Nutanix Exam Regulatory Compliance & Legal Framework 3 — Questions and Answers
Question 1: A healthcare organization using Nutanix Objects must sign which legal agreement with Nutanix before storing ePHI in the object store?
- Service Level Agreement (SLA)
- Business Associate Agreement (BAA) (Correct answer)
- Non-Disclosure Agreement (NDA)
- End User License Agreement (EULA)
Correct answer: Business Associate Agreement (BAA)
HIPAA requires a BAA between a covered entity and any business associate (including cloud/storage vendors) that processes, stores, or transmits ePHI.
Question 2: Which Nutanix cluster configuration option helps satisfy ISO 27001 Annex A control A.12.3 regarding information backup?
- Node expansion (scale-out)
- Protection Domains with scheduled snapshots replicated to a remote site (Correct answer)
- Prism Pro capacity planning
- Flow micro-segmentation policies
Correct answer: Protection Domains with scheduled snapshots replicated to a remote site
ISO 27001 A.12.3 requires regular tested backups; Nutanix Protection Domains with remote replication directly fulfill this control.
Question 3: Under NIST SP 800-53, the 'Least Privilege' principle for Nutanix administrators is best enforced by:
- Disabling all remote access
- Creating custom Prism Central roles that grant only required permissions (Correct answer)
- Using shared administrator accounts
- Enabling all cluster APIs by default
Correct answer: Creating custom Prism Central roles that grant only required permissions
NIST AC-6 (Least Privilege) requires that users have only the minimum access necessary; custom Prism Central roles allow granular permission assignment.
Question 4: A PCI DSS QSA is reviewing network segmentation. Which Nutanix tool provides evidence that cardholder data environment VMs are isolated from out-of-scope VMs?
- Prism capacity runway reports
- Nutanix Flow Network Security policy audit exports (Correct answer)
- Storage pool utilization graphs
- NCC cluster health summary
Correct answer: Nutanix Flow Network Security policy audit exports
Flow Network Security policies enforce and log micro-segmentation rules; their audit exports provide QSAs with evidence of cardholder data environment isolation.
Question 5: GDPR Article 25 mandates 'Data Protection by Design and by Default.' In a Nutanix deployment, this principle is best demonstrated by:
- Enabling encryption only on demand after a breach
- Enabling cluster-wide AES encryption and RBAC from initial deployment (Correct answer)
- Storing all data in a public bucket
- Turning off audit logging to improve performance
Correct answer: Enabling cluster-wide AES encryption and RBAC from initial deployment
Data protection by design requires privacy controls to be built in from the start, not added reactively, which maps to enabling encryption and access controls at initial deployment.
Question 6: Which U.S. federal law primarily governs cybersecurity requirements for companies operating in the defense industrial base and may affect Nutanix deployments handling CUI?
- FERPA
- CMMC / DFARS 252.204-7012 (Correct answer)
- COPPA
- Gramm-Leach-Bliley Act
Correct answer: CMMC / DFARS 252.204-7012
CMMC (Cybersecurity Maturity Model Certification) and DFARS 252.204-7012 mandate cybersecurity controls for defense contractors handling Controlled Unclassified Information (CUI).
Question 7: When Nutanix cluster nodes are decommissioned, which compliance-driven requirement dictates that drives must be sanitized before physical disposal?
- NIST SP 800-88 media sanitization guidelines (Correct answer)
- PCI DSS Requirement 1 network firewall rules
- HIPAA minimum necessary standard
- SOC 2 availability criteria
Correct answer: NIST SP 800-88 media sanitization guidelines
NIST SP 800-88 provides authoritative guidance on media sanitization methods (clear, purge, destroy) required before disposing of storage media containing sensitive data.
A healthcare organization using Nutanix Objects must sign which legal agreement with Nutanix before storing ePHI in the object store?