Public-health on-premises NSX-T uses a default-deny Distributed Firewall. The agency's cloud SDDC still has any-any on its NSX-T instance. Auditors ask why production-like workloads are wide open in the cloud. What should the administrator flag?
Select an answer to reveal the explanation.
Short Explanation
Two fabrics, two postures. Default deny at home and any-any in the cloud is a split-brain, not a design. Call out the gap and write equivalent DFW in the cloud — Federation routing is not the VCP-SEC shortcut that magically copies policy.
Full Explanation
Multi-cloud troubleshooting includes policy parity: an on-premises default-deny Distributed Firewall does not enforce on a separate cloud NSX-T instance that remains any-any. NSX Federation as a networking design is outside this exam's security-administration focus and must not be assumed. Carbon Black Cloud endpoint prevention and Workspace ONE UEM compliance do not replace NSX micro-segmentation in the cloud SDDC, so flag the inconsistent posture and apply equivalent DFW, or the vendor's supported cloud security pattern, where those workloads run.