Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Nutanix Certified Professional - Multicloud Infrastructure (NCP-MCI) 7.5 NCP-MCI-7.5 Question # 6 Topic 1 Discussion

Nutanix Certified Professional - Multicloud Infrastructure (NCP-MCI) 7.5 NCP-MCI-7.5 Question # 6 Topic 1 Discussion

NCP-MCI-7.5 Exam Topic 1 Question 6 Discussion:
Question #: 6
Topic #: 1

An administrator detects suspicious outbound connections from a single VM that hosts a web tier component.

The incident response requirement is to immediately quarantine the VM so it cannot communicate with any other workload, but still allow connectivity from a designated forensic tooling group so investigators can collect evidence.

The organization uses categories for policy scope and wants a change that can be applied quickly during an incident without redesigning existing policies.

Which action best meets the requirement?


A.

Assign the VM to the built-in Quarantine category with the Forensic value so quarantine behavior blocks traffic except to and from forensic tools.


B.

Assign the VM to the built-in Quarantine category with the Strict value and separately create a shared service policy to allow forensic access.


C.

Create an application policy that only allows outbound traffic to forensic tools, leaving inbound traffic as allow all for faster investigation.


D.

Create an isolation environment policy between the VM and all other categories to block traffic and manually add exceptions for forensic tools.


Get Premium NCP-MCI-7.5 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.