Pre-Summer Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Nutanix Certified Professional - Network and Security (NCP-NS) 7.5 Question and Answers

Nutanix Certified Professional - Network and Security (NCP-NS) 7.5

Last Update May 25, 2026
Total Questions : 106

We are offering FREE NCP-NS-7.5 Nutanix exam questions. All you do is to just go and sign up. Give your details, prepare NCP-NS-7.5 free exam questions and then go for complete pool of Nutanix Certified Professional - Network and Security (NCP-NS) 7.5 test questions that will help you more.

NCP-NS-7.5 pdf

NCP-NS-7.5 PDF

$36.75  $104.99
NCP-NS-7.5 Engine

NCP-NS-7.5 Testing Engine

$43.75  $124.99
NCP-NS-7.5 PDF + Engine

NCP-NS-7.5 PDF + Testing Engine

$57.75  $164.99
Questions 1

What entity is automatically created on the cluster hosting Prism Central when Microsegmentation is enabled?

Options:

A.  

A storage container named flow_data is created.

B.  

A Bucket named flow_data is created.

C.  

A File Share named flow_data is created.

D.  

A virtual machine named flow_data is created.

Discussion 0
Questions 2

Which statement is correct about cloning Application Security Policies?

Options:

A.  

The system prevents saving the cloned policy if it has the same secured entities as the original.

B.  

The policy type can be changed while cloning a policy.

C.  

Only one policy can be cloned at a time.

D.  

The default name of the cloned policy must be manually entered; the system does not provide a default.

Discussion 0
Questions 3

An administrator is using Flow Network Security to secure a 3-tier application and has already created and assigned the categories. The administrator does not have the details of the rules that need to be allowed to secure the application. How can the administrator use Flow Network Security to monitor the traffic and help with the policy creation without impacting the applications connectivity?

Options:

A.  

Use service insertion to redirect traffic through a monitoring service to capture the application traffic and create the Flow Network Security policy based on data captured in monitoring service.

B.  

Create the Policy in Save mode, review the discovered traffic, allow the required traffic flows, and move Policy to Enforce mode.

C.  

Create the Policy in Monitor mode, review the discovered traffic, allow the required traffic flows, and move Policy to Enforce mode.

D.  

Redirect the traffic to a Syslog server and monitor the traffic on the syslog server and then create the Flow Network Security policy based on monitored data in syslog server.

Discussion 0
Questions 4

A new multi-tier application is being deployed across several subnets in a Nutanix environment. The security team wants to create a Flow Network Security Policy to restrict traffic between the tiers, but the complete matrix of required network ports and protocols is not fully documented. Which strategy should the team employ first to accurately capture the necessary communication patterns without risking application outage?

Options:

A.  

Create an IPFIX export of all the application traffic and monitor all traffic for 48 hours.

B.  

Apply a Security policy in Monitor mode to discover all traffic between the application tiers.

C.  

Create broad Security Policy to permit all TCP traffic between the tiers to ensure connectivity.

D.  

Apply a Security Policy in Enforce mode adding the required flows as they appear in the flow logs.

Discussion 0
Questions 5

An administrator has a VPC with a single active gateway node that successfully peers with an external router using a single BGP GW and session. To eliminate a single point of failure, the administrator deploys a second BGP gateway to the VPC. After the second gateway is added and shows a healthy state, the external router still only sees a single BGP session. What is the most likely reason for the second session not being established on the external router?

Options:

A.  

The BGP Hold-down timer on the external router is set too high.

B.  

Network Security Groups are blocking BGP traffic from the second gateway's IP address.

C.  

The external router needs BGP peering configuration pointing to the IP address of the first gateway node.

D.  

The second BGP gateway requires a BGP session configured to peer with the external router.

Discussion 0
Questions 6

A newly-deployed Flow Virtual Networking VPC environment is experiencing connectivity issues... A packet capture on the physical switch shows packets are being fragmented. What is the probable cause of the packet fragmentation and performance issues?

Options:

A.  

A Network Security Group is incorrectly filtering IP fragments.

B.  

The MTU on the physical or virtual switch layer is set too low.

C.  

The VM's guest OS network driver is faulty and requires an update.

D.  

The VPC's external network uplink has an incorrect VLAN ID configured.

Discussion 0
Questions 7

What is the role of the Network Controller in Flow Virtual Networking?

Options:

A.  

Distribute the network traffic load across multiple guest VMs efficiently.

B.  

It enables you to configure and manage common administrative tasks that are applicable to the platform and various Nutanix apps.

C.  

It is used to create VPN, VTEP, or BGP gateways to connect subnets using VPN connections, Layer 2 subnet extensions over VPN or VTEP, or over BGP session.

D.  

It manages configuration, monitoring, and optimization of network resources.

Discussion 0
Questions 8

Refer to Exhibit:

In the AD-VDI Departmental SecPol policy shown in the exhibit, ADGroup: Engineering is configured as a secured entity in a VDI Security Policy. Prism Central shows 2 / 2 active sessions under this group, but the administrator confirms that three Engineering users are currently logged in to persistent VDI desktops. The third user's VM shows no ADGroup assignment in its VM details in Prism Central, even after the user has successfully logged in. All three users are members of the same AD group, and the Domain Controller event logs confirm a successful interactive login for the third user. Which condition explains why the third user's VM is not being assigned the ADGroup: Engineering category?

Options:

A.  

The Active Directory Service account used by Prism Central is locked.

B.  

The third user's VM has been assigned an AppType category, preventing ID-Based categorization.

C.  

The Flow Identity Service has been disabled in Prism Central for the VM the third user is logging in to.

D.  

The Flow Network Security policy scope does not include the VLAN where the third user's VM resides.

Discussion 0
Questions 9

A junior network operator is assigned two predefined roles in Prism Central... Role A: Prism Viewer Role B: VPC Admin The operator reports being able to successfully create, update, and delete Virtual Private Clouds (VPCs). However, the operator is unable to create a VM into the VPC. How does Prism Central determine the operator's effective permissions?

Options:

A.  

The system applies the principle of "most privilege," granting the highest level of access from any assigned role.

B.  

The permissions of the VPC Admin role override the more restrictive Prism Viewer role.

C.  

The Prism Viewer role's permissions take precedence, preventing any write operations from the VPC Admin role.

D.  

The permissions are the union of both roles, granting VPC management rights and global read-only access.

Discussion 0
Questions 10

An administrator is building a new VPC in Prism Central to isolate a test environment. The administrator plans to connect it to an external network later, but they want to complete the initial creation first. Which configuration items are the minimum required to successfully create the VPC?

Options:

A.  

VPC name and one External Access VLAN

B.  

VPC name and Transit VPC toggle switch

C.  

VPC name and one Overlay Subnet

D.  

VPC name and cluster selection

Discussion 0
Questions 11

An administrator observes a Network Controller Unreachable alert in Prism Central for a specific AHV cluster. All other management tasks for the cluster from Prism Central are succeeding and the cluster itself reports a healthy status. Which step is the most appropriate to investigate the cause of this specific alert?

Options:

A.  

On the affected Prism Element cluster, verify that the Network Controller service is enabled and healthy on all CVMs.

B.  

Verify physical network connectivity and MTU settings between Prism Central and the affected AHV hosts.

C.  

Check for and restart any unhealthy Flow Virtual Networking microservices within the Prism Central scale-out architecture.

D.  

Unregister and then re-register the affected cluster in Prism Central to force a full synchronization of the network controller state.

Discussion 0
Questions 12

Which two options are supported as a Secured Entity in Flow Network Security Application Policies? (Choose two.)

Options:

A.  

Subnet Category

B.  

vNIC Category

C.  

VPC Category

D.  

VG Category

Discussion 0
Questions 13

A VM with IP address 172.20.10.5 on a Subnet with CIDR 172.20.10.0/24 is unable to be routed externally from the VPC. The VPC is successfully peered via BGP... However, when checking the BGP Session, no routes are being advertised by the VPC. What is the most likely configuration issue?

Options:

A.  

There is no default route within the VPC to send traffic to the NAT external network.

B.  

The VM does not have a Floating IP assigned to allow external connectivity.

C.  

The VPC does not have a NO-NAT network configured to advertise the routes.

D.  

A network Policy is blocking outbound access for the VM.

Discussion 0
Questions 14

An administrator plans to upgrade the Network Controller in a Flow Virtual Networking deployment. The environment includes multiple AHV clusters managed by Prism Central. Which prerequisite must be verified before upgrading the Network Controller?

Options:

A.  

Flow Network Security must be upgraded to the target release before upgrading the Network Controller.

B.  

Each cluster must be running the Flow Network Security version specified as compatible with the target Network Controller release.

C.  

Each cluster must be running AHV versions compatible with the target Network Controller release.

D.  

Network Controller Prism Element upgrades must be applied before before Network Controller Prism Central upgrades can be applied.

Discussion 0
Questions 15

Flow Network Security Next-Gen is supported in which two environments? (Choose two.)

Options:

A.  

On-Premises Overlay Networks

B.  

NC2 VLAN Networks

C.  

NC2 Overlay Networks

D.  

On-Premises VLAN Basic Networks

Discussion 0
Questions 16

Exhibit:

A VM with IP address 172.20.9.5 resides on a subnet with CIDR 172.20.9.0/24. The VPC is successfully peered via BGP with an external router... External networks outside the VPC are unable to reach the VM. What configuration change should be made to enable reachability for the VM?

Options:

A.  

Modify the ERP values within the VPC to advertise a CIDR of 172.20.8.0/22

B.  

Apply a PBR rule for the VM's address forwarding traffic to the IP of the No-NAT external Gateway address

C.  

Apply a default route to the VPC sending all traffic to the NAT External Network

D.  

Associate a NAT external network to the VPC and apply a floating IP address to the VM

Discussion 0
Questions 17

An administrator has a requirement to capture application flow data for a policy in Monitor mode and export those events to an external SIEM for correlation with other logs. Which two actions are required to achieve this? (Choose two.)

Options:

A.  

Enable IPFIX export on the monitored policy.

B.  

Enable Policy Hit Logging on the monitored policy.

C.  

Create a Flow Audit Policy on the monitored policy.

D.  

Configure a remote syslog destination in Prism Central.

Discussion 0
Questions 18

An administrator has been tasked with configuring virtual switches and setting the appropriate MTU size for a Nutanix cluster to optimize network performance. The cluster needs to support high-throughput traffic between VMs and ensure compatibility with external networks. The administrator needs to configure the virtual switches and MTU size to enable jumbo frames while ensuring that all nodes and network components are properly aligned to prevent packet loss or fragmentation. What is the first step to configure the virtual switches and MTU size in a Nutanix cluster for optimal network performance?

Options:

A.  

Enable multicast filtering on the virtual switches to optimize MTU configuration.

B.  

Set the MTU size to 1500 on the Nutanix virtual switches and configure a separate VLAN for MTU traffic.

C.  

Set the MTU size to 1500 on all nodes and virtual switches for compatibility with external networks.

D.  

Configure the MTU size to 9000 on all nodes and virtual switches, and verify that all physical network switches support jumbo frames.

Discussion 0
Questions 19

Which two statements are true with respect to Flow Network Security Policies? (Choose two.)

Options:

A.  

Flow Network Security is a stateful firewall.

B.  

Flow Network Security supports L3 and L4-based firewall rules.

C.  

Flow Network Security supports L7-based firewall rules.

D.  

Flow Network Security supports rules based on L2 MAC Addresses.

Discussion 0
Questions 20

An organization plans to apply security controls based on user group membership in Active Directory. What configuration is required in Prism Central before VDI policies can be used?

Options:

A.  

Map category assignments to roles using RBAC settings.

B.  

Create the list of users and assign categories to them.

C.  

Assign categories to identities in the Admin Center.

D.  

Configure category values mapped to AD groups.

Discussion 0
Questions 21

What must an administrator do before disabling the Network Controller?

Options:

A.  

Convert external subnets into VLAN Basic networks.

B.  

Delete VLAN Basic Subnets.

C.  

Once enabled, the Network controller cannot be disabled.

D.  

Delete all external subnets and VPCs which are in-use.

Discussion 0
Questions 22

Which policy mode records traffic without enforcing rule actions?

Options:

A.  

Enforce

B.  

Monitor

C.  

Isolate

D.  

Save

Discussion 0
Questions 23

Which step is required before placing the Flow Network Security software bundle on a local web server?

Options:

A.  

Perform an inventory on the Nutanix cluster before transferring any bundle files to the web server.

B.  

Extract the downloaded bundle using 7zip and upload it directly to Prism Central.

C.  

Enable Direct Upload in Life Cycle Manager so the bundles can be transferred automatically to the Nutanix cluster.

D.  

Set up a local web server and download both the required software LCM bundle and compatibility bundle.

Discussion 0
Questions 24

An administrator needs to allow communication between several VPCs without requiring to configure routes in the physical network or using a dynamic routing protocol like BGP. How should the administrator satisfy this requirement?

Options:

A.  

Merge all the subnets into a single VPC.

B.  

Peer the VPCs directly.

C.  

Configure a VPN network between each of the VPCs.

D.  

Connect the VPCs to a single Transit VPC.

Discussion 0
Questions 25

An administrator has a VPC with multiple overlay subnets and a VPN gateway configured for site-to-site connectivity. During testing, the administrator noticed fragmented packets and poor performance. Which configuration change resolves this issue without disabling VPN?

Options:

A.  

Increase MTU to 1500 on guest VMs

B.  

Enable jumbo frames on VLAN subnets

C.  

Reduce MTU to 1356 on guest VMs

D.  

Disable Geneve encapsulation

Discussion 0
Questions 26

When configuring an Application policy, an administrator defines a VM Category Application:MySQL as a Secured Entity. The administrator wants to ensure that traffic between VMs in the Secured Entity is kept to only required replication traffic on the default mysql service port. How should the administrator best accomplish this?

Options:

A.  

Create an Inter-Tier Rule specifying the mysql service as the allowed traffic.

B.  

Create an Intra-Tier Rule specifying the mysql service as the allowed traffic.

C.  

Create an Inbound Rule specifying the mysql service as the allowed traffic.

D.  

Create an Outbound Rule specifying the mysql service as the allowed traffic.

Discussion 0
Questions 27

In Nutanix Flow, which action transitions a security policy from observing traffic to actively enforcing the rules?

Options:

A.  

Disable Traffic Visualization for the policy.

B.  

Enforce policy by setting its scope.

C.  

Change policy mode from Monitor to Save.

D.  

Change policy mode from Monitor to Enforce.

Discussion 0
Questions 28

An administrator needs to use Prism Central to identify a subnet belonging to a VPC. How can the administrator identify networks associated with a VPC within Prism Central?

Options:

A.  

There will be a valid IP Prefix for the subnet.

B.  

The subnet will reference multiple clusters.

C.  

The subnet will have a non-zero VLAN ID.

D.  

The subnet will be identified as type Overlay.

Discussion 0
Questions 29

Which policy mode blocks all traffic that is not explicitly allowed by the policy?

Options:

A.  

Monitor Mode

B.  

Save Mode

C.  

Block Mode

D.  

Enforce Mode

Discussion 0
Questions 30

An administrator has deployed a microsegmentation policy in Nutanix Flow that allows certain VM traffic based on Active Directory (AD) user group membership. Users in a specific AD group report they are unable to access the VMs, while other users can connect without issues. The administrator suspects the problem is related to identity-based policy mapping. What should the administrator do to troubleshoot and resolve the access issue related to the identity-based policy?

Options:

A.  

Add the IP addresses of the blocked VMs to the Inbound ruleset.

B.  

Ensure the VMs are associated to the proper AD group categories.

C.  

Reboot all VMs associated with the policy to refresh their security group mapping.

D.  

Verify that the affected users are members of the mapped AD group.

Discussion 0
Questions 31

An administrator creates an Isolation Policy in Prism Central to prevent communication between the Prod and Staging environments. The policy is in Enforce mode... but VMs in the two environments can still communicate. Which configuration issue most likely explains why the Isolation Policy is not blocking the traffic?

Options:

A.  

The Isolation Policy does not specify any services/ports, so no traffic is matched for enforcement.

B.  

Isolation Policies restrict north-south communication when associated with a VPC gateway, not east-west traffic between categories.

C.  

An Application Policy allows traffic between the same categories, overriding this policy.

D.  

The Prod and Staging categories have not been assigned to the VMs, so the policy does not apply.

Discussion 0