Your Nutanix AHV cluster hosts web, application, and database VMs on separate VLANs. You need microsegmentation so web talks only to application, application only to database, and all other east-west traffic is denied. Which Nutanix capability should you use?
Select an answer to reveal the explanation.
Short Explanation
Think of Flow security policies like a bouncer for VM traffic: you define who talks to whom, not just which VLAN they sit on. You can create separate web, app, and database groups and allow only the needed tier hops. The trap is thinking VLANs alone microsegment—VLANs isolate broadcast domains, but they don't give you fine-grained east-west policy.
Full Explanation
Flow security policies are the Nutanix AHV-native mechanism for microsegmentation. They attach to VMs or groups and enforce distributed firewall rules between tiers, allowing web-to-application and application-to-database flows while denying other east-west traffic. Policies operate at the AHV/Flow layer, so they do not require external physical VLAN reconfiguration or guest OS firewall changes. VLAN isolation by itself separates Layer 2 broadcast domains, but it does not define fine-grained application traffic rules between tiers; two VMs on different VLANs can still communicate through routing or bridges if permitted, and VLANs alone cannot express tier-based allow/deny semantics. Bridge configuration maps VM networks to uplinks; it does not enforce policy between application tiers. Prism Central RBAC controls who may administer or view Prism objects and operations; it does not control VM-to-VM network traffic, so it cannot segment web, application, and database workloads. Exam caveat: choose the feature that enforces inter-VM traffic policy, not the feature that merely provides network separation or administrative access. Operational check: create tier groups or tags, define an explicit allow rule for the required tier hop, and verify the policy blocks an unintended cross-tier connection before enabling it cluster-wide.