An administrator must enforce firewall-like rules between application tiers on AHV VMs managed by Prism Central. Which capability provides this policy enforcement at the hypervisor network layer?
Select an answer to reveal the explanation.
Short Explanation
Think of it like putting a security guard at each VM's network door: Flow enforces the rules, not the VLAN or the bridge. If you're expecting segmentation just from changing VLANs, you'll miss the actual policy layer. Flow is what turns Prism Central rules into per-VM enforcement.
Full Explanation
Nutanix Flow is the capability used when security requirements call for rules between VMs, application tiers, or categories on AHV. It applies policy at the virtual networking layer, so rules can be attached to VMs and enforced without relying only on physical switches or OS firewalls. In a Prism Central environment, Flow is used to create network security policies and associate them with managed AHV VMs, making it the correct mechanism for firewall-like enforcement. VLAN segmentation is wrong because it separates Layer 2 broadcast domains and can isolate traffic, but it does not provide rule-based, stateful security policy between workloads. An AHV bridge is wrong because it connects virtual machines to physical or virtual network segments for connectivity, not for enforcing security rules. Bond failover is wrong because it provides link redundancy and resilience across physical NICs, not network security policy enforcement. Exam caveat: Flow is the security policy layer, while VLANs and bridges are connectivity constructs that may support policy but do not enforce it. Operational check: verify Flow is enabled in Prism Central, then create and attach a network security policy to the target VMs or categories.