Academy/VCDX Defense Preparation/Lab C3: Design Scenario — Regulated Industry (Healthcare + Middle East Data Residency)
This lab targets VCF 9.0

Lab C3: Design Scenario — Regulated Industry (Healthcare + Middle East Data Residency)

VCF 9.0Intermediatevcdx-distinguished⏱ 90 min

Objectives

  • Design a VCF 9.0 architecture for a UAE healthcare customer (parallel to MOHAP constraints).

Prerequisites

VCF lab environment deployed and operational

Lab Environment

Standard VCF lab environment for VCDX Defense Preparation

Tasks

Task 1 Lab C3: Design Scenario — Regulated Industry (Healthcare + Middle East Data Residency)

Design a VCF 9.0 architecture for a UAE healthcare customer (parallel to MOHAP constraints).

Step 1

Capture constraints: data residency (UAE), MoH cybersecurity framework, ADHICS compliance.

Step 2

Design isolated management and workload domains with NSX + vDefend zero-trust.

Step 3

Size vSAN ESA for 700 workloads with 3-year growth; pick OSA vs ESA vs Max with rationale.

Step 4

Design HCX RAV migration waves from source vSphere 7.x and write cut-over runbook.

Step 5

Include DR design (secondary site or cloud) with stretched cluster + NSX Federation.

Step 6

Document which compliance controls each design decision satisfies.

Validation Gate

Check: Verify lab completion

Expected: Lab exercise completed successfully

Common Errors

Healthcare design without explicit HIPAA control mapping
Fix: A healthcare VCF design must map each HIPAA technical safeguard to a specific design element: encryption at rest (vSAN encryption → §164.312(a)(2)(iv)), access controls (NSX DFW + vCenter RBAC → §164.312(a)(1)), audit logging (VCF Operations + syslog → §164.312(b)). Panelists will ask: 'Show me where HIPAA §164.312(a)(1) is addressed in your design.'
Not addressing BAA (Business Associate Agreement) implications in the design
Fix: If any component of the design involves a third-party service (cloud DR, managed backup, SaaS monitoring), HIPAA requires a BAA with that provider. Document: which design components involve third parties, whether BAAs are in place, and what happens if a BAA is not available (design alternative).
PHI data flow not mapped end-to-end
Fix: Map where PHI data exists (at rest), moves (in transit), and is processed (in use) through the entire design. Each PHI touchpoint must have: encryption (at rest and in transit), access control (RBAC), and audit logging. A gap in the PHI data flow map is a HIPAA compliance gap.

Final Validation

Lab completed successfully

✓ All steps completed → No errors observed

Cleanup / Restore

• Revert to snapshot if needed

Design Reflection (VCDX)

Regulated industry design scenarios test compliance awareness beyond technical architecture. VCDX panelists want to see that regulatory requirements drive design decisions, not just technology features.

⚠ Known Pitfalls (from Community KB)

Designing for healthcare without explicitly mapping HIPAA controls — panelists will find the gaps.
Ignoring BAA requirements for third-party components in the design — this is a compliance blind spot.
Was this page useful?
Type to search. ↑ ↓ to move, Enter to open, Esc to close.