A Nutanix administrator must let a development team create and manage workloads only within its own Prism Central project, without granting access to other projects or cluster-level settings. Which control delegates this administration with least privilege?
Select an answer to reveal the explanation.
Short Explanation
Think of it like handing your team a key to their own apartment, not the master key to the whole building. You want them to manage their project, not wander into other clusters. Project-scoped admin rights give them exactly that boundary.
Full Explanation
Project administration in Prism Central is designed as a scoped delegation boundary. When a team is assigned project ownership or project administrator rights, its management authority is limited to the resources, categories, and self-service placements associated with that project. This satisfies the requirement to delegate workload administration while preserving cluster and cross-project separation, because the role is evaluated against project membership rather than cluster-wide privileges. Granting cluster administrator privileges is too broad: it gives control over hosts, storage, networking, and other projects, so relying on naming conventions or user discipline does not enforce isolation. Full Prism Central administrator access is also excessive; category views or filtered displays may make the console easier to navigate, but they do not replace authorization boundaries. A read-only viewer role cannot perform delegated administration, and requiring manual approval for each request shifts work back to central administrators instead of enabling self-service management. Exam caveat: choose the least-privileged role that still allows the team to perform its assigned workload tasks. Operational check: confirm the delegated team can create and modify VMs inside its project, while attempts to view or alter another project or cluster are denied.