VCP Regulatory Compliance & Legal Framework 4 — Questions and Answers
Question 1: Which international standard provides a framework for information security management systems (ISMS) that is commonly used alongside VMware deployments to achieve certification?
- ISO/IEC 27001 (Correct answer)
- ISO 9001
- IEEE 802.1Q
- ISO/IEC 20000
Correct answer: ISO/IEC 27001
ISO/IEC 27001 specifies requirements for establishing, implementing, and maintaining an ISMS, providing the governance framework under which VMware security controls are documented and audited.
Question 2: PCI DSS Requirement 6.4 requires that public-facing web applications be protected against known attacks. Which VMware solution can fulfill this by acting as a virtual WAF for workloads?
- vSphere Replication
- NSX Advanced Load Balancer (Avi) with WAF profile (Correct answer)
- vSAN Witness Appliance
- vCenter Content Library
Correct answer: NSX Advanced Load Balancer (Avi) with WAF profile
NSX Advanced Load Balancer (Avi Networks) includes a WAF module that inspects HTTP traffic and blocks OWASP Top 10 attacks, satisfying PCI DSS Req 6.4.
Question 3: When configuring vCenter Server for compliance with CIS Benchmark recommendations, which default setting should be changed to reduce attack surface?
- Increase the number of vCenter appliance CPUs
- Disable the managed object browser (MOB) (Correct answer)
- Enable vCenter High Availability
- Configure vSAN stretched cluster
Correct answer: Disable the managed object browser (MOB)
The CIS VMware ESXi and vCenter benchmarks recommend disabling the Managed Object Browser (MOB) as it exposes internal API objects and is not needed in production.
Question 4: A regulated financial firm requires that all VM snapshots containing customer data be retained for exactly 7 years per SEC Rule 17a-4. Which storage capability supports immutable retention?
- vSphere Snapshot Manager retention policy
- vSAN datastore with WORM-compliant object storage backend (Correct answer)
- vSphere Storage vMotion
- vCenter Schedule Tasks for snapshot deletion
Correct answer: vSAN datastore with WORM-compliant object storage backend
SEC Rule 17a-4 requires WORM (Write Once Read Many) storage; integrating vSAN with a compliant WORM object storage backend ensures records cannot be altered or deleted during the retention period.
Question 5: Under HIPAA, a VMware cloud provider hosting ePHI workloads for a hospital must sign which agreement before the hospital may share patient data with them?
- Service Level Agreement (SLA)
- Business Associate Agreement (BAA) (Correct answer)
- Data Processing Agreement (DPA)
- Non-Disclosure Agreement (NDA)
Correct answer: Business Associate Agreement (BAA)
HIPAA requires a Business Associate Agreement (BAA) between a covered entity and any vendor (business associate) that creates, receives, maintains, or transmits ePHI on their behalf.
Question 6: Which VMware vSphere privilege category must be tightly controlled to comply with the principle of least privilege required by frameworks like NIST SP 800-53 AC-6?
- Datastore.Browse privilege
- Global.Act As vCenter Server privilege (Correct answer)
- Network.Assign Network privilege
- Virtual Machine.Interact.Console Interact privilege
Correct answer: Global.Act As vCenter Server privilege
The 'Global.Act As vCenter Server' privilege grants nearly unrestricted administrative rights and must be restricted to prevent privilege escalation, supporting AC-6 least privilege controls.
Question 7: A US Department of Defense contractor virtualizing workloads must comply with which cybersecurity framework that uses maturity levels to assess practices?
- CMMC (Cybersecurity Maturity Model Certification) (Correct answer)
- ISO 31000
- COBIT 2019
- ITIL v4
Correct answer: CMMC (Cybersecurity Maturity Model Certification)
CMMC is the DoD's framework requiring contractors to achieve a specific maturity level (1-3) based on practice implementation, covering CUI protection in virtualized environments.
Which international standard provides a framework for information security management systems (ISMS) that is commonly used alongside VMware deployments to achieve certification?