VCP Regulatory Compliance & Legal Framework 2 — Questions and Answers
Question 1: Which US federal regulation specifically mandates security controls for electronic protected health information (ePHI) stored or processed in virtualized environments?
- HIPAA Security Rule (Correct answer)
- FERPA
- GLBA Safeguards Rule
- FISMA
Correct answer: HIPAA Security Rule
The HIPAA Security Rule requires covered entities and business associates to implement technical safeguards for ePHI, including in virtualized and cloud environments.
Question 2: A VMware administrator needs to ensure audit logs cannot be tampered with to meet SOX compliance. Which vSphere feature best addresses this requirement?
- vCenter Server Alarms
- VMware vSphere Syslog with remote forwarding to an immutable log store (Correct answer)
- vRealize Operations Manager dashboards
- vSphere Distributed Switch port mirroring
Correct answer: VMware vSphere Syslog with remote forwarding to an immutable log store
Forwarding syslog to an immutable, remote log store ensures audit trail integrity required by SOX Section 802 for financial record retention.
Question 3: Under GDPR, what legal concept requires that personal data processing be limited to only what is necessary for the specified purpose?
- Right to Erasure
- Data Minimization (Correct answer)
- Purpose Limitation
- Storage Limitation
Correct answer: Data Minimization
Data Minimization (Article 5(1)(c) GDPR) mandates that only data adequate, relevant, and limited to what is necessary for the purpose may be collected.
Question 4: Which VMware product provides a centralized policy engine to enforce network micro-segmentation controls that support PCI DSS Requirement 1 (network segmentation)?
- vSphere Replication
- NSX-T Data Center (Correct answer)
- vSAN Encryption
- vCenter Linked Mode
Correct answer: NSX-T Data Center
NSX-T provides distributed firewall and micro-segmentation capabilities that enforce network isolation between cardholder data environment segments as required by PCI DSS Req 1.
Question 5: A company operating VMs in the US that store EU resident data is subject to which data transfer framework when moving that data back to EU-based systems?
- COPPA Safe Harbor
- EU-US Data Privacy Framework (Correct answer)
- CCPA opt-out provision
- NIST CSF Tier 3
Correct answer: EU-US Data Privacy Framework
The EU-US Data Privacy Framework (successor to Privacy Shield) governs lawful transfer of EU personal data to certified US organizations.
Question 6: When decommissioning a VM that processed PCI cardholder data, which action is required to meet PCI DSS media sanitization requirements?
- Delete the VM from vCenter inventory
- Power off the VM and archive the VMDK
- Cryptographically erase or destroy the underlying storage containing VM disk files (Correct answer)
- Migrate the VM to a dev cluster
Correct answer: Cryptographically erase or destroy the underlying storage containing VM disk files
PCI DSS Requirement 9.8 mandates that media containing cardholder data be rendered unrecoverable via cryptographic erasure or physical destruction.
Question 7: Which NIST Special Publication provides the primary framework for categorizing federal information systems by impact level, which VMware implementations in federal agencies must follow?
- NIST SP 800-53
- NIST SP 800-145
- NIST SP 800-60 (Correct answer)
- NIST SP 800-171
Correct answer: NIST SP 800-60
NIST SP 800-60 provides guidance for mapping information types to security categories (Low/Moderate/High) required before applying controls from SP 800-53.
Which US federal regulation specifically mandates security controls for electronic protected health information (ePHI) stored or processed in virtualized environments?