A Nutanix admin protects production VMs with protection-domain snapshots and backups to an external target. Management requires backup copies to remain undeletable for 90 days even if attackers compromise administrator accounts. Which retention design best satisfies this requirement?
Select an answer to reveal the explanation.
Short Explanation
Think of ransomware as an attacker who can delete, not just read. You need retention that says 'no take-backs,' so immutable backup copies stay locked until the clock runs out. More snapshots or replication helps recovery, but it does not stop deletion.
Full Explanation
Immutable or locked retention makes backup copies write-once/read-many for a defined period, so even privileged users or compromised automation cannot delete them before the retention timer expires. In a ransomware scenario, that property matters more than speed or encryption because the attacker's next action after encrypting production is often to destroy local snapshots, protection-domain backups, or external backup copies. Increasing snapshot frequency and extending local retention creates more recovery points, but those snapshots remain mutable if credentials or cluster controls are compromised. Async replication to another site improves geographic availability and can provide a clean copy, yet it does not make the backup target immutable unless the target itself enforces locking or immutability. Encryption and credential rotation protect confidentiality and reduce unauthorized access, but they do not prevent an authorized or stolen administrative identity from deleting retention-managed data. Exam caveat: the requirement is ransomware-resistant retention, not merely faster recovery or encrypted transport. Operational check: confirm the backup repository or external object target supports object lock/immutable retention, set the retention period to the required number of days, and attempt a deletion test from a privileged account before the period expires.