On election night, threat intel flags a command-and-control network talking to a results-app group. Security needs a fast Distributed Firewall block that must not live forever. How should the Emergency category be used?
Select an answer to reveal the explanation.
Short Explanation
Emergency is the red pull-handle, not a new permanent wall around the city. Slap a time-bounded deny on that C2 group, then take the handle off the wall when the indicator expires.
Full Explanation
The NSX-T Emergency category is evaluated above Infrastructure and Application and is intended for incident-response blocks such as a malicious C2 group. Those rules are operational tools: they should be time-bounded and removed when the indicator of compromise expires. Permanent Application any-any denies, disabling Identity Firewall, or blackholing the WAN are not Emergency-category management.