A Nutanix administrator configures Metro Availability between two on-premises sites. During a network partition test, both sites can see local CVMs but cannot see the partner site. The administrator wants to prevent split-brain and keep one site authoritative. Which mechanism must be deployed?
Select an answer to reveal the explanation.
Short Explanation
Think of Metro like two people holding a rope: if they can’t see each other, they need a referee to decide who keeps the rope. You add a witness so the surviving side has quorum and the other side stands down. Without that tie-breaker, both sites can think they own the VM and split-brain happens.
Full Explanation
Metro Availability extends a cluster across two sites with synchronous replication, so a single logical cluster must still know which side is authoritative when sites lose network connectivity. A quorum witness supplies the third arbitration vote needed for cluster membership; the surviving site plus witness forms a majority and can keep serving, while the isolated site is prevented from independently taking ownership. The witness is deployed outside the two replicated sites, so it remains reachable during a site-to-site partition. Asynchronous replication policies do not solve this problem because they only determine how often data is copied, not which site has voting authority during a partition. NearSync replication with a low RPO similarly addresses recovery point, not split-brain prevention, and cannot arbitrate cluster membership if both sites remain up. Waiting for manual failover after connectivity returns is a recovery action, not a protective mechanism, because both sites may have already accepted writes during the outage. Exam caveat: Metro questions often conflate availability, replication mode, and quorum, but only quorum behavior directly prevents split-brain. Operational check: confirm the witness is deployed, healthy, and reachable from both sites before conducting a partition test.