VCP Regulatory Compliance & Legal Framework 3 — Questions and Answers
Question 1: A VMware vSphere environment processes data for California residents. Which regulation grants those residents the right to opt out of the sale of their personal information?
- HIPAA
- GLBA
- CCPA/CPRA (Correct answer)
- FERPA
Correct answer: CCPA/CPRA
The California Consumer Privacy Act (CCPA), as amended by the CPRA, grants California residents the right to opt out of the sale or sharing of their personal information.
Question 2: In a FedRAMP authorized cloud deployment using VMware Cloud on AWS, which party is responsible for ensuring the hypervisor layer meets FedRAMP security requirements?
- The federal agency tenant
- The Cloud Service Provider (CSP) (Correct answer)
- NIST directly
- The end users accessing VMs
Correct answer: The Cloud Service Provider (CSP)
Under the FedRAMP shared responsibility model, the CSP is responsible for the security of hypervisor and underlying infrastructure layers.
Question 3: Which vSphere configuration option helps satisfy the NIST SP 800-53 AC-2 (Account Management) control by automatically disabling inactive accounts?
- vCenter Single Sign-On password policy
- vCenter SSO inactivity timeout and account lockout policy (Correct answer)
- vSphere Host Profile enforcement
- vRealize Log Insight alerting
Correct answer: vCenter SSO inactivity timeout and account lockout policy
SSO account lockout and inactivity settings in vCenter enforce automatic disabling of dormant accounts, directly supporting AC-2 account management requirements.
Question 4: A healthcare organization is using vSAN to store VMs containing ePHI. Which vSAN capability directly supports HIPAA's requirement for data-at-rest encryption?
- vSAN Stretched Cluster
- vSAN Data-at-Rest Encryption (D@RE) (Correct answer)
- vSAN Deduplication and Compression
- vSAN iSCSI Target Service
Correct answer: vSAN Data-at-Rest Encryption (D@RE)
vSAN Data-at-Rest Encryption (D@RE) encrypts all data stored on vSAN datastores, satisfying HIPAA's addressable encryption standard for ePHI at rest.
Question 5: Under SOC 2 Trust Services Criteria, which category specifically evaluates whether a service organization's virtual infrastructure is available as agreed upon?
- Confidentiality
- Privacy
- Availability (Correct answer)
- Processing Integrity
Correct answer: Availability
The SOC 2 Availability criteria evaluates whether systems are available for operation and use as committed, including uptime SLAs for virtual infrastructure.
Question 6: Which VMware feature enforces DISA STIG compliance by applying a standardized security baseline to ESXi hosts automatically?
- vSphere Host Profiles (Correct answer)
- vCenter Update Manager
- NSX Intelligence
- vSphere Distributed Resource Scheduler
Correct answer: vSphere Host Profiles
vSphere Host Profiles capture and enforce a reference host configuration — including STIG hardening settings — across all ESXi hosts in a cluster.
Question 7: A company subject to GLBA must protect nonpublic personal financial information. Which VMware capability supports GLBA's Safeguards Rule by restricting VM-to-VM traffic within the same VLAN?
- vSphere vMotion encryption
- NSX-T Distributed Firewall micro-segmentation (Correct answer)
- vSAN Erasure Coding
- vCenter Role-Based Access Control
Correct answer: NSX-T Distributed Firewall micro-segmentation
NSX-T's Distributed Firewall enforces east-west traffic policies between VMs on the same VLAN, preventing lateral movement that could expose financial data protected under GLBA.
A VMware vSphere environment processes data for California residents.
Which regulation grants those residents the right to opt out of the sale of their personal information?