Nutanix Exam Regulatory Compliance & Legal Framework 2 — Questions and Answers
Question 1: Under HIPAA, which Nutanix feature helps ensure that ePHI stored in a cluster remains protected from unauthorized access by internal staff?
- Flow Network Segmentation
- Role-Based Access Control (RBAC) (Correct answer)
- Leap disaster recovery
- Acropolis Hypervisor (AHV)
Correct answer: Role-Based Access Control (RBAC)
RBAC restricts access to sensitive data based on job roles, satisfying HIPAA's minimum necessary access principle for ePHI.
Question 2: Which Nutanix capability directly supports PCI DSS Requirement 10 by providing immutable logs of all administrator actions?
- Prism Central alerts
- Audit log retention via Syslog forwarding (Correct answer)
- NCC health checks
- Storage QoS policies
Correct answer: Audit log retention via Syslog forwarding
PCI DSS Requirement 10 mandates tracking and monitoring of all access to network resources, which Nutanix satisfies through Syslog-forwarded, tamper-evident audit logs.
Question 3: A company subject to GDPR wants to ensure data deleted upon a subject access request cannot be recovered. Which Nutanix feature is most relevant?
- Erasure coding
- Secure data shredding / crypto-erase on decommission (Correct answer)
- Deduplication
- Compression
Correct answer: Secure data shredding / crypto-erase on decommission
GDPR's right to erasure requires that data be irrecoverably deleted, which is achieved through crypto-erase or secure shredding rather than simple logical deletion.
Question 4: SOC 2 Type II compliance differs from SOC 2 Type I in that it:
- Covers more security domains
- Tests controls over a period of time rather than a single point in time (Correct answer)
- Requires government certification
- Is specific to cloud-only environments
Correct answer: Tests controls over a period of time rather than a single point in time
SOC 2 Type II evaluates the operational effectiveness of controls over a minimum six-month period, providing stronger assurance than the point-in-time Type I.
Question 5: When deploying Nutanix in a FedRAMP High environment, which encryption standard is mandated for data at rest?
- DES-128
- AES-256 (Correct answer)
- RSA-1024
- 3DES-112
Correct answer: AES-256
FedRAMP High requires FIPS 140-2 validated cryptographic modules, with AES-256 being the accepted standard for data-at-rest encryption.
Question 6: Which Nutanix licensing model concern is most relevant when an organization must comply with software asset management audits?
- Node failure tolerance settings
- Accurate tracking of CPU-socket or core-based license entitlements (Correct answer)
- VM snapshot schedules
- Network VLAN configurations
Correct answer: Accurate tracking of CPU-socket or core-based license entitlements
Software asset management audits verify that license entitlements match actual deployment, so accurate tracking of Nutanix CPU-socket or core-based licenses is essential.
Question 7: Under the EU AI Act framework, a Nutanix-hosted AI workload used for credit scoring would likely be classified as:
- Minimal risk
- High risk (Correct answer)
- Unacceptable risk
- Limited risk
Correct answer: High risk
The EU AI Act designates AI systems used in credit scoring as high-risk because they significantly affect individuals' financial opportunities and rights.
Under HIPAA, which Nutanix feature helps ensure that ePHI stored in a cluster remains protected from unauthorized access by internal staff?