After first boot of the 911 NSX Managers, the install checklist requires SSH and API access only from jump hosts. How should the administrator treat that requirement?
Select an answer to reveal the explanation.
Short Explanation
The NSX management plane is the 911 station's master key box—only the jump room should reach it. Limit SSH and API to those networks during setup. Opening the WAN or swapping in Carbon Black Live Response is not Manager hardening.
Full Explanation
Tightening NSX Manager SSH and API access after first boot is part of the NSX-T setup workflow. Restricting those services to jump-host networks reduces management-plane attack surface before policy is even written. Exposing SSH/API across the civic WAN contradicts that hardening. Carbon Black Live Response and Workspace ONE Access publication are not substitutes for NSX Manager source restriction.