Valid NCP-NS Test Answers & Nutanix NCP-NS Exam PDF [Q22-Q45]

Share

Valid NCP-NS Test Answers & Nutanix NCP-NS Exam PDF

Nutanix NCP-NS Certification Real 2026 Mock Exam

NEW QUESTION # 22
An administrator needs to delegate the management of security policies to a dedicated SecOps team. To enforce the principle of least privilege, the administrator assigns the predefined Flow Policy Author role to a user on the team.
The user confirms they can create, monitor, and enforce security policies. However, when attempting to build a new application security policy for a set of newly deployed VMs, the user reports they are unable to create a new category to group these VMs. The option is not available in the Prism Central UI.
Which statement explains this behavior?

  • A. The user's role must be assigned with a scope for the specific projects they manage.
  • B. The Flow Policy Author role can only apply policies to existing categories by design.
  • C. The Flow Policy Author role must be cloned into a custom role before it can be used.
  • D. The user is missing the Flow Admin role, which is required for category management.

Answer: D


NEW QUESTION # 23
Refer to the exhibit.

How should an Application Policy be created whose rules apply only to vNIC1 of VM1?

  • A. Add Cat:SubnetA as secured entity in the Application Policy.
  • B. Create an Entity Group with Cat:SubnetA, Cat:SubnetB and Cat:VM1 and then add the Entity Group as Secured Entity to the Application Policy.
  • C. Create an Entity Group with Cat:SubnetA and Cat:VM1 and then add the Entity Group as Secured Entity to the Application Policy.
  • D. Add Cat:SubnetA and Cat:VM1 as secured entity in the Application Policy.

Answer: C


NEW QUESTION # 24
An administrator needs to configure a security policy that controls VM-to-VM communication within a category defined as secured entity.
Which configuration action should the administrator take to restrict all intra-tier communication between the VMs within a category defined as secured entity?

  • A. Configure the security policy with allow-all intra-tier traffic.
  • B. Apply the policy with inbound rules that block all inter-VM communication.
  • C. Use deny-all intra-tier traffic configuration in the policy.
  • D. Set the security policy to allow-specific traffic for intra-tier communication.

Answer: C


NEW QUESTION # 25
An administrator sets up a VPN between two Nutanix VPCs in different Availability Zones. After deployment, the VPN tunnel shows as Up, but traffic between the VPCs is not flowing.
Which configuration step is most likely missing?

  • A. IPsec encryption settings on the VPN profile
  • B. Static routes for remote subnets on the VPC
  • C. NAT policy on each of the VPC routers
  • D. MTU adjustment on the AHV hosts

Answer: B


NEW QUESTION # 26
An administrator has a VPC with a single active gateway node that successfully peers with an external router using a single BGP GW and session.
To eliminate a single point of failure, the administrator deploys a second BGP gateway to the VPC. After the second gateway is added and shows a healthy state, the external router still only sees a single BGP session.
What is the most likely reason for the second session not being established on the external router?

  • A. The second BGP gateway requires a BGP session configured to peer with the external router.
  • B. The external router needs BGP peering configuration pointing to the IP address of the first gateway node.
  • C. The BGP Hold-down timer on the external router is set too high.
  • D. Network Security Groups are blocking BGP traffic from the second gateway's IP address.

Answer: A


NEW QUESTION # 27
Which policy mode records traffic without enforcing rule actions?

  • A. Save
  • B. Enforce
  • C. Monitor
  • D. Isolate

Answer: C


NEW QUESTION # 28
While configuring a new security policy in a Nutanix microsegmentation environment, an administrator wants the policy to remain flexible even if virtual machines change subnets or obtain new IP addresses.
Which configuration approach should the administrator use when defining the policy scope?

  • A. Apply the policy after setting static routes for each VM.
  • B. Assign IP addresses manually to all VMs included in the policy.
  • C. Configure the policy only on specific VLAN IDs.
  • D. Use VM categories to define the secured and allowed entities.

Answer: D


NEW QUESTION # 29
Which policy is used to isolate a compromised VM in the most efficient way possible?

  • A. Application Policy
  • B. Isolation Policy
  • C. Shared Service Policy
  • D. Quarantine Policy

Answer: D


NEW QUESTION # 30
An administrator configures a VPN gateway with eBGP for dynamic route exchange. After setup, routes are not advertised to the remote peer.
Which configuration is most likely missing?

  • A. ASN configuration for the local gateway to identify its autonomous system.
  • B. VLAN ID alignment between local and remote networks.
  • C. DHCP options for assigning IP addresses to remote endpoints.
  • D. Peer IP address required for establishing the BGP session.

Answer: A


NEW QUESTION # 31
An administrator is designing a VPC for a three-tier application. The workloads must communicate with the Internet using source NAT and also communicate with on-premises networks 10.50.0.0/16 and 172.20.32.0/20 with no address translation. In the Create VPC dialog, the administrator can associate external subnets and specify destination prefixes.
Which configuration satisfies the requirements?

  • A. Associate a NAT external network only; set Destination Prefixes to 0.0.0.0/0, 10.50.0.0/16, 172.20.32.0/20.
  • B. Associate a NONAT external network only; set Destination Prefixes to 0.0.0.0/0.
  • C. Associate a NONAT external network for 0.0.0.0/0 and a NAT external network for 10.50.0.0/16, 172.20.32.0/20.
  • D. Associate a NAT external network for 0.0.0.0/0 and a NONAT external network for 10.50.0.0/16, 172.20.32.0/20.

Answer: D


NEW QUESTION # 32
An administrator must delegate management of a single tenant VPC to a junior engineer. The engineer should be able to modify that VPC but must not see or change any other VPCs or networking configurations in Prism Central.
The administrator wants to meet this requirement using RBAC.
Which action should the administrator take to meet this requirement?

  • A. Assign a Custom Role cloned from VPC Admin and restrict its scope to the desired VPC.
  • B. Assign the Network Infrastructure Admin role and restrict its scope to the desired VPC.
  • C. Assign a Custom Role cloned from Network Infrastructure Admin and restrict its scope to the desired VP
  • D. Assign the VPC Admin role and restrict its scope to the desired VPC.

Answer: D


NEW QUESTION # 33
An organization plans to apply security controls based on user group membership in Active Directory.
What configuration is required in Prism Central before VDI policies can be used?

  • A. Configure category values mapped to AD groups.
  • B. Map category assignments to roles using RBAC settings.
  • C. Assign categories to identities in the Admin Center.
  • D. Create the list of users and assign categories to them.

Answer: A


NEW QUESTION # 34
An administrator is setting up a transit VPC to connect two VPCs and enable both internal (on-prem) and Internet connectivity.
Which is the best configuration to meet the requirement?

  • A. Configure the transit VPC with two NAT External Subnets to support redundancy for internet connectivity.
  • B. Configure the transit VPC with one NAT External Subnet and one No-NAT External Subnet, each serving different traffic types.
  • C. Configure the transit VPC with a single No-NAT External Subnet to handle both internal and internet traffic.
  • D. Configure the transit VPC with two No-NAT Overlay External Subnets for both Internet and on-prem traffic.

Answer: B


NEW QUESTION # 35
Refer to th exhibit.

An administrator needs to setup a Syslog server to capture the Flow Network Security Hit logs. Which module name should be selected?

  • A. Flow Service Logs
  • B. Security Policy Hit logs
  • C. API Audit
  • D. Audit

Answer: B


NEW QUESTION # 36
An administrator wants to configure the subnet 10.1.1.0/24 to stretch across two VPCs over a Network Gateway in VXLAN mode. The VMs on this subnet need to communicate with a traffic pattern of size 2000 Bytes.
What is the minimum MTU required in the underlay network to ensure communication happens without fragmentation or traffic drops?

  • A. 9216 Bytes
  • B. 2116 Bytes
  • C. 2058 Bytes
  • D. 2108 Bytes

Answer: C


NEW QUESTION # 37
An administrator has just added a new VPC for Tenant-B... However, users are reporting that they are unable to access external resources from VMs created in the Tenant-B-Prod subnet.
What should be done to correct the problem?

  • A. Update the ERPs for Tenant-B-VPC.
  • B. Update the ERPs for Transit-VPC.
  • C. Add a Network Policy in Transit-VP
  • D. Add a Network Policy in Tenant-B-VPC.

Answer: A


NEW QUESTION # 38
An administrator is using Flow Network Security to secure a 3-tier application and has already created and assigned the categories. The administrator does not have the details of the rules that need to be allowed to secure the application.
How can the administrator use Flow Network Security to monitor the traffic and help with the policy creation without impacting the applications connectivity?

  • A. Use service insertion to redirect traffic through a monitoring service to capture the application traffic and create the Flow Network Security policy based on data captured in monitoring service.
  • B. Create the Policy in Monitor mode, review the discovered traffic, allow the required traffic flows, and move Policy to Enforce mode.
  • C. Redirect the traffic to a Syslog server and monitor the traffic on the syslog server and then create the Flow Network Security policy based on monitored data in syslog server.
  • D. Create the Policy in Save mode, review the discovered traffic, allow the required traffic flows, and move Policy to Enforce mode.

Answer: B


NEW QUESTION # 39
An administrator is building a new VPC in Prism Central to isolate a test environment. The administrator plans to connect it to an external network later, but they want to complete the initial creation first.
Which configuration items are the minimum required to successfully create the VPC?

  • A. VPC name and Transit VPC toggle switch
  • B. VPC name and cluster selection
  • C. VPC name and one External Access VLAN
  • D. VPC name and one Overlay Subnet

Answer: C


NEW QUESTION # 40
An administrator is designing a Transit VPC to provide shared corporate services (e.g., DNS) for two tenant VPCs:
VPC-A requires WAN access using NAT.
VPC-B requires WAN access without NAT.
Both VPCs connect to the Transit VPC for shared services hosted on the corporate network.
Shared services residing in the Transit VPC use routed IP addressing for WAN connectivity.
Which two configuration elements should the administrator implement on the Transit VPC? (Choose two.)

  • A. Associate one No-NAT external VLAN to the Transit VPC router for underlay connectivity.
  • B. Use one Overlay external subnet in the Transit VPC to which both VPCs will connect.
  • C. Create two Overlay external subnets in the Transit VPC: one for VPC-A and one for VPC-
  • D. Associate both a NAT and a No-NAT external VLAN to the Transit VPC to support separate egress paths.

Answer: A,B


NEW QUESTION # 41
Which policy mode blocks all traffic that is not explicitly allowed by the policy?

  • A. Block Mode
  • B. Enforce Mode
  • C. Monitor Mode
  • D. Save Mode

Answer: B


NEW QUESTION # 42
An administrator creates a new VPC in No NAT mode to allow VMs in a web tier to reach an external firewall.
After deployment... none of the VMs can reach external IP addresses...
Which action should the administrator take to restore routed north-south connectivity from the VPC?

  • A. Change the VPC mode to NAT so that outbound traffic is automatically translated.
  • B. Configure a Flow Security Policy to allow egress traffic from the VPC subnet.
  • C. Add a default static route in each VM pointing to the external firewall's IP address.
  • D. Create an Externally Routable Prefix (ERP) entry for the overlay subnet in the VPC.

Answer: D


NEW QUESTION # 43
Users have recently reported intermittent connectivity issues and slower-than-usual application performance for a Nutanix cluster to an administrator. The administrator needs to identify the root cause of these issues by analyzing the health of the infrastructure components.
What action should the administrator take first to diagnose the root cause of the problem?

  • A. Review cluster health status, checking for any warnings or alerts relevant to the performance issues.
  • B. Reboot the Nutanix cluster nodes to clear any potential performance-related cache or memory issues.
  • C. Enable network QoS to prioritize the performance of critical applications.
  • D. Rebalance virtual machines across the cluster to balance resource load and improve performance.

Answer: A


NEW QUESTION # 44
A customer wants to extend a VLAN subnet to a remote data center using VTEP. The administrator configures a Subnet Extension which shows UP in the Prism Interface, yet traffic fails to pass.
Which setting is most likely misconfigured?

  • A. VXLAN UDP port is set to 4789.
  • B. Route Policy for VTEP has not been configured.
  • C. Remote gateway IP address has not been configured.
  • D. VLAN ID does not match in the remote data center.

Answer: D


NEW QUESTION # 45
......


Nutanix NCP-NS Exam Syllabus Topics:

TopicDetails
Topic 1
  • Troubleshoot Flow Virtual Networking: Covers diagnosing and resolving connectivity failures, BGP issues, gateway health problems, and interpreting alerts and logs related to virtual networking components.
Topic 2
  • Deploy and Upgrade a Flow Environment: Covers preparing clusters for Flow Network Security and Virtual Networking, managing upgrade paths and dependencies, configuring virtual switches and MTU, and administering user roles and RBAC permissions.
Topic 3
  • Troubleshoot Flow Network Security: Covers identifying policy-related traffic issues, analyzing security hit logs and audit logs, and troubleshooting identity based policy failures tied to Active Directory group mapping.
Topic 4
  • Configure Flow Virtual Networking: Covers creating and managing VPCs, overlay networks, external connectivity options, BGP peering, load balancing, and policy based routing within Nutanix Flow Virtual Networking.
Topic 5
  • Configure Flow Network Security: Covers analyzing application traffic flows, creating and configuring isolation, application, and identity based security policies, and managing policy lifecycle modes in Flow Network Security.

 

NCP-NS Exam Questions and Valid NCP-NS Dumps PDF: https://examcollection.dumpsactual.com/NCP-NS-actualtests-dumps.html