A school district enables Application default-deny on student-information VMs. DNS and Active Directory then fail even though Infrastructure allows for DNS and LDAP already exist. An intern proposes moving Infrastructure below Application. What should the operator do?
Select an answer to reveal the explanation.
Short Explanation
Think of Infrastructure as the hallway lights and Application as the classroom door. If you put the door in front of the lights, nobody can even find DNS. Leave Infrastructure above Application so name and directory traffic still work when app default-deny turns on.
Full Explanation
NSX-T Distributed Firewall evaluates categories in a fixed order, with Infrastructure above Application. DNS, DHCP, NTP, and directory allows belong in Infrastructure so they still hit after Application default-deny is enabled. Reordering categories, substituting Tier-0 routing for DFW, or disabling Guest Introspection does not restore those services and breaks category management.