Pre-Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

NCP-NS-7.5 Nutanix Certified Professional - Network and Security (NCP-NS) 7.5 Questions and Answers

Questions 4

While configuring third-party services (Service Insertion) in Flow Network Security Next-Gen, an administrator notices dropped packets when redirecting traffic through a network function. Which configuration change would address this issue?

Options:

A.

Reduce the MTU size to 1400 to match Geneve encapsulation.

B.

Disable Geneve tunneling on the virtual switch.

C.

Increase the MTU by an additional 58 bytes for the Geneve header.

D.

Keep the default MTU at 1500. Encapsulation is handled automatically.

Buy Now
Questions 5

A VPC admin creates a policy to allow traffic between two IP subnets but forgets to enable reverse direction. What happens in this scenario?

Options:

A.

Traffic is blocked completely because the policy is invalid.

B.

Policy is rejected by Prism Central during validation.

C.

Traffic flows bidirectionally because policies are stateful by default.

D.

Traffic flows only in one direction, blocking return traffic.

Buy Now
Questions 6

What is the role of the Network Controller in Flow Virtual Networking?

Options:

A.

Distribute the network traffic load across multiple guest VMs efficiently.

B.

It enables you to configure and manage common administrative tasks that are applicable to the platform and various Nutanix apps.

C.

It is used to create VPN, VTEP, or BGP gateways to connect subnets using VPN connections, Layer 2 subnet extensions over VPN or VTEP, or over BGP session.

D.

It manages configuration, monitoring, and optimization of network resources.

Buy Now
Questions 7

Which prerequisite is required before enabling Flow Network Security Next-Gen micro segmentation?

Options:

A.

Network Controller must be enabled in Prism Central.

B.

All workloads should be on VLAN networks.

C.

A Flow license is optional and cannot be installed later.

D.

The environment must use ESXi as the hypervisor.

Buy Now
Questions 8

An administrator is deploying a new multi-tenant environment in Prism Central and has created a VPC named TenantVPC1. The administrator needs to enable external connectivity for this VPC so that some services inside the VPC can be accessed from the corporate network without NAT translation, while other services require Internet access through SNAT translation. The administrator plans to use an External Network(s) to provision this connectivity. Which configuration should the administrator apply to satisfy this requirement?

Options:

A.

Create two External Networks for TenantVPC1: one NAT (for Internet access) and one Routed/No-NAT (for corporate network access). Attach both to the VPC.

B.

Create two External Networks both of type Routed/No-NAT and attach both to TenantVPC1, one for corporate access and one for internet access.

C.

Create a single External Network of type NAT only and attach it to TenantVPC1. Define SNAT and Floating IPs for both the corporate-network services and internet-facing services.

D.

Create one External Network of type Routed/No-NAT only, attach to TenantVPC1, and configure routing policy to translate IP addresses for internet-facing services.

Buy Now
Questions 9

Which statement best describes the function of an External Network in Flow Virtual Networking?

Options:

A.

It acts as the entry and exit point for traffic to and from a VPC.

B.

It enables communication between subnets within a VPC.

C.

It enables communication between VPCs.

D.

Each VPC requires a dedicated External Network that cannot be shared.

Buy Now
Questions 10

An administrator manages a four-node cluster Each node has a 4 available 10GB uplinks, and all four are configured as an Active/Active bundle. They want to use Flow Virtual Networking to provide networking to the VMs in the cluster with the following requirements: VMs should be in a single VPC. VMs should be reachable by their real IP addresses. The VPC should have access to the most north/south bandwidth possible. No changes can be made to the physical infrastructure. How can this best be achieved?

Options:

A.

Create a VPC with a single No-NAT External Network with three gateway nodes.

B.

Create a VPC with four No-NAT External Networks, each with a single gateway node.

C.

Create a VPC with a single No-NAT External Network with four gateway nodes.

D.

Create a VPC with a single NAT External Network with three gateway nodes.

Buy Now
Questions 11

Which policy mode records traffic without enforcing rule actions?

Options:

A.

Enforce

B.

Monitor

C.

Isolate

D.

Save

Buy Now
Questions 12

An administrator needs to make a web server VM, which is inside a private VPC overlay subnet, accessible from the external network. The administrator assigns a Floating IP to the VM, but the service is still unreachable from the outside. What is a likely reason for this failure?

Options:

A.

A Floating IP was assigned from a different external subnet than the one used by the VPC.

B.

The VPC has no default route configured to use the external subnet.

C.

The VM was not rebooted after the Floating IP was assigned.

D.

The web server VM is not running the latest version of NGT.

Buy Now
Questions 13

An administrator has a VPC with a single active gateway node that successfully peers with an external router using a single BGP GW and session. To eliminate a single point of failure, the administrator deploys a second BGP gateway to the VPC. After the second gateway is added and shows a healthy state, the external router still only sees a single BGP session. What is the most likely reason for the second session not being established on the external router?

Options:

A.

The BGP Hold-down timer on the external router is set too high.

B.

Network Security Groups are blocking BGP traffic from the second gateway's IP address.

C.

The external router needs BGP peering configuration pointing to the IP address of the first gateway node.

D.

The second BGP gateway requires a BGP session configured to peer with the external router.

Buy Now
Questions 14

Refer to Exhibit:

NCP-NS-7.5 Question 14

An administrator is tasked with configuring an application policy for a two-tier public website with Web and DB components. The database servers need to communicate with each other for replication, but the web servers should not be able to communicate with each other. The administrator configures the policy... and sets it to Enforce mode. Later testing reveals that the web servers are able to communicate with each other. What should the administrator do to resolve this?

Options:

A.

Create an isolation policy for the PubSite-Prod-Web entity group.

B.

Edit the PubSite-Prod-Web entity group's intra-tier rule.

C.

Configure a VPC Network Policy to deny the traffic.

D.

Ensure the PubSite-Prod-Web servers are in different Subnets.

Buy Now
Questions 15

Exhibit:

NCP-NS-7.5 Question 15

An administrator has just added a new VPC for Tenant-B... However, users are reporting that they are unable to access external resources from VMs created in the Tenant-B-Prod subnet. What should be done to correct the problem?

Options:

A.

Update the ERPs for Tenant-B-VPC.

B.

Add a Network Policy in Tenant-B-VPC.

C.

Add a Network Policy in Transit-VPC.

D.

Update the ERPs for Transit-VPC.

Buy Now
Questions 16

An administrator is deploying a multi-tier (web, app, database) application on a Nutanix cluster using AHV. The administrator needs to allow internal communication between tiers and provide external access to the web tier. How should the administrator satisfy this requirement?

Options:

A.

Create separate VLAN networks for each tier and configure routing on the physical network.

B.

Create a VPC with a single subnet and assign workloads of each tier to this subnet.

C.

Create separate VPCs for each tier and connect them to the same external NAT network and configure routing policies for inter-tier traffic.

D.

Create a VPC with subnets for each tier and configure the Externally Routable Prefix to include only web subnets.

Buy Now
Questions 17

A VM with IP address 172.20.10.5 on a Subnet with CIDR 172.20.10.0/24 is unable to be routed externally from the VPC. The VPC is successfully peered via BGP... However, when checking the BGP Session, no routes are being advertised by the VPC. What is the most likely configuration issue?

Options:

A.

There is no default route within the VPC to send traffic to the NAT external network.

B.

The VM does not have a Floating IP assigned to allow external connectivity.

C.

The VPC does not have a NO-NAT network configured to advertise the routes.

D.

A network Policy is blocking outbound access for the VM.

Buy Now
Questions 18

An administrator wants to configure the subnet 10.1.1.0/24 to stretch across two VPCs over a Network Gateway in VXLAN mode. The VMs on this subnet need to communicate with a traffic pattern of size 2000 Bytes. What is the minimum MTU required in the underlay network to ensure communication happens without fragmentation or traffic drops?

Options:

A.

2058 Bytes

B.

2108 Bytes

C.

2116 Bytes

D.

9216 Bytes

Buy Now
Questions 19

An administrator has configured a VPC with multiple overlay subnets and attached a VPN gateway using IPSec. After enabling Jumbo Frames on the physical network, VMs are still experiencing packet drops. What is the most likely reason?

Options:

A.

MTU on guest VMs exceeds recommended size for IPSec.

B.

DHCP relay is misconfigured.

C.

Jumbo frames are not supported on overlay subnets.

D.

Floating IP is missing on the VPN gateway.

Buy Now
Questions 20

When creating a VPC, enabling the Transit VPC toggle changes the role of the VPC. What does the Transit VPC toggle do?

Options:

A.

Forces NAT for all external subnets

B.

Creates a hub-and-spoke VPC for routing

C.

Converts all Overlay subnets into VLAN subnets

D.

Enables DHCP relay for routed subnets

Buy Now
Questions 21

An administrator is building a new VPC in Prism Central to isolate a test environment. The administrator plans to connect it to an external network later, but they want to complete the initial creation first. Which configuration items are the minimum required to successfully create the VPC?

Options:

A.

VPC name and one External Access VLAN

B.

VPC name and Transit VPC toggle switch

C.

VPC name and one Overlay Subnet

D.

VPC name and cluster selection

Buy Now
Questions 22

An administrator is building a VPC... VPC CIDR: 10.10.0.0/16 Subnet CIDR: 10.10.10.0/24 "Ext_Net_Ext" (NAT): 192.168.1.0/24 "Ext_Net_Internal" (Routed): 172.16.1.0/24 The on-premises application server has an IP address of 172.16.2.50/24. A VM (10.10.10.100) in the VPC Subnet can reach the internet but cannot reach the on-premises server. Which static route needs to be added to the VPC route table to resolve this?

Options:

A.

Destination prefix: 172.16.2.0/24, Next-Hop: Ext_Net_Ext

B.

Destination Prefix: 10.10.0.0/16, Next-Hop: Ext_Net_Internal

C.

Destination prefix: 192.168.1.0/24 Next-Hop: Ext_Net_Ext

D.

Destination prefix: 172.16.2.0/24, Next-Hop: Ext_Net_Internal

Buy Now
Questions 23

A customer wants to migrate VMs from a VLAN Basic Subnet to an Overlay Subnet with the same IP prefix. Which migration approach ensures minimal disruption?

Options:

A.

Perform cold migration, acknowledging that ingress/egress connections will not be preserved.

B.

Enable trunk mode on VLAN to allow multiple subnets on the same interface.

C.

Change IPAM mode to unmanaged to allow manual IP assignment.

D.

Create a Layer 2 connectivity between the subnets and perform live migration.

Buy Now
Questions 24

An administrator has deployed a VPC for a multi-tier application on Nutanix AHV. The Web tier requires public internet access, while the App and Database tiers must remain private and isolated. Which steps should the administrator take to configure the external network correctly?

Options:

A.

Use overlay networks for external access instead of configuring a VPC external network.

B.

Assign external IPs to all VMs in the VPC to simplify connectivity.

C.

Configure an external network for the Web tier subnet and leave App and Database tiers private.

D.

Attach a single external network to the VPC and allow all tiers unrestricted internet access.

Buy Now
Questions 25

Users have recently reported intermittent connectivity issues and slower-than-usual application performance for a Nutanix cluster to an administrator. The administrator needs to identify the root cause of these issues by analyzing the health of the infrastructure components. What action should the administrator take first to diagnose the root cause of the problem?

Options:

A.

Review cluster health status, checking for any warnings or alerts relevant to the performance issues.

B.

Enable network QoS to prioritize the performance of critical applications.

C.

Rebalance virtual machines across the cluster to balance resource load and improve performance.

D.

Reboot the Nutanix cluster nodes to clear any potential performance-related cache or memory issues.

Buy Now
Questions 26

Which two statements are true with respect to Flow Network Security Policies? (Choose two.)

Options:

A.

Flow Network Security is a stateful firewall.

B.

Flow Network Security supports L3 and L4-based firewall rules.

C.

Flow Network Security supports L7-based firewall rules.

D.

Flow Network Security supports rules based on L2 MAC Addresses.

Buy Now
Questions 27

The alert details mention a specific external network. Attempts to assign new Floating IPs to VMs fail, but existing Floating IPs continue to work. What is the cause of this alert?

Options:

A.

A firewall is blocking communication between Prism Central and the VPC's virtual router.

B.

The VPC's connection to the external network is down.

C.

A firewall is blocking communication between Prism Central and the VPC's virtual router.

D.

There are no more available IP addresses in the address pool configured for Floating IPs in that external network.

Buy Now
Questions 28

A customer wants to extend a VLAN subnet to a remote data center using VTEP. The administrator configures a Subnet Extension which shows UP in the Prism Interface, yet traffic fails to pass. Which setting is most likely misconfigured?

Options:

A.

Route Policy for VTEP has not been configured.

B.

VLAN ID does not match in the remote data center.

C.

Remote gateway IP address has not been configured.

D.

VXLAN UDP port is set to 4789.

Buy Now
Questions 29

An administrator has configured a VPC and associated a NAT external network. A virtual machine connected to a subnet within this VPC is required to be accessible externally. What action must the administrator take to accomplish this?

Options:

A.

Configure a static route on the VPC's routing table.

B.

Create a Network Security Group allowing inbound traffic.

C.

Assign a Floating IP address to the virtual machine.

D.

Attach a second interface to the virtual machine.

Buy Now
Questions 30

What is the first step in preparing a Nutanix cluster for Flow Virtual Networking?

Options:

A.

Enable the Network Controller in Prism Central.

B.

Install the latest version of Acropolis OS (AOS) on all nodes.

C.

Install the Nutanix Flow Controller on all cluster nodes.

D.

Configure the VLANs on the physical network switches.

Buy Now
Questions 31

An administrator has two user VPCs connected via a Transit VPC. Routing works for most subnets, but one overlay subnet cannot reach external networks. What is the most probable cause?

Options:

A.

Incorrect ASN in the BGP configuration in the Transit VPC

B.

Mismatch in ERP configuration in user and Transit VPC

C.

Floating IP not assigned to the gateway

D.

DHCP configuration is disabled on the overlay subnet in the user VPC

Buy Now
Exam Code: NCP-NS-7.5
Exam Name: Nutanix Certified Professional - Network and Security (NCP-NS) 7.5
Last Update: May 30, 2026
Questions: 106

PDF + Testing Engine

$134.99

Testing Engine

$99.99

PDF (Q&A)

$84.99