County guest Wi-Fi VMs must not talk to court case-management VMs, and both can land on the same overlay transport. What control should the administrator use?
Select an answer to reveal the explanation.
Short Explanation
Overlay east-west can walk around a ToR ACL like a skybridge over a locked lobby door. Distributed Firewall rides with the VM, so guest Wi-Fi still cannot reach case-management. Access policies and USB device control are not that packet path.
Full Explanation
On an NSX overlay, east-west traffic can be switched in the hypervisor and never hit a physical ToR ACL. Distributed Firewall with security groups follows the VM and is the correct isolation control between guest Wi-Fi and court workloads. Workspace ONE Access governs user application access, not VM-to-VM packets. Carbon Black device control addresses removable media, not this east-west path.