A city wants Distributed Firewall in default-deny, but some transport nodes are not yet Up and inventory groups are not built. What should the administrator do during the install workflow?
Select an answer to reveal the explanation.
Short Explanation
Default-deny on a half-built cluster is like locking the stadium before the seats are installed—you just strand the people already inside. Get transport nodes Up and groups built first. Then default-deny is a policy choice, not an outage.
Full Explanation
NSX-T install workflow completeness—Managers, transport nodes in Up state, compute inventory, and groups—must precede an aggressive Distributed Firewall default-deny. Flipping Drop on day zero of an incomplete cluster typically black-holes management and application traffic that has no allow rules yet. Exclusion-listing every VM or pausing for a vendor-neutral GRC program does not finish the security fabric. Build inventory and groups, then tighten the default action.