Court case-management VMs are tagged, and the administrator wants an exported Distributed Firewall allow list from observed east-west flows among those VMs. Which workflow is correct?
Select an answer to reveal the explanation.
Short Explanation
Intelligence watched who talked to whom and can hand over a first-draft allow list. Review that draft in NSX policy. A Carbon Black process tree is not a DFW export.
Full Explanation
NSX Intelligence output for this use case is security policy recommendations derived from observed flows among grouped or tagged VMs. The administrator reviews those recommendations in Distributed Firewall policy rather than publishing blindly. Carbon Black Cloud process trees, Workspace ONE UEM compliance, and disabling DFW do not produce NSX allow-list policy from overlay flows.