An administrator must isolate application traffic from management traffic on an AHV cluster. Existing management VMs use the default management network. Which action provides the required network isolation?
Select an answer to reveal the explanation.
Short Explanation
Think of it like this: a VLAN is your traffic lane, not a bandwidth pipe. If you need app chatter kept off management, you build a separate virtual network with its own VLAN and plug the app NICs into it. Don't confuse Flow, subnets, or LACP with a real isolated network construct.
Full Explanation
Nutanix AHV isolates tenant or application traffic by defining a virtual network that combines a bridge with a VLAN ID. The bridge provides the virtual switch construct on the host, while the VLAN places frames in a distinct Layer 2 domain. When application VM NICs are attached to that virtual network, their traffic is separated from management frames that remain on the management network. Extending the management network with another subnet on the existing bridge does not create a separate Layer 2 domain; it merely reuses the same bridge, so management and application frames can still share the same broadcast context. Flow microsegmentation can enforce allow or deny rules between VMs, but it operates as policy enforcement rather than the underlying network construct needed to create the isolated network. LACP improves link redundancy and bandwidth aggregation on a bond, but it does not segment traffic; it only chooses active member links and balances flows. Exam caveat: exact Prism wording can vary across releases, so focus on bridge plus VLAN isolation rather than menu labels. Operational check: confirm the application VM NIC is attached to the new virtual network and that its traffic reaches only the intended gateway or VLAN.