Prepare for the Nutanix Certified Associate Exam with tailored resources, including multiple choice questions and detailed explanations. Hone your skills and master the exam content for success!

Practice this question and more.


What could be causing the issue if a security policy meant to isolate an application is still allowing outbound internet connections?

  1. The Activate box was not checked in the rule, so it is not enforcing

  2. The policy has been left in monitor mode instead of enforcing mode

  3. The 0.0.0.0 address was not specified in the outbound rule

  4. The blocked connections are illustrated for information only

The correct answer is: The policy has been left in monitor mode instead of enforcing mode

The scenario described indicates that despite having a security policy designed to isolate an application, outbound internet connections are still being allowed. Choosing monitor mode for the policy means that it is primarily tracking and reporting actions rather than actively enforcing restrictions. This would explain why an application could still initiate outbound connections, as the policy is not set to prevent such actions. In enforcing mode, all defined rules would actively restrict traffic according to the policy's specifications. Therefore, having the policy in monitor mode allows traffic to go through without being blocked, demonstrating why the application's outbound internet connections are still permitted. The focus here is on the active enforcement of the policy, which is crucial for maintaining security and isolation as intended by the policy's design.