Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

NCP-NS-7.5 Nutanix Certified Professional - Network and Security (NCP-NS) 7.5 Questions and Answers

Questions 4

During a security review, the administrator confirms that the existing security policy does not explicitly allow traffic from Environment: Development to Environment: Production. A VM in the Development category was still able to reach a Production VM over IPv6. What is the most likely cause of this behavior?

Options:

A.

An isolation policy was incorrectly applied instead of an application policy.

B.

The Allow All IPv6 option in the policy was selected.

C.

The policy was misconfigured and allowed all Layer 2 broadcast traffic.

D.

The VM was using a static IPv6 address.

Buy Now
Questions 5

An administrator has two user VPCs connected via a Transit VPC. Routing works for most subnets, but one overlay subnet cannot reach external networks. What is the most probable cause?

Options:

A.

Incorrect ASN in the BGP configuration in the Transit VPC

B.

Mismatch in ERP configuration in user and Transit VPC

C.

Floating IP not assigned to the gateway

D.

DHCP configuration is disabled on the overlay subnet in the user VPC

Buy Now
Questions 6

While configuring a new security policy in a Nutanix microsegmentation environment, an administrator wants the policy to remain flexible even if virtual machines change subnets or obtain new IP addresses. Which configuration approach should the administrator use when defining the policy scope?

Options:

A.

Configure the policy only on specific VLAN IDs.

B.

Use VM categories to define the secured and allowed entities.

C.

Apply the policy after setting static routes for each VM.

D.

Assign IP addresses manually to all VMs included in the policy.

Buy Now
Questions 7

An administrator has observed the following message: Which two statements most accurately describe the security hitlog captured above? (Choose two.)

Options:

A.

This is a security hit log on the rule name "Production-External-WebTier".

B.

The source ip address is 10.38.174.5 and source port is TCP/123.

C.

86.108.190.23 is sending a packet on UDP 123.

D.

10.38.174.57 is sending a packet destined to UDP 123.

Buy Now
Questions 8

While configuring third-party services (Service Insertion) in Flow Network Security Next-Gen, an administrator notices dropped packets when redirecting traffic through a network function. Which configuration change would address this issue?

Options:

A.

Reduce the MTU size to 1400 to match Geneve encapsulation.

B.

Disable Geneve tunneling on the virtual switch.

C.

Increase the MTU by an additional 58 bytes for the Geneve header.

D.

Keep the default MTU at 1500. Encapsulation is handled automatically.

Buy Now
Questions 9

What happens when a monitored policy is enforced?

Options:

A.

Stops logging traffic

B.

Blocks all traffic that is not allowed

C.

Deletes the policy hitlogs

D.

Removes all discovered flows

Buy Now
Questions 10

In Nutanix Flow, which action transitions a security policy from observing traffic to actively enforcing the rules?

Options:

A.

Disable Traffic Visualization for the policy.

B.

Enforce policy by setting its scope.

C.

Change policy mode from Monitor to Save.

D.

Change policy mode from Monitor to Enforce.

Buy Now
Questions 11

How can the administrator discover the root cause of the issue?

Options:

A.

Confirm that Inter-VM connectivity is enabled within the VM networking settings and that VMs in the Database tier are configured correctly to accept inbound traffic.

B.

Check if traffic isolation has been configured on the Database tier and ensure that there is no policy preventing App tier communication with the Database tier.

C.

Check the security policies again to ensure that the rule allowing port 3306 from Web - > Database is applied and active, then check the policy enforcement mode to ensure it is in Enforcement Mode.

D.

Verify that the port 3306 is open on the external gateway and that SNAT is not being applied for internal communication.

Buy Now
Questions 12

An administrator is building a VPC... VPC CIDR: 10.10.0.0/16 Subnet CIDR: 10.10.10.0/24 "Ext_Net_Ext" (NAT): 192.168.1.0/24 "Ext_Net_Internal" (Routed): 172.16.1.0/24 The on-premises application server has an IP address of 172.16.2.50/24. A VM (10.10.10.100) in the VPC Subnet can reach the internet but cannot reach the on-premises server. Which static route needs to be added to the VPC route table to resolve this?

Options:

A.

Destination prefix: 172.16.2.0/24, Next-Hop: Ext_Net_Ext

B.

Destination Prefix: 10.10.0.0/16, Next-Hop: Ext_Net_Internal

C.

Destination prefix: 192.168.1.0/24 Next-Hop: Ext_Net_Ext

D.

Destination prefix: 172.16.2.0/24, Next-Hop: Ext_Net_Internal

Buy Now
Questions 13

An administrator notices that several VMs in a Nutanix AHV cluster are intermittently losing network connectivity. In Prism Central, a critical alert appears: "Network Function VM (NFVM) packet processing delays" What is the next step that the administrator should take for this issue?

Options:

A.

Review the Alerts and Events in Prism Central to confirm if the affected host shows NIC or uplink errors.

B.

Reboot the affected VMs to re-establish virtual NIC connections.

C.

Increase the MTU size on all virtual switches to improve packet throughput.

D.

Disable all Flow policies on the cluster to eliminate microsegmentation as the cause.

Buy Now
Questions 14

An administrator uses Nutanix Flow to secure a three-tier application (Web, App, and Database tiers). After observing the traffic, they find that: The Web tier communicates with the App tier over HTTP (port 80) The App tier communicates with the Database tier over TCP port 1433 The Database tier does not initiate connections The Web tier receives inbound HTTP traffic from the corporate DMZ on port 8080 No other traffic should be allowed What should the administrator do to document and then securely apply these flows in Nutanix Flow?

Options:

A.

Use Flow Network Visualization to capture observed flows and convert them into microsegmentation security policies.

B.

Add all VMs to a single security policy to simplify communication.

C.

Disable traffic-flow discovery and configure all policies manually.

D.

Manually create isolation policies between all VMs in the environment.

Buy Now
Questions 15

Which prerequisite is required before enabling Flow Network Security Next-Gen micro segmentation?

Options:

A.

Network Controller must be enabled in Prism Central.

B.

All workloads should be on VLAN networks.

C.

A Flow license is optional and cannot be installed later.

D.

The environment must use ESXi as the hypervisor.

Buy Now
Questions 16

An administrator is using Flow Network Security to secure a 3-tier application and has already created and assigned the categories. The administrator does not have the details of the rules that need to be allowed to secure the application. How can the administrator use Flow Network Security to monitor the traffic and help with the policy creation without impacting the applications connectivity?

Options:

A.

Use service insertion to redirect traffic through a monitoring service to capture the application traffic and create the Flow Network Security policy based on data captured in monitoring service.

B.

Create the Policy in Save mode, review the discovered traffic, allow the required traffic flows, and move Policy to Enforce mode.

C.

Create the Policy in Monitor mode, review the discovered traffic, allow the required traffic flows, and move Policy to Enforce mode.

D.

Redirect the traffic to a Syslog server and monitor the traffic on the syslog server and then create the Flow Network Security policy based on monitored data in syslog server.

Buy Now
Questions 17

An administrator has created a VPC with the following subnets: 10.1.1.0/24 10.1.2.0/24 10.1.3.0/24 What action must be taken for these networks to be externally routable?

Options:

A.

Assign a No-NAT External Network & ERP 10.1.0.0/22

B.

Assign a No-NAT External Network & ERP 10.1.0.0/23

C.

Assign a NAT External Network & ERP 10.1.0.0/22

D.

Assign a NAT external network & ERP 10.1.0.0/23

Buy Now
Questions 18

A customer wants to migrate VMs from a VLAN Basic Subnet to an Overlay Subnet with the same IP prefix. Which migration approach ensures minimal disruption?

Options:

A.

Perform cold migration, acknowledging that ingress/egress connections will not be preserved.

B.

Enable trunk mode on VLAN to allow multiple subnets on the same interface.

C.

Change IPAM mode to unmanaged to allow manual IP assignment.

D.

Create a Layer 2 connectivity between the subnets and perform live migration.

Buy Now
Questions 19

What is the additional resource requirement for each Prism Central VM when enabling Flow Virtual Networking on a Small Prism Central deployment?

Options:

A.

2 GB of memory and 1 vCPUs

B.

3 GB of memory and 2 vCPUs

C.

4 GB of memory and 3 vCPUs

D.

5 GB of memory and 4 vCPUs

Buy Now
Questions 20

Which step is required to prepare an AHV cluster for Flow Virtual Networking?

Options:

A.

Assign all VMs to a single VLAN before enabling Flow.

B.

Configure static routes for all overlay networks before enabling Flow.

C.

Disable all existing microsegmentation policies to allow virtual networking.

D.

Ensure all CVMs have network connectivity to Prism Central.

Buy Now
Questions 21

An administrator is designing a new Transit VPC to service multiple Tenant VPCs. While adding subnets, the administrator must choose the correct network type supported by Flow Virtual Networking for this VPC. Which network type is supported for subnets inside a Transit VPC in Flow Virtual Networking?

Options:

A.

Overlay subnets

B.

VLAN Basic subnets

C.

VLAN subnets

D.

VXLAN subnets

Buy Now
Questions 22

When configuring an Application policy, an administrator defines a VM Category Application:MySQL as a Secured Entity. The administrator wants to ensure that traffic between VMs in the Secured Entity is kept to only required replication traffic on the default mysql service port. How should the administrator best accomplish this?

Options:

A.

Create an Inter-Tier Rule specifying the mysql service as the allowed traffic.

B.

Create an Intra-Tier Rule specifying the mysql service as the allowed traffic.

C.

Create an Inbound Rule specifying the mysql service as the allowed traffic.

D.

Create an Outbound Rule specifying the mysql service as the allowed traffic.

Buy Now
Questions 23

An administrator receives a ticket reporting unwanted traffic between production and development servers. The administrator reviews the Flow Network Security logs and finds the following:

NCP-NS-7.5 Question 23

How can the administrator resolve the issue?

Options:

A.

Update the policy to disallow the unwanted traffic.

B.

Move the servers to separate IP subnets.

C.

Enable the Network Controller for the policy

D.

Change the enforcement mode for the policy

Buy Now
Questions 24

An administrator needs to isolate communication between VMs in Production and Development environments. Each VM is categorized by Environment and Site category values. The administrator wants this isolation to apply only to VMs located at Site: Branch-001. Which configuration best meets the requirement?

Options:

A.

Create a Quarantine Policy between Environment:Production and Environment:Development. Scope the policy to Site: Branch-001.

B.

Create a Quarantine Policy blocking traffic between (Environment: Production + Site: Branch-001) and (Environment: Development + Site: Branch-001).

C.

Create an Isolation Policy between Environment:Production and Environment:Development. Scope the policy to Site: Branch-001.

D.

Create an Isolation Policy blocking traffic between (Environment: Production + Site: Branch-001) and (Environment: Development + Site: Branch-001).

Buy Now
Questions 25

An administrator is configuring a Nutanix environment for Flow Network Security Next-Gen. Where should the MTU be set to ensure that Geneve encapsulation overhead is properly accounted for?

Options:

A.

On the CVM's virtual network interfaces

B.

On the AHV host's physical network interfaces

C.

On the virtual switch within Prism Central

D.

On the upstream virtual router

Buy Now
Questions 26

Exhibit:

NCP-NS-7.5 Question 26

An administrator needs to setup a Syslog server to capture the Flow Network Security Hit logs. Which module name should be selected?

Options:

A.

Flow Service Logs

B.

API Audit

C.

Security Policy Hit logs

D.

Audit

Buy Now
Questions 27

An administrator has a VPC with a single active gateway node that successfully peers with an external router using a single BGP GW and session. To eliminate a single point of failure, the administrator deploys a second BGP gateway to the VPC. After the second gateway is added and shows a healthy state, the external router still only sees a single BGP session. What is the most likely reason for the second session not being established on the external router?

Options:

A.

The BGP Hold-down timer on the external router is set too high.

B.

Network Security Groups are blocking BGP traffic from the second gateway's IP address.

C.

The external router needs BGP peering configuration pointing to the IP address of the first gateway node.

D.

The second BGP gateway requires a BGP session configured to peer with the external router.

Buy Now
Questions 28

An administrator has a VPC with multiple overlay subnets and a VPN gateway configured for site-to-site connectivity. During testing, the administrator noticed fragmented packets and poor performance. Which configuration change resolves this issue without disabling VPN?

Options:

A.

Increase MTU to 1500 on guest VMs

B.

Enable jumbo frames on VLAN subnets

C.

Reduce MTU to 1356 on guest VMs

D.

Disable Geneve encapsulation

Buy Now
Questions 29

An administrator needs to use Prism Central to identify a subnet belonging to a VPC. How can the administrator identify networks associated with a VPC within Prism Central?

Options:

A.

There will be a valid IP Prefix for the subnet.

B.

The subnet will reference multiple clusters.

C.

The subnet will have a non-zero VLAN ID.

D.

The subnet will be identified as type Overlay.

Buy Now
Questions 30

What is the role of the Network Controller in Flow Virtual Networking?

Options:

A.

Distribute the network traffic load across multiple guest VMs efficiently.

B.

It enables you to configure and manage common administrative tasks that are applicable to the platform and various Nutanix apps.

C.

It is used to create VPN, VTEP, or BGP gateways to connect subnets using VPN connections, Layer 2 subnet extensions over VPN or VTEP, or over BGP session.

D.

It manages configuration, monitoring, and optimization of network resources.

Buy Now
Questions 31

An administrator is setting up a transit VPC to connect two VPCs and enable both internal (on-prem) and Internet connectivity. Which is the best configuration to meet the requirement?

Options:

A.

Configure the transit VPC with two NAT External Subnets to support redundancy for internet connectivity.

B.

Configure the transit VPC with one NAT External Subnet and one No-NAT External Subnet, each serving different traffic types.

C.

Configure the transit VPC with two No-NAT Overlay External Subnets for both Internet and on-prem traffic.

D.

Configure the transit VPC with a single No-NAT External Subnet to handle both internal and internet traffic.

Buy Now
Exam Code: NCP-NS-7.5
Exam Name: Nutanix Certified Professional - Network and Security (NCP-NS) 7.5
Last Update: Jun 1, 2026
Questions: 106

PDF + Testing Engine

$64.99   $185.69

Testing Engine

$49.99   $142.83

PDF (Q&A)

$54.99   $157.11