A security reviewer asks for a record of administrative changes to cluster settings over the last 30 days. You must provide evidence without exporting performance data. Which source best satisfies this request?
Select an answer to reveal the explanation.
Short Explanation
Think of this like a building access log: you want to know who changed the lock settings, not how noisy the elevator was. Audit logs record admin actions, while metrics don't show who changed a setting. If you hand over performance graphs, you haven't answered the question.
Full Explanation
Administrative change evidence is best obtained from audit log entries because they record user or API actions that modify configuration, including identity, timestamp, and affected object. In a Nutanix Prism environment, you would review the audit log for configuration-related entries and correlate them with the requested date range to show who changed cluster settings and when. NCC health check results are wrong because they evaluate the current health and compliance posture of the cluster, not a historical ledger of administrator actions. Performance metrics are wrong because they describe CPU, memory, storage latency, or capacity behavior over time, which cannot prove who changed a setting. LCM pre-check results are wrong because they assess readiness for software updates and may mention configuration issues, but they do not provide a general record of administrative changes to cluster settings. Exam caveat: if a question asks for accountability for changes, choose audit or event history, not performance or health-check output. Operational check: export or view audit log entries for the relevant window and verify that each entry includes actor, action, and target.