A self-service engineer needs to deploy development VMs in a Nutanix project. The engineer must not be able to delete production VMs in the same project. Which role should you assign?
Select an answer to reveal the explanation.
Short Explanation
Think of RBAC like keys on a key ring: a Project VM User can build and manage their own VMs, but they don't get the master key to delete production VMs owned by others. If you hand them Project VM Admin, you've just let the builder tear down the factory. Give them the narrower role and let ownership boundaries do the rest.
Full Explanation
Nutanix RBAC separates what a user can request from what the user can destroy. In a project context, the Project VM User role supports self-service VM creation and management of VMs the user owns, while destructive actions against VMs outside that ownership boundary remain restricted. That matches the requirement because the engineer can deploy development workloads without gaining authority over production VMs owned by other users. The Project VM Admin role is too broad because it manages all VMs in the assigned project, including production VMs, regardless of ownership. The Project Admin role also exceeds the need because it controls project settings and resources in addition to VMs, undermining least privilege. The Cluster Admin role is inappropriate because it grants cluster-wide administrative reach far beyond one project and would bypass the project boundary entirely. Exam caveat: focus on ownership and role scope, not menu labels or permission strings. Operational check: confirm the test user can create a development VM but receives no delete permission for a production VM owned by another account.