NSX creates a workload-level security boundary, irrespective of the physical hardware, “VLAN” or “subnet” that the workload is in. It can logically decompose the data center into security sections. Information technology teams can implement their own security policies specific to each workload by creating dynamic and intelligent security groups at the virtual machine level. In this way, unlike a traditional data center network, if an attacker breaks through the perimeter firewall and infiltrates the data center structure, lateral movement of other resources within the data center is prevented. Thus, the attack diameter is reduced to the minimum level.