Pre-Summer Sale - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65percent

Welcome To DumpsPedia

NCP-NS-7.5 Sample Questions Answers

Questions 4

An administrator is deploying a multi-tier application on a Nutanix AHV cluster. The Web tier needs to be accessible from the internet, the App tier must communicate only with the Web tier and the Database tier, and the Database tier should accept traffic only from the App tier. The administrator must determine the correct configuration to ensure secure, reliable connectivity for the Web tier while maintaining isolation from the Internet for the App and Database tiers. Which connectivity option should the administrator implement to meet the requirements?

Options:

A.

Assign direct external IPs to all VMs in the VPC.

B.

Use overlay networks for the Web tier to provide internet access.

C.

Assign Floating IP assignments to Web tier only.

D.

Connect all tiers directly to the external network with no NAT.

Buy Now
Questions 5

An administrator creates a VPC named AppVPC1 in Nutanix Cloud Infrastructure (NCI) with separate subnets for the web, app, and database tiers. The database subnet must remain isolated from external networks; however, all tiers need to communicate with each other internally. What should the administrator configure to limit external access to only the web and app subnets?

Options:

A.

Enable NAT Gateway on the database subnet for outbound communication.

B.

Configure a routing policy in the VPC to deny external traffic to and from the database subnet.

C.

Attach the web and app subnets to the external network through an AHV managed bridge.

D.

Create Static Routes on the physical network to interconnect the VPC subnets.

Buy Now
Questions 6

An administrator sets up a VPN between two Nutanix VPCs in different Availability Zones. After deployment, the VPN tunnel shows as Up, but traffic between the VPCs is not flowing. Which configuration step is most likely missing?

Options:

A.

NAT policy on each of the VPC routers

B.

IPsec encryption settings on the VPN profile

C.

MTU adjustment on the AHV hosts

D.

Static routes for remote subnets on the VPC

Buy Now
Questions 7

An administrator has a VPC with multiple overlay subnets and a VPN gateway configured for site-to-site connectivity. During testing, the administrator noticed fragmented packets and poor performance. Which configuration change resolves this issue without disabling VPN?

Options:

A.

Increase MTU to 1500 on guest VMs

B.

Enable jumbo frames on VLAN subnets

C.

Reduce MTU to 1356 on guest VMs

D.

Disable Geneve encapsulation

Buy Now
Questions 8

An organization plans to apply security controls based on user group membership in Active Directory. What configuration is required in Prism Central before VDI policies can be used?

Options:

A.

Map category assignments to roles using RBAC settings.

B.

Create the list of users and assign categories to them.

C.

Assign categories to identities in the Admin Center.

D.

Configure category values mapped to AD groups.

Buy Now
Questions 9

An enterprise has deployed a VPC called FinanceVPC using Nutanix Flow Virtual Networking. The Finance team needs the following connectivity: Internal servers in the VPC must reach an on-premises corporate data-center via a point-to-point encrypted link. Some servers in the VPC must also access the public internet with source NAT and receive inbound access via floating IPs. The corporate network uses overlapping IP space with other VPCs in the environment, so address translation is necessary for those workloads. The networking design must support routing via BGP for future site expansions and provide low-latency north-south connectivity. Which actions should the administrator take to satisfy this requirement?

Options:

A.

Use two No-NAT External Networks—one for the on-prem link and one for Internet access; configure static routes for both without NAT.

B.

Use a single No-NAT External Network for both on-prem and Internet access; configure BGP and direct routing out to the internet without NAT.

C.

Use a No-NAT External Network for the on-premises link and a NAT External Network for Internet access. Configure a VPN tunnel to the on-premises location and enable BGP on the VPC router for the on-premises link.

D.

Use a single NAT External Network for both the on-prem link and Internet access; configure a default route to the external network and enable SNAT and floating IPs for all traffic.

Buy Now
Questions 10

An administrator creates a new VPC in No NAT mode to allow VMs in a web tier to reach an external firewall. After deployment... none of the VMs can reach external IP addresses... Which action should the administrator take to restore routed north-south connectivity from the VPC?

Options:

A.

Configure a Flow Security Policy to allow egress traffic from the VPC subnet.

B.

Create an Externally Routable Prefix (ERP) entry for the overlay subnet in the VPC.

C.

Change the VPC mode to NAT so that outbound traffic is automatically translated.

D.

Add a default static route in each VM pointing to the external firewall's IP address.

Buy Now
Questions 11

An administrator needs to configure a security policy that controls VM-to-VM communication within a category defined as secured entity. Which configuration action should the administrator take to restrict all intra-tier communication between the VMs within a category defined as secured entity?

Options:

A.

Apply the policy with inbound rules that block all inter-VM communication.

B.

Configure the security policy with allow-all intra-tier traffic.

C.

Set the security policy to allow-specific traffic for intra-tier communication.

D.

Use deny-all intra-tier traffic configuration in the policy.

Buy Now
Questions 12

An administrator plans to upgrade the Network Controller in a Flow Virtual Networking deployment. The environment includes multiple AHV clusters managed by Prism Central. Which prerequisite must be verified before upgrading the Network Controller?

Options:

A.

Flow Network Security must be upgraded to the target release before upgrading the Network Controller.

B.

Each cluster must be running the Flow Network Security version specified as compatible with the target Network Controller release.

C.

Each cluster must be running AHV versions compatible with the target Network Controller release.

D.

Network Controller Prism Element upgrades must be applied before before Network Controller Prism Central upgrades can be applied.

Buy Now
Questions 13

Flow Network Security Next-Gen is supported in which two environments? (Choose two.)

Options:

A.

On-Premises Overlay Networks

B.

NC2 VLAN Networks

C.

NC2 Overlay Networks

D.

On-Premises VLAN Basic Networks

Buy Now
Questions 14

Refer to Exhibit:

An administrator has been tasked with troubleshooting why the servers in the Web Category are not able to ping the servers in the App Category. Why is this issue occurring?

Options:

A.

ICMP is not allowed between the Web and App categories.

B.

The firewall on the App Servers is blocking Ping packets.

C.

Ping is not installed in the Web Servers.

D.

The servers are not in the same category.

Buy Now
Questions 15

Which statement is correct about cloning Application Security Policies?

Options:

A.

The system prevents saving the cloned policy if it has the same secured entities as the original.

B.

The policy type can be changed while cloning a policy.

C.

Only one policy can be cloned at a time.

D.

The default name of the cloned policy must be manually entered; the system does not provide a default.

Buy Now
Questions 16

An administrator configures a VPN gateway with eBGP for dynamic route exchange. After setup, routes are not advertised to the remote peer. Which configuration is most likely missing?

Options:

A.

DHCP options for assigning IP addresses to remote endpoints.

B.

ASN configuration for the local gateway to identify its autonomous system.

C.

VLAN ID alignment between local and remote networks.

D.

Peer IP address required for establishing the BGP session.

Buy Now
Questions 17

An administrator has been tasked with configuring virtual switches and setting the appropriate MTU size for a Nutanix cluster to optimize network performance. The cluster needs to support high-throughput traffic between VMs and ensure compatibility with external networks. The administrator needs to configure the virtual switches and MTU size to enable jumbo frames while ensuring that all nodes and network components are properly aligned to prevent packet loss or fragmentation. What is the first step to configure the virtual switches and MTU size in a Nutanix cluster for optimal network performance?

Options:

A.

Enable multicast filtering on the virtual switches to optimize MTU configuration.

B.

Set the MTU size to 1500 on the Nutanix virtual switches and configure a separate VLAN for MTU traffic.

C.

Set the MTU size to 1500 on all nodes and virtual switches for compatibility with external networks.

D.

Configure the MTU size to 9000 on all nodes and virtual switches, and verify that all physical network switches support jumbo frames.

Buy Now
Questions 18

Which step is required to prepare an AHV cluster for Flow Virtual Networking?

Options:

A.

Assign all VMs to a single VLAN before enabling Flow.

B.

Configure static routes for all overlay networks before enabling Flow.

C.

Disable all existing microsegmentation policies to allow virtual networking.

D.

Ensure all CVMs have network connectivity to Prism Central.

Buy Now
Questions 19

An administrator is designing a new Transit VPC to service multiple Tenant VPCs. While adding subnets, the administrator must choose the correct network type supported by Flow Virtual Networking for this VPC. Which network type is supported for subnets inside a Transit VPC in Flow Virtual Networking?

Options:

A.

Overlay subnets

B.

VLAN Basic subnets

C.

VLAN subnets

D.

VXLAN subnets

Buy Now
Questions 20

A VDI policy in Flow Network Security allows access to specific resources only when users from the Admins Active Directory group log into a VM. Some administrators report that when they log in to certain VMs, access is blocked (default deny applies), while the same user accounts work correctly when logged on to other VMs. When checking the VM details in Prism Central, operations observes that the expected dynamic category based on the logged-in AD user is not assigned on the affected VMs. What is the most likely reason for this behavior?

Options:

A.

The Admins group contains nested AD groups, and only the top-level group is synchronized by Prism Central.

B.

The Prism Central Active Directory service connection is misconfigured or has failed.

C.

The affected VMs allowed login using cached credentials without contacting the Domain Controller.

D.

The security policy is in Monitor mode, so the dynamic category assignment is not applied.

Buy Now
Questions 21

An administrator is deploying a new multi-tenant environment in Prism Central and has created a VPC named TenantVPC1. The administrator needs to enable external connectivity for this VPC so that some services inside the VPC can be accessed from the corporate network without NAT translation, while other services require Internet access through SNAT translation. The administrator plans to use an External Network(s) to provision this connectivity. Which configuration should the administrator apply to satisfy this requirement?

Options:

A.

Create two External Networks for TenantVPC1: one NAT (for Internet access) and one Routed/No-NAT (for corporate network access). Attach both to the VPC.

B.

Create two External Networks both of type Routed/No-NAT and attach both to TenantVPC1, one for corporate access and one for internet access.

C.

Create a single External Network of type NAT only and attach it to TenantVPC1. Define SNAT and Floating IPs for both the corporate-network services and internet-facing services.

D.

Create one External Network of type Routed/No-NAT only, attach to TenantVPC1, and configure routing policy to translate IP addresses for internet-facing services.

Buy Now
Questions 22

Which two options are supported as a Secured Entity in Flow Network Security Application Policies? (Choose two.)

Options:

A.

Subnet Category

B.

vNIC Category

C.

VPC Category

D.

VG Category

Buy Now
Questions 23

Exhibit:

An administrator has just added a new VPC for Tenant-B... However, users are reporting that they are unable to access external resources from VMs created in the Tenant-B-Prod subnet. What should be done to correct the problem?

Options:

A.

Update the ERPs for Tenant-B-VPC.

B.

Add a Network Policy in Tenant-B-VPC.

C.

Add a Network Policy in Transit-VPC.

D.

Update the ERPs for Transit-VPC.

Buy Now
Questions 24

Refer to Exhibit:

An administrator is tasked with configuring an application policy for a two-tier public website with Web and DB components. The database servers need to communicate with each other for replication, but the web servers should not be able to communicate with each other. The administrator configures the policy... and sets it to Enforce mode. Later testing reveals that the web servers are able to communicate with each other. What should the administrator do to resolve this?

Options:

A.

Create an isolation policy for the PubSite-Prod-Web entity group.

B.

Edit the PubSite-Prod-Web entity group's intra-tier rule.

C.

Configure a VPC Network Policy to deny the traffic.

D.

Ensure the PubSite-Prod-Web servers are in different Subnets.

Buy Now
Questions 25

An administrator uses Nutanix Flow to secure a three-tier application (Web, App, and Database tiers). After observing the traffic, they find that: The Web tier communicates with the App tier over HTTP (port 80) The App tier communicates with the Database tier over TCP port 1433 The Database tier does not initiate connections The Web tier receives inbound HTTP traffic from the corporate DMZ on port 8080 No other traffic should be allowed What should the administrator do to document and then securely apply these flows in Nutanix Flow?

Options:

A.

Use Flow Network Visualization to capture observed flows and convert them into microsegmentation security policies.

B.

Add all VMs to a single security policy to simplify communication.

C.

Disable traffic-flow discovery and configure all policies manually.

D.

Manually create isolation policies between all VMs in the environment.

Buy Now
Questions 26

What entity is automatically created on the cluster hosting Prism Central when Microsegmentation is enabled?

Options:

A.

A storage container named flow_data is created.

B.

A Bucket named flow_data is created.

C.

A File Share named flow_data is created.

D.

A virtual machine named flow_data is created.

Buy Now
Questions 27

When setting up a Network Function VM for Service Insertion, an administrator needs to configure the vNICs that will be used for redirecting traffic. What is the correct configuration for the vNICs on the Network Function VM?

Options:

A.

Two specific Network Function vNICs must be created, one for inbound traffic and the other for outbound traffic.

B.

A single vNIC of type Network Function is required, which handles both ingress and egress traffic.

C.

Two Network Function vNICs are required that must be assigned static IP addresses from a managed IPAM network.

D.

Two standard vNICs are required, one for ingress and one for egress and must be on a trunked VLAN.

Buy Now
Questions 28

Refer to Exhibit:

An organization uses an FNS-NG Service Chain to steer application traffic through a pair of third-party firewall Network Function VMs operating in Active/Standby mode. Users suddenly report that all application access is blocked. The administrator reviews Prism Central - > Network & Security - > Network Functions, where the summary shown in the exhibit is displayed. Additional information: Alert: "Network Function 'PANW Service Insertion' virtual NIC pair(s) are unhealthy." Both firewall VMs are powered on and reachable. The security policy using the service chain has not been changed. Based on the exhibit and findings, what is the most likely cause of the traffic outage?

Options:

A.

The service-chain health check failed to reroute sessions to the healthy firewall.

B.

One of the Network Function vNIC pairs lost dataplane connectivity, interrupting traffic until health is stabilized.

C.

Firewall policy synchronization was not configured when the standby firewall became active.

D.

The inbound vNIC on SE-PA-VM Firewall-2 failed, preventing redirected packets from reaching the firewall.

Buy Now
Questions 29

An administrator has a VPC with a single active gateway node that successfully peers with an external router using a single BGP GW and session. To eliminate a single point of failure, the administrator deploys a second BGP gateway to the VPC. After the second gateway is added and shows a healthy state, the external router still only sees a single BGP session. What is the most likely reason for the second session not being established on the external router?

Options:

A.

The BGP Hold-down timer on the external router is set too high.

B.

Network Security Groups are blocking BGP traffic from the second gateway's IP address.

C.

The external router needs BGP peering configuration pointing to the IP address of the first gateway node.

D.

The second BGP gateway requires a BGP session configured to peer with the external router.

Buy Now
Questions 30

A newly-deployed Flow Virtual Networking VPC environment is experiencing connectivity issues... A packet capture on the physical switch shows packets are being fragmented. What is the probable cause of the packet fragmentation and performance issues?

Options:

A.

A Network Security Group is incorrectly filtering IP fragments.

B.

The MTU on the physical or virtual switch layer is set too low.

C.

The VM's guest OS network driver is faulty and requires an update.

D.

The VPC's external network uplink has an incorrect VLAN ID configured.

Buy Now
Exam Code: NCP-NS-7.5
Exam Name: Nutanix Certified Professional - Network and Security (NCP-NS) 7.5
Last Update: May 25, 2026
Questions: 106
$64.4  $183.99
$49.35  $140.99
$44.8  $127.99
buy now NCP-NS-7.5