A Nutanix administrator manages one AHV cluster in Prism Central. Finance and Engineering need self-service visibility into only their own VMs, and the VMs already carry team tags. Which mechanism restricts each team's view to the matching workloads?
Select an answer to reveal the explanation.
Short Explanation
Think of categories like colored tags on VMs: give a user the right to see only the tag they own. You don't need a separate cluster or a network trick. The trap is thinking isolation automatically means console visibility.
Full Explanation
Category-based access control uses metadata applied to VMs and mapped to user permissions, so a user's Prism Central view is filtered to the categories they are entitled to see. The administrator first assigns a consistent category, such as Finance or Engineering, to each VM, then grants team users or groups permission only for those categories. This keeps one shared cluster while presenting a scoped self-service view. Separate Prism Element clusters would create administrative and storage silos, and it does not use the existing category model; it is a coarse deployment change rather than access scoping. Flow network segmentation controls packet forwarding and microsegmentation policies, but it does not hide inventory objects in the management UI or enforce user-visible object lists. A storage policy governs data placement, performance, and protection characteristics for disks; it does not authorize users or determine which VM records are displayed. Exam caveat: distinguish object-level visibility from network isolation and from cluster separation when a requirement says teams should see only their workloads. Operational check: verify that a test user assigned only the Engineering category can list Engineering VMs but cannot list VMs carrying Finance or Production categories.