As part of their security policies, ACME Enterprise needs Visibility into all data center applications. This can help Identify rogue applications that either capture confidential information or siphon sensitive data to external sources.

John, Cloud Administrator at ACME Enterprise, wants to confirm that access to the share point server is only through Internet Explorer and no rogue application (such as FTP or RDP) can access this server.

1

Log in to the vSphere Web Client.

2

Click Networking & Security and then Activity Monitoring.

3

Click the VM Activity tab.

4

Leave Where source value as All observed virtual machines to capture traffic originating from all virtual machines in the datacenter.

5

In Where destination, select includes.

6

Click the link next to And where destination virtual machine and select the share point server.

7

Click Search.

The Outbound App column in the search results show that all access to the share point server was only through Internet Explorer. The relatively homogenous search results indicate that there is a firewall rule applied to this share point server preventing all other access methods.

Also note that the search results display the source user of the observed traffic rather than the source group. Clicking arow in the search result displays details about the source user such as the AD group toi which the user belongs,