A VM with a Flow security policy moves from one AHV host to another in the same Prism Central-managed cluster. What happens to the policy enforcement?
Select an answer to reveal the explanation.
Short Explanation
Think of Flow policy like a badge on the VM, not a sticker on the host. When your VM hops AHV hosts, the policy follows it because enforcement keys off categories, not location. Don't let networking placement fool you into thinking security enforcement changes.
Full Explanation
Flow security policies are defined in Prism Central and attached to workloads through category-based membership. The enforcement point is the Nutanix data plane serving the VM, so when a VM moves between AHV hosts in the same managed cluster, the policy remains associated with the VM's identity and categories rather than with a particular physical host or bridge. A distractor suggesting manual re-tagging on the destination host confuses placement with policy attachment: categories travel with the VM metadata, not with host configuration. Another distractor tying enforcement to the destination VLAN or bridge mistakes network segmentation for security policy scope; Flow policy is evaluated against the VM, not only the underlying network path. A third distractor requiring the destination CVM to re-download the policy before traffic is allowed overstates a per-host provisioning step and ignores that policy enforcement is distributed across the cluster's control and data planes. Exam caveat: Prism Central labels may differ by version, so test the concept of category-bound, host-independent enforcement rather than a specific menu string. Operational check: after a live migration, confirm the VM's category assignment, then validate that the Flow policy still appears enforced and perform an allowed and denied connection test.