A water utility wants a default-deny stance inside the historian application rather than one data-center-wide rule. What should the administrator configure?
Select an answer to reveal the explanation.
Short Explanation
A policy is a labeled folder of rules, and the folder should hang on the historian group—not on the entire civic data center. That is how you get default deny inside the app without boiling the ocean.
Full Explanation
In NSX-T, a security policy is a container of ordered rules and is commonly scoped with Applied To groups. An Application-category policy bound to the historian group implements intra-app allows plus a default deny for that application. A fabric-wide any-any, a single Tier-0 gateway rule, or a Carbon Black policy is not group-scoped NSX application policy.