Your audit team says every Prism Central configuration change must be attributable to one person. Which design meets this requirement?
Select an answer to reveal the explanation.
Short Explanation
Think of user accountability like badge swipes at a door: one shared badge tells you someone entered, but not who. You need named accounts mapped to Prism Central roles so every change has a person attached to it. The trap is treating a service or shared admin account as good enough for humans; it's functional, but it wrecks attribution.
Full Explanation
Nutanix Prism Central supports role-based access control tied to user identity. When accountability is required, each administrator should authenticate through an external identity source such as Active Directory or LDAP, receive a unique account, and be assigned a Prism Central role that grants only the permissions needed. Prism Central audit/event records can then associate configuration changes with that account, so an action is linked to a person rather than to a group or shared login. A shared administrator account destroys attribution because every change appears under the same identity; ticket records are outside the product audit trail and cannot prove who performed the action. An automation service account may be appropriate for scripted work, but it is not a person and should not be used as a substitute for human accountability. Local administrator access on each CVM is an infrastructure-level escape hatch for troubleshooting, not a Prism Central identity model, and it bypasses centralized RBAC and audit correlation. Exam caveat: the requirement is accountability, not just least privilege, so the correct design must preserve a unique human identity through authentication and authorization. Operational check: verify a test configuration change in Prism Central appears in audit/event data with the expected user name before allowing shared credentials.