Nutanix Exam Regulatory Compliance & Legal Framework 5 — Questions and Answers
Question 1: A Nutanix administrator must implement controls to satisfy PCI DSS Requirement 8 regarding unique user IDs. Which action best fulfills this requirement?
- Creating a single shared 'admin' account for all cluster administrators
- Integrating Prism Central with Active Directory so each admin has a unique named account (Correct answer)
- Using the default Nutanix admin credentials without modification
- Sharing credentials only among senior staff
Correct answer: Integrating Prism Central with Active Directory so each admin has a unique named account
PCI DSS Req 8 prohibits shared accounts and requires unique IDs for all users; AD integration in Prism Central ensures each administrator authenticates with their own identity.
Question 2: Under HIPAA's Breach Notification Rule, if a Nutanix cluster containing ePHI is compromised, covered entities must notify affected individuals within:
- 7 calendar days
- 60 calendar days of discovery (Correct answer)
- 30 business days
- 12 months of fiscal year end
Correct answer: 60 calendar days of discovery
HIPAA's Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and no later than 60 calendar days from discovery of the breach.
Question 3: A Nutanix deployment must comply with FIPS 140-2. Which cluster configuration change is required?
- Enabling FIPS mode, which restricts the cluster to FIPS-validated cryptographic algorithms only (Correct answer)
- Disabling all encryption for performance
- Using MD5 hashes for data integrity
- Installing third-party antivirus on all nodes
Correct answer: Enabling FIPS mode, which restricts the cluster to FIPS-validated cryptographic algorithms only
Enabling FIPS mode in Nutanix restricts the operating system and services to only FIPS 140-2 validated cryptographic modules, disabling non-compliant algorithms.
Question 4: Which Nutanix feature helps meet the NIST Cybersecurity Framework 'Detect' function by identifying anomalous VM behavior?
- Nutanix Security Central behavioral analytics and anomaly detection (Correct answer)
- Storage compression ratios
- VM live migration schedules
- Acropolis storage policies
Correct answer: Nutanix Security Central behavioral analytics and anomaly detection
The NIST CSF 'Detect' function requires continuous monitoring for anomalies; Nutanix Security Central provides behavioral analytics that identify deviations from baseline VM activity.
Question 5: An organization subject to NYDFS Cybersecurity Regulation (23 NYCRR 500) must submit an annual Certification of Compliance. Which Nutanix audit capability supports this process?
- Cluster replication factor settings
- Prism Central audit logs demonstrating continuous control implementation throughout the year (Correct answer)
- VM template library
- Node hardware health LEDs
Correct answer: Prism Central audit logs demonstrating continuous control implementation throughout the year
NYDFS 23 NYCRR 500 requires annual certification backed by evidence of year-round control implementation; Prism Central audit logs provide continuous activity records to support this attestation.
Question 6: When a Nutanix cluster is subject to a legal hold (litigation hold), which data management action must the organization avoid?
- Monitoring cluster performance
- Deleting, overwriting, or modifying any data covered by the hold scope (Correct answer)
- Adding new VMs unrelated to the hold
- Reviewing existing snapshots
Correct answer: Deleting, overwriting, or modifying any data covered by the hold scope
A legal hold requires preservation of all potentially relevant data in its original state; deletion or modification of covered data constitutes spoliation and can result in court sanctions.
Question 7: Which privacy principle, required under GDPR and CCPA, limits the collection of personal data to only what is strictly necessary for the specified purpose?
- Data portability
- Data minimization (Correct answer)
- Data residency
- Data sovereignty
Correct answer: Data minimization
Data minimization requires that organizations collect and process only the personal data that is adequate, relevant, and limited to what is necessary for the stated purpose.
A Nutanix administrator must implement controls to satisfy PCI DSS Requirement 8 regarding unique user IDs.
Which action best fulfills this requirement?