Transit fare-collection VMs handle cardholder-like data. Auditors want assurance that east-west isolation on those segments is actually enforced. What should the administrator monitor?
Select an answer to reveal the explanation.
Short Explanation
PCI-like fare data is a locked turnstile, and the deny log is the clicker that proves nobody hopped it. Watch Distributed Firewall hits and denies on those fare groups, not BGP uptime.
Full Explanation
NSX-T Distributed Firewall hit and deny logs are the assurance signal that east-west policy on fare-data groups is matching. BGP neighbor state, sensor version without DFW logging, and Horizon clone counts do not show whether isolation rules fired. Enable and review those DFW logs as part of regulation monitoring.