2026 Provide Updated Nutanix NCP-NS Dumps as Practice Test and PDF
NCP-NS Dumps are Available for Instant Access
Nutanix NCP-NS Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
NEW QUESTION # 29
Which statement is correct about cloning Application Security Policies?
- A. Only one policy can be cloned at a time.
- B. The system prevents saving the cloned policy if it has the same secured entities as the original.
- C. The default name of the cloned policy must be manually entered; the system does not provide a default.
- D. The policy type can be changed while cloning a policy.
Answer: D
NEW QUESTION # 30
Which two statements are true with respect to Flow Network Security Policies? (Choose two.)
- A. Flow Network Security supports L3 and L4-based firewall rules.
- B. Flow Network Security is a stateful firewall.
- C. Flow Network Security supports rules based on L2 MAC Addresses.
- D. Flow Network Security supports L7-based firewall rules.
Answer: A,B
NEW QUESTION # 31
An administrator plans to upgrade a Nutanix cluster running AHV and Prism Central. The current cluster is on AOS 6.10, and the administrator wants to move to AOS 7.3 while ensuring all components remain compatible.
What is the correct upgrade order to minimize downtime and maintain cluster functionality?
- A. Upgrade CVMs -> Upgrade cluster AOS -> Upgrade Prism Central -> Upgrade AHV hosts
- B. Upgrade cluster AOS -> Upgrade AHV hosts -> Upgrade Prism Central -> Upgrade CVMs
- C. Upgrade Prism Central -> Upgrade AHV hosts -> Upgrade CVMs -> Upgrade cluster AOS
- D. Upgrade AHV hosts -> Upgrade cluster AOS -> Upgrade Prism Central -> Upgrade CVMs
Answer: A
NEW QUESTION # 32
When configuring an Application policy, an administrator defines a VM Category Application:MySQL as a Secured Entity. The administrator wants to ensure that traffic between VMs in the Secured Entity is kept to only required replication traffic on the default mysql service port.
How should the administrator best accomplish this?
- A. Create an Outbound Rule specifying the mysql service as the allowed traffic.
- B. Create an Inbound Rule specifying the mysql service as the allowed traffic.
- C. Create an Inter-Tier Rule specifying the mysql service as the allowed traffic.
- D. Create an Intra-Tier Rule specifying the mysql service as the allowed traffic.
Answer: D
NEW QUESTION # 33
An administrator finds that App tier VMs cannot connect to the Database tier on port 3306, and Flow logs show the traffic is being denied by a security policy. The Web tier communicates normally.
What should the administrator do to allow the App tier to access the Database tier?
- A. Enable NAT for the Database tier to allow connections from the App tier.
- B. Change the Database tier subnet to match the App tier subnet.
- C. Update the microsegmentation policy in Nutanix Flow to allow App -> Database traffic on port 3306.
- D. Delete all existing Flow policies and recreate them from scratch.
Answer: C
NEW QUESTION # 34
An administrator needs to isolate communication between VMs in Production and Development environments. Each VM is categorized by Environment and Site category values. The administrator wants this isolation to apply only to VMs located at Site: Branch-001.
Which configuration best meets the requirement?
- A. Create an Isolation Policy blocking traffic between (Environment: Production + Site: Branch-001) and (Environment: Development + Site: Branch-001).
- B. Create a Quarantine Policy between Environment:Production and Environment:Development. Scope the policy to Site: Branch-001.
- C. Create a Quarantine Policy blocking traffic between (Environment: Production + Site: Branch-001) and (Environment: Development + Site: Branch-001).
- D. Create an Isolation Policy between Environment:Production and Environment:Development. Scope the policy to Site: Branch-001.
Answer: A
NEW QUESTION # 35
An administrator is building a VPC...
VPC CIDR: 10.10.0.0/16
Subnet CIDR: 10.10.10.0/24
"Ext_Net_Ext" (NAT): 192.168.1.0/24
"Ext_Net_Internal" (Routed): 172.16.1.0/24
The on-premises application server has an IP address of 172.16.2.50/24. A VM (10.10.10.100) in the VPC Subnet can reach the internet but cannot reach the on-premises server.
Which static route needs to be added to the VPC route table to resolve this?
- A. Destination prefix: 172.16.2.0/24, Next-Hop: Ext_Net_Internal
- B. Destination Prefix: 10.10.0.0/16, Next-Hop: Ext_Net_Internal
- C. Destination prefix: 172.16.2.0/24, Next-Hop: Ext_Net_Ext
- D. Destination prefix: 192.168.1.0/24 Next-Hop: Ext_Net_Ext
Answer: A
NEW QUESTION # 36
During a security review, the administrator confirms that the existing security policy does not explicitly allow traffic from Environment: Development to Environment: Production. A VM in the Development category was still able to reach a Production VM over IPv6.
What is the most likely cause of this behavior?
- A. An isolation policy was incorrectly applied instead of an application policy.
- B. The Allow All IPv6 option in the policy was selected.
- C. The VM was using a static IPv6 address.
- D. The policy was misconfigured and allowed all Layer 2 broadcast traffic.
Answer: B
NEW QUESTION # 37
An administrator has observed the following message:
Which two statements most accurately describe the security hitlog captured above? (Choose two.)
- A. 86.108.190.23 is sending a packet on UDP 123.
- B. The source ip address is 10.38.174.5 and source port is TCP/123.
- C. 10.38.174.57 is sending a packet destined to UDP 123.
- D. This is a security hit log on the rule name "Production-External-WebTier".
Answer: B,C
NEW QUESTION # 38
When setting up a Network Function VM for Service Insertion, an administrator needs to configure the vNICs that will be used for redirecting traffic.
What is the correct configuration for the vNICs on the Network Function VM?
- A. A single vNIC of type Network Function is required, which handles both ingress and egress traffic.
- B. Two Network Function vNICs are required that must be assigned static IP addresses from a managed IPAM network.
- C. Two standard vNICs are required, one for ingress and one for egress and must be on a trunked VLAN.
- D. Two specific Network Function vNICs must be created, one for inbound traffic and the other for outbound traffic.
Answer: D
NEW QUESTION # 39
An administrator has deployed a VPC for a multi-tier application on Nutanix AHV. The Web tier requires public internet access, while the App and Database tiers must remain private and isolated.
Which steps should the administrator take to configure the external network correctly?
- A. Attach a single external network to the VPC and allow all tiers unrestricted internet access.
- B. Configure an external network for the Web tier subnet and leave App and Database tiers private.
- C. Assign external IPs to all VMs in the VPC to simplify connectivity.
- D. Use overlay networks for external access instead of configuring a VPC external network.
Answer: B
NEW QUESTION # 40
An administrator has two user VPCs connected via a Transit VPC. Routing works for most subnets, but one overlay subnet cannot reach external networks.
What is the most probable cause?
- A. DHCP configuration is disabled on the overlay subnet in the user VPC
- B. Incorrect ASN in the BGP configuration in the Transit VPC
- C. Floating IP not assigned to the gateway
- D. Mismatch in ERP configuration in user and Transit VPC
Answer: D
NEW QUESTION # 41
An administrator creates an Isolation Policy in Prism Central to prevent communication between the Prod and Staging environments.
The policy is in Enforce mode... but VMs in the two environments can still communicate.
Which configuration issue most likely explains why the Isolation Policy is not blocking the traffic?
- A. The Isolation Policy does not specify any services/ports, so no traffic is matched for enforcement.
- B. The Prod and Staging categories have not been assigned to the VMs, so the policy does not apply.
- C. Isolation Policies restrict north-south communication when associated with a VPC gateway, not east-west traffic between categories.
- D. An Application Policy allows traffic between the same categories, overriding this policy.
Answer: D
NEW QUESTION # 42
A VDI policy in Flow Network Security allows access to specific resources only when users from the Admins Active Directory group log into a VM.
Some administrators report that when they log in to certain VMs, access is blocked (default deny applies), while the same user accounts work correctly when logged on to other VMs.
When checking the VM details in Prism Central, operations observes that the expected dynamic category based on the logged-in AD user is not assigned on the affected VMs.
What is the most likely reason for this behavior?
- A. The affected VMs allowed login using cached credentials without contacting the Domain Controller.
- B. The Prism Central Active Directory service connection is misconfigured or has failed.
- C. The Admins group contains nested AD groups, and only the top-level group is synchronized by Prism Central.
- D. The security policy is in Monitor mode, so the dynamic category assignment is not applied.
Answer: B
NEW QUESTION # 43
Which prerequisite is required before enabling Flow Network Security Next-Gen micro segmentation?
- A. All workloads should be on VLAN networks.
- B. Network Controller must be enabled in Prism Central.
- C. The environment must use ESXi as the hypervisor.
- D. A Flow license is optional and cannot be installed later.
Answer: B
NEW QUESTION # 44
An administrator has created a VPC with the following subnets:
10.1.1.0/24
10.1.2.0/24
10.1.3.0/24
What action must be taken for these networks to be externally routable?
- A. Assign a No-NAT External Network & ERP 10.1.0.0/23
- B. Assign a No-NAT External Network & ERP 10.1.0.0/22
- C. Assign a NAT External Network & ERP 10.1.0.0/22
- D. Assign a NAT external network & ERP 10.1.0.0/23
Answer: C
NEW QUESTION # 45
Refer to the exhibit.
How should an Application Policy be created whose rules apply only to vNIC1 of VM1?
- A. Add Cat:SubnetA and Cat:VM1 as secured entity in the Application Policy.
- B. Create an Entity Group with Cat:SubnetA, Cat:SubnetB and Cat:VM1 and then add the Entity Group as Secured Entity to the Application Policy.
- C. Add Cat:SubnetA as secured entity in the Application Policy.
- D. Create an Entity Group with Cat:SubnetA and Cat:VM1 and then add the Entity Group as Secured Entity to the Application Policy.
Answer: D
NEW QUESTION # 46
An administrator creates a VPC named AppVPC1 in Nutanix Cloud Infrastructure (NCI) with separate subnets for the web, app, and database tiers. The database subnet must remain isolated from external networks; however, all tiers need to communicate with each other internally.
What should the administrator configure to limit external access to only the web and app subnets?
- A. Configure a routing policy in the VPC to deny external traffic to and from the database subnet.
- B. Enable NAT Gateway on the database subnet for outbound communication.
- C. Create Static Routes on the physical network to interconnect the VPC subnets.
- D. Attach the web and app subnets to the external network through an AHV managed bridge.
Answer: A
NEW QUESTION # 47
What does placing a policy in Monitor mode accomplish?
- A. Enables hitlogs for traffic that matches the policy.
- B. Blocks traffic that does not match the policy.
- C. Visualizes discovered traffic that matches the policy.
- D. Redirects discovered traffic to a monitoring device.
Answer: C
NEW QUESTION # 48
An administrator observes a Network Controller Unreachable alert in Prism Central for a specific AHV cluster. All other management tasks for the cluster from Prism Central are succeeding and the cluster itself reports a healthy status.
Which step is the most appropriate to investigate the cause of this specific alert?
- A. Check for and restart any unhealthy Flow Virtual Networking microservices within the Prism Central scale-out architecture.
- B. Unregister and then re-register the affected cluster in Prism Central to force a full synchronization of the network controller state.
- C. On the affected Prism Element cluster, verify that the Network Controller service is enabled and healthy on all CVMs.
- D. Verify physical network connectivity and MTU settings between Prism Central and the affected AHV hosts.
Answer: C
NEW QUESTION # 49
An administrator needs to allow communication between several VPCs without requiring to configure routes in the physical network or using a dynamic routing protocol like BGP.
How should the administrator satisfy this requirement?
- A. Configure a VPN network between each of the VPCs.
- B. Merge all the subnets into a single VPC.
- C. Peer the VPCs directly.
- D. Connect the VPCs to a single Transit VPC.
Answer: D
NEW QUESTION # 50
When creating a VPC, enabling the Transit VPC toggle changes the role of the VPC.
What does the Transit VPC toggle do?
- A. Enables DHCP relay for routed subnets
- B. Converts all Overlay subnets into VLAN subnets
- C. Forces NAT for all external subnets
- D. Creates a hub-and-spoke VPC for routing
Answer: D
NEW QUESTION # 51
A VPC admin creates a policy to allow traffic between two IP subnets but forgets to enable reverse direction.
What happens in this scenario?
- A. Policy is rejected by Prism Central during validation.
- B. Traffic flows bidirectionally because policies are stateful by default.
- C. Traffic is blocked completely because the policy is invalid.
- D. Traffic flows only in one direction, blocking return traffic.
Answer: D
NEW QUESTION # 52
In a Nutanix deployment, when is the Network Controller automatically enabled?
- A. When the Network Controller is enabled on a Hyper-V cluster
- B. When the Network Controller is manually configured from the Prism Central settings page
- C. When the X-Large Prism Central deployment is installed or upgraded
- D. When the Small Prism Central deployment is scaled out to three PCVM's
Answer: D
NEW QUESTION # 53
......
Updated NCP-NS Dumps Questions For Nutanix Exam: https://www.ipassleader.com/Nutanix/NCP-NS-practice-exam-dumps.html
Valid NCP-NS Dumps for Helping Passing NCP-NS Exam!: https://drive.google.com/open?id=14TjQs-tQ6gLyrsY2VjD6w0mpAeNyDskJ