HR wants Distributed Firewall rules that use Active Directory groups for city staff rather than only IP sets. Which NSX GUI path enables that identity-based control?
Select an answer to reveal the explanation.
Short Explanation
Badges beat desk numbers: AD groups say who the person is, not which IP they grabbed today. Turn on Identity Firewall with AD, then use those groups in DFW—not NAT and not Carbon Black.
Full Explanation
Identity Firewall uses an Active Directory identity source (System Identity Firewall AD in the NSX-T 3.x GUI) and then allows directory groups as sources or destinations in Distributed Firewall rules under Security. NAT, Traceflow, and Carbon Black user inventory are not the NSX identity-based DFW control. Associate items stay at identify-the-GUI-path depth, not professional IDFW design.