Parks inspectors may use Tunnel only for Boxer and the city GIS app; personal Safari must stay off the civic LAN. What access model is that?
Select an answer to reveal the explanation.
Short Explanation
Think of Tunnel as a staff-only side door for named apps, not a loading dock that swallows Safari too. Device-wide IPsec would haul personal browsing onto the LAN, and Horizon HTML Access or NSX would be the wrong door entirely. Only Boxer and GIS using Tunnel is the per-app VPN model.
Full Explanation
Workspace ONE Tunnel is application-scoped: administrators nominate managed apps such as Boxer or a GIS client, and other processes including personal Safari do not use that path. A device-wide always-on IPsec VPN is a different access model and is not the exam definition of Tunnel. Horizon HTML Access is a VDI client, and NSX Distributed Firewall is a data-center security product, not a phone VPN client. Associate identification should keep Tunnel in the per-app Workspace ONE productivity-app family.