A water utility must prove OT historian VMs stay in a Distributed Firewall group separate from citizen portal VMs for NERC-like separation evidence. What should the administrator produce?
Select an answer to reveal the explanation.
Short Explanation
Who is on the plant-floor roster is the whole question. Export the OT Distributed Firewall group, line it up with the asset inventory, and prove the citizen portal VMs are not on that list.
Full Explanation
Group membership is the assurance artifact for OT separation: current NSX-T security groups must map to the OT inventory and exclude citizen workloads. Integrity models, vMotion compatibility, and Hub versions on unenrolled SCADA hosts do not show who is in the OT group. Review membership whenever assets change.