Question 1
Q1A financial services firm is deploying a new three-tier application within a VMware Cloud Foundation workload domain. To comply with PCI-DSS requirements, the security team must implement a zero-trust security model using vDefend Distributed Firewall. The initial goal is to understand all traffic flows without blocking legitimate communication before moving to a full enforcement model. Which vDefend feature should the administrator use to achieve this initial goal, and what is the correct state for the firewall rule section containing the micro-segmentation policy?
Show answer & explanation
Correct answer: C
vDefend Security Intelligence is the primary tool for discovering and visualizing application traffic flows to plan micro-segmentation. To monitor the effect of new firewall rules without blocking traffic, the firewall section should be set to 'Log Only' mode. This allows administrators to validate the policy by reviewing logs before moving to 'Enforced' mode, which is a critical step in a phased rollout.