ISC Infrastructure And System Security Practice Question
To secure internal traffic within a VMware NSX-T environment using distributed firewalling, which object type is recommended for defining policies based on application identity rather than network topology?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security Groups
Security Groups in NSX-T allow administrators to bundle virtual machines based on tags or attributes, enabling identity-based micro-segmentation that persists regardless of IP changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
MAC Sets
Why it's wrong here
MAC-based filtering is obsolete and difficult to maintain.
- ✗
Logical Ports
Why it's wrong here
Logical ports are too granular and do not provide the abstract grouping required for application policies.
- ✗
IP Sets
Why it's wrong here
IP Sets rely on address-based logic, which is brittle in dynamic environments.
- ✓
Security Groups
Why this is correct
Security Groups support dynamic membership based on tags, facilitating intent-based policy.
About these practice questions
This ISC question is part of Courseiva's 208-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official (ISC)² exam blueprint
This ISC practice question is part of Courseiva's free (ISC)² certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ISC exam.