Nutanix Exam Regulatory Compliance & Legal Framework 4 — Questions and Answers
Question 1: A Nutanix customer in the financial sector must comply with DORA (Digital Operational Resilience Act). Which capability is most directly aligned with DORA's ICT risk management pillar?
- VM live migration (AHV)
- Nutanix Leap with automated failover and RTO/RPO documentation (Correct answer)
- Prism Element dashboard theming
- Storage tiering policies
Correct answer: Nutanix Leap with automated failover and RTO/RPO documentation
DORA's ICT risk management pillar requires documented resilience capabilities with defined recovery objectives, which Nutanix Leap addresses through automated failover with measurable RTO/RPO.
Question 2: Under CCPA, if a California resident requests deletion of their personal data stored in a Nutanix Files share, the organization must:
- Archive the data to cold storage instead
- Locate and delete the data within 45 days and verify deletion (Correct answer)
- Transfer the data to another jurisdiction
- Anonymize only the name field
Correct answer: Locate and delete the data within 45 days and verify deletion
CCPA grants California residents the right to deletion, requiring businesses to verify and complete deletion within 45 calendar days of the verified request.
Question 3: Which Nutanix feature helps an organization meet SOX IT General Controls requirements around change management for infrastructure?
- Prism Central API-driven change audit trails integrated with ITSM tools (Correct answer)
- Automatic deduplication ratios
- VM disk hot-add capability
- Flow DNS resolution
Correct answer: Prism Central API-driven change audit trails integrated with ITSM tools
SOX ITGC change management requires documented, approved changes; Prism Central API audit trails integrated with ITSM tools provide the approval and change evidence auditors require.
Question 4: A Nutanix cluster processes data subject to ITAR (International Traffic in Arms Regulations). Which access control requirement is most critical?
- Allowing all employees global access for efficiency
- Restricting cluster access to U.S. persons only and logging all access attempts (Correct answer)
- Enabling self-service VM provisioning for all users
- Disabling two-factor authentication to reduce friction
Correct answer: Restricting cluster access to U.S. persons only and logging all access attempts
ITAR requires that controlled defense-related data be accessible only to U.S. persons, with comprehensive access logging to demonstrate compliance.
Question 5: ISO/IEC 27017 extends ISO 27001 with cloud-specific controls. Which Nutanix deployment scenario would require adherence to ISO 27017?
- An on-premises cluster with no external connectivity
- A Nutanix Cloud Clusters (NC2) deployment on AWS providing managed services to customers (Correct answer)
- A single-node test cluster in a developer's lab
- A cluster used only for development with no production data
Correct answer: A Nutanix Cloud Clusters (NC2) deployment on AWS providing managed services to customers
ISO 27017 applies to cloud service providers and their customers; NC2 on a public cloud represents a cloud service context where these additional controls are relevant.
Question 6: When performing a Nutanix software upgrade in a regulated environment, what documentation artifact is typically required by compliance frameworks like NIST RMF?
- Marketing brochures for the new version
- A formal change request with risk assessment, rollback plan, and approval signatures (Correct answer)
- Only an email notification to users
- A verbal approval from the manager
Correct answer: A formal change request with risk assessment, rollback plan, and approval signatures
NIST RMF and most compliance frameworks require formal change management documentation including risk assessment and rollback procedures before applying changes to production systems.
Question 7: Which legal concept determines whether a Nutanix cloud deployment falls under GDPR jurisdiction, regardless of where the cloud vendor is headquartered?
- The vendor's country of incorporation
- Whether EU residents' personal data is processed, regardless of processing location (Correct answer)
- The physical location of the data center only
- The nationality of the IT administrators
Correct answer: Whether EU residents' personal data is processed, regardless of processing location
GDPR applies based on the data subject's location (EU residents), not where the processor or controller is based, making it applicable even for non-EU vendors processing EU resident data.
A Nutanix customer in the financial sector must comply with DORA (Digital Operational Resilience Act).
Which capability is most directly aligned with DORA's ICT risk management pillar?