Nutanix Exam Risk Assessment & Management 4 — Questions and Answers
Question 1: Which risk management framework is MOST commonly referenced when organizations align their Nutanix infrastructure controls with enterprise IT governance?
- ITIL v4
- NIST Cybersecurity Framework (Correct answer)
- Agile Scrum
- TOGAF
Correct answer: NIST Cybersecurity Framework
The NIST Cybersecurity Framework is widely used to align IT infrastructure controls, including Nutanix deployments, with enterprise risk and governance requirements.
Question 2: In a Nutanix environment, which action BEST reduces the risk of a single point of failure for cluster management?
- Using a single large Prism Element instance
- Deploying Prism Central in a scale-out (3-VM) configuration (Correct answer)
- Enabling only local Prism Element access
- Disabling remote support tunnels
Correct answer: Deploying Prism Central in a scale-out (3-VM) configuration
Deploying Prism Central in a scale-out 3-VM configuration eliminates the single-VM Prism Central as a single point of failure for cluster management.
Question 3: A risk analysis shows that unauthorized lateral movement between application tiers is a top threat. Which Nutanix solution DIRECTLY mitigates this risk?
- Nutanix Files
- Nutanix Flow Network Security (microsegmentation) (Correct answer)
- Nutanix Mine
- Prism Capacity Runway
Correct answer: Nutanix Flow Network Security (microsegmentation)
Nutanix Flow Network Security uses microsegmentation to create security policies that restrict lateral movement between VMs and application tiers.
Question 4: What risk does enabling 'Rebuild Reservation' on a Nutanix cluster mitigate?
- Risk of running out of storage for snapshots
- Risk that a node failure leaves insufficient capacity to re-replicate all data (Correct answer)
- Risk of VM performance degradation during backups
- Risk of unauthorized admin access to Prism
Correct answer: Risk that a node failure leaves insufficient capacity to re-replicate all data
Rebuild Reservation reserves enough cluster capacity so that if a node fails, remaining nodes have space to re-replicate all data and restore the required replication factor.
Question 5: During patch management risk assessment, what is the SAFEST approach to applying AOS (Acropolis Operating System) upgrades on a production Nutanix cluster?
- Apply upgrades simultaneously to all nodes to minimize window
- Use rolling upgrade (one node at a time) during off-peak hours (Correct answer)
- Disable replication before upgrading to speed up the process
- Upgrade the cluster controller VMs (CVMs) manually via SSH
Correct answer: Use rolling upgrade (one node at a time) during off-peak hours
Rolling upgrades (one node at a time) ensure the cluster remains available throughout the process, minimizing risk to production workloads.
Question 6: An organization must ensure that any Nutanix storage failure does not impact more than 15 minutes of data. Which DR parameter directly captures this requirement?
- RTO of 15 minutes
- RPO of 15 minutes (Correct answer)
- MTTR of 15 minutes
- MTBF of 15 minutes
Correct answer: RPO of 15 minutes
RPO (Recovery Point Objective) of 15 minutes means no more than 15 minutes of data loss is acceptable, dictating snapshot or replication frequency.
Question 7: Which Nutanix capability allows administrators to test DR failover without impacting production workloads, reducing the risk of an untested recovery plan?
- Nutanix Calm runbooks
- Leap Test Failover (non-disruptive DR testing) (Correct answer)
- NCC health checks
- Flow security policy simulation
Correct answer: Leap Test Failover (non-disruptive DR testing)
Nutanix Leap's Test Failover capability allows DR plans to be validated in an isolated network environment without interrupting production workloads.
Which risk management framework is MOST commonly referenced when organizations align their Nutanix infrastructure controls with enterprise IT governance?