipal payment VRF that handles PCI cardholder traffic must never reach the guest Wi-Fi VRF. Which approach best preserves strict Layer 3 isolation?
Select an answer to reveal the explanation.
Short Explanation
PCI and guest Wi-Fi should be neighbors that never share a hallway. No common routes, no shared RTs, no firewall pinholes unless compliance explicitly blesses them—and guest Wi-Fi almost never qualifies. Stuffing them together or bridging SSIDs into the payment VLAN is how audits become incident reports.
Full Explanation
Strict L3 isolation for sensitive tenants is policy-driven absence of connectivity: unique route targets, no leaked prefixes, and no firewall or IRB paths between PCI and guest VRFs. Co-locating instances, advertising defaults across tenants, or bridging guests into the PCI L2 domain defeats isolation and compliance intent. JN0-683 multitenancy expects that sensitive VRFs remain unreachable from untrusted tenants by design.