Latest [Jul 22, 2026] NCP-NS Exam Questions – Valid NCP-NS Dumps Pdf [Q14-Q36]

Share

Latest [Jul 22, 2026] NCP-NS Exam Questions – Valid NCP-NS Dumps Pdf

NCP-NS Practice Test Questions Answers Updated 108 Questions


Nutanix NCP-NS Exam Syllabus Topics:

TopicDetails
Topic 1
  • Troubleshoot Flow Network Security: Covers identifying policy-related traffic issues, analyzing security hit logs and audit logs, and troubleshooting identity based policy failures tied to Active Directory group mapping.
Topic 2
  • Troubleshoot Flow Virtual Networking: Covers diagnosing and resolving connectivity failures, BGP issues, gateway health problems, and interpreting alerts and logs related to virtual networking components.
Topic 3
  • Configure Flow Network Security: Covers analyzing application traffic flows, creating and configuring isolation, application, and identity based security policies, and managing policy lifecycle modes in Flow Network Security.
Topic 4
  • Deploy and Upgrade a Flow Environment: Covers preparing clusters for Flow Network Security and Virtual Networking, managing upgrade paths and dependencies, configuring virtual switches and MTU, and administering user roles and RBAC permissions.
Topic 5
  • Configure Flow Virtual Networking: Covers creating and managing VPCs, overlay networks, external connectivity options, BGP peering, load balancing, and policy based routing within Nutanix Flow Virtual Networking.

 

NEW QUESTION # 14
Refer to the exhibit.

In the AD-VDI Departmental SecPol policy shown in the exhibit, ADGroup: Engineering is configured as a secured entity in a VDI Security Policy. Prism Central shows 2 / 2 active sessions under this group, but the administrator confirms that three Engineering users are currently logged in to persistent VDI desktops. The third user's VM shows no ADGroup assignment in its VM details in Prism Central, even after the user has successfully logged in. All three users are members of the same AD group, and the Domain Controller event logs confirm a successful interactive login for the third user. Which condition explains why the third user's VM is not being assigned the ADGroup: Engineering category?

  • A. The Flow Identity Service has been disabled in Prism Central for the VM the third user is logging in to.
  • B. The third user's VM has been assigned an AppType category, preventing ID-Based categorization.
  • C. The Active Directory Service account used by Prism Central is locked.
  • D. The Flow Network Security policy scope does not include the VLAN where the third user's VM resides.

Answer: B


NEW QUESTION # 15
An organization plans to apply security controls based on user group membership in Active Directory.
What configuration is required in Prism Central before VDI policies can be used?

  • A. Create the list of users and assign categories to them.
  • B. Assign categories to identities in the Admin Center.
  • C. Map category assignments to roles using RBAC settings.
  • D. Configure category values mapped to AD groups.

Answer: D


NEW QUESTION # 16
An administrator is designing a Transit VPC to provide shared corporate services (e.g., DNS) for two tenant VPCs:
VPC-A requires WAN access using NAT.
VPC-B requires WAN access without NAT.
Both VPCs connect to the Transit VPC for shared services hosted on the corporate network.
Shared services residing in the Transit VPC use routed IP addressing for WAN connectivity.
Which two configuration elements should the administrator implement on the Transit VPC? (Choose two.)

  • A. Associate one No-NAT external VLAN to the Transit VPC router for underlay connectivity.
  • B. Create two Overlay external subnets in the Transit VPC: one for VPC-A and one for VPC-
  • C. Use one Overlay external subnet in the Transit VPC to which both VPCs will connect.
  • D. Associate both a NAT and a No-NAT external VLAN to the Transit VPC to support separate egress paths.

Answer: A,C


NEW QUESTION # 17
An administrator sets up a VPN between two Nutanix VPCs in different Availability Zones. After deployment, the VPN tunnel shows as Up, but traffic between the VPCs is not flowing.
Which configuration step is most likely missing?

  • A. Static routes for remote subnets on the VPC
  • B. NAT policy on each of the VPC routers
  • C. MTU adjustment on the AHV hosts
  • D. IPsec encryption settings on the VPN profile

Answer: A


NEW QUESTION # 18
An administrator has two user VPCs connected via a Transit VPC. Routing works for most subnets, but one overlay subnet cannot reach external networks.
What is the most probable cause?

  • A. Floating IP not assigned to the gateway
  • B. Mismatch in ERP configuration in user and Transit VPC
  • C. Incorrect ASN in the BGP configuration in the Transit VPC
  • D. DHCP configuration is disabled on the overlay subnet in the user VPC

Answer: B


NEW QUESTION # 19
A junior network operator is assigned two predefined roles in Prism Central...
Role A: Prism Viewer
Role B: VPC Admin
The operator reports being able to successfully create, update, and delete Virtual Private Clouds (VPCs). However, the operator is unable to create a VM into the VPC.
How does Prism Central determine the operator's effective permissions?

  • A. The permissions are the union of both roles, granting VPC management rights and global read-only access.
  • B. The permissions of the VPC Admin role override the more restrictive Prism Viewer role.
  • C. The system applies the principle of "most privilege," granting the highest level of access from any assigned role.
  • D. The Prism Viewer role's permissions take precedence, preventing any write operations from the VPC Admin role.

Answer: C


NEW QUESTION # 20
An administrator needs to configure a security policy that controls VM-to-VM communication within a category defined as secured entity.
Which configuration action should the administrator take to restrict all intra-tier communication between the VMs within a category defined as secured entity?

  • A. Apply the policy with inbound rules that block all inter-VM communication.
  • B. Use deny-all intra-tier traffic configuration in the policy.
  • C. Configure the security policy with allow-all intra-tier traffic.
  • D. Set the security policy to allow-specific traffic for intra-tier communication.

Answer: B


NEW QUESTION # 21
What does placing a policy in Monitor mode accomplish?

  • A. Enables hitlogs for traffic that matches the policy.
  • B. Redirects discovered traffic to a monitoring device.
  • C. Blocks traffic that does not match the policy.
  • D. Visualizes discovered traffic that matches the policy.

Answer: D


NEW QUESTION # 22
A customer wants to extend a VLAN subnet to a remote data center using VTEP. The administrator configures a Subnet Extension which shows UP in the Prism Interface, yet traffic fails to pass.
Which setting is most likely misconfigured?

  • A. VLAN ID does not match in the remote data center.
  • B. Remote gateway IP address has not been configured.
  • C. VXLAN UDP port is set to 4789.
  • D. Route Policy for VTEP has not been configured.

Answer: A


NEW QUESTION # 23
An administrator is responsible for managing user access to a Nutanix cluster... configure custom user roles...
What is the first step in configuring and managing user roles for a Nutanix cluster?

  • A. Create the requisite Custom Roles from custom or built-in Authorization Polices.
  • B. Modify the administrator role to restrict access to critical system functions.
  • C. Create the requisite Authorization Polices from custom or built-in roles.
  • D. Disable default roles and create new roles for each team.

Answer: C


NEW QUESTION # 24
When configuring an Application policy, an administrator defines a VM Category Application:MySQL as a Secured Entity. The administrator wants to ensure that traffic between VMs in the Secured Entity is kept to only required replication traffic on the default mysql service port.
How should the administrator best accomplish this?

  • A. Create an Inbound Rule specifying the mysql service as the allowed traffic.
  • B. Create an Inter-Tier Rule specifying the mysql service as the allowed traffic.
  • C. Create an Intra-Tier Rule specifying the mysql service as the allowed traffic.
  • D. Create an Outbound Rule specifying the mysql service as the allowed traffic.

Answer: C


NEW QUESTION # 25
Before creating a new Application Security Policy in Prism Central, what prerequisite must exist?

  • A. A category key/value pair must be defined for use in the policy.
  • B. Targeted VMs must have category assignments.
  • C. The Network Controller must be deployed on each cluster in the policy's scope.
  • D. Flow Network Security must be enabled on all registered clusters.

Answer: B


NEW QUESTION # 26
A new multi-tier application is being deployed across several subnets in a Nutanix environment. The security team wants to create a Flow Network Security Policy to restrict traffic between the tiers, but the complete matrix of required network ports and protocols is not fully documented.
Which strategy should the team employ first to accurately capture the necessary communication patterns without risking application outage?

  • A. Create an IPFIX export of all the application traffic and monitor all traffic for 48 hours.
  • B. Create broad Security Policy to permit all TCP traffic between the tiers to ensure connectivity.
  • C. Apply a Security Policy in Enforce mode adding the required flows as they appear in the flow logs.
  • D. Apply a Security policy in Monitor mode to discover all traffic between the application tiers.

Answer: D


NEW QUESTION # 27
An administrator needs to make a web server VM, which is inside a private VPC overlay subnet, accessible from the external network. The administrator assigns a Floating IP to the VM, but the service is still unreachable from the outside.
What is a likely reason for this failure?

  • A. A Floating IP was assigned from a different external subnet than the one used by the VPC.
  • B. The VM was not rebooted after the Floating IP was assigned.
  • C. The VPC has no default route configured to use the external subnet.
  • D. The web server VM is not running the latest version of NGT.

Answer: C


NEW QUESTION # 28
An administrator has a VPC with a single active gateway node that successfully peers with an external router using a single BGP GW and session.
To eliminate a single point of failure, the administrator deploys a second BGP gateway to the VPC. After the second gateway is added and shows a healthy state, the external router still only sees a single BGP session.
What is the most likely reason for the second session not being established on the external router?

  • A. The BGP Hold-down timer on the external router is set too high.
  • B. The second BGP gateway requires a BGP session configured to peer with the external router.
  • C. Network Security Groups are blocking BGP traffic from the second gateway's IP address.
  • D. The external router needs BGP peering configuration pointing to the IP address of the first gateway node.

Answer: B


NEW QUESTION # 29
Which statement is correct about cloning Application Security Policies?

  • A. Only one policy can be cloned at a time.
  • B. The default name of the cloned policy must be manually entered; the system does not provide a default.
  • C. The policy type can be changed while cloning a policy.
  • D. The system prevents saving the cloned policy if it has the same secured entities as the original.

Answer: C


NEW QUESTION # 30
Flow Network Security Next-Gen is supported in which two environments? (Choose two.)

  • A. On-Premises VLAN Basic Networks
  • B. On-Premises Overlay Networks
  • C. NC2 Overlay Networks
  • D. NC2 VLAN Networks

Answer: B,C


NEW QUESTION # 31
What type of policy would be used to block all traffic between VMs in the category Environment:Sandbox and VMs in the category Environment:Production?

  • A. Shared Services Policy
  • B. Application Policy
  • C. Isolation Policy
  • D. Quarantine Policy

Answer: C


NEW QUESTION # 32
While configuring third-party services (Service Insertion) in Flow Network Security Next-Gen, an administrator notices dropped packets when redirecting traffic through a network function.
Which configuration change would address this issue?

  • A. Disable Geneve tunneling on the virtual switch.
  • B. Reduce the MTU size to 1400 to match Geneve encapsulation.
  • C. Increase the MTU by an additional 58 bytes for the Geneve header.
  • D. Keep the default MTU at 1500. Encapsulation is handled automatically.

Answer: C


NEW QUESTION # 33
An administrator has configured two VPCs with overlapping externally routable prefixes (ERPs). The two VPCs are associated to separate external networks that are part of the same physical routing domain.
What outcome should the administrator expect?

  • A. Prefixes are merged into a single advertised route
  • B. NAT is always automatically enforced
  • C. The larger prefix takes priority automatically
  • D. Routing conflicts and unreachable external paths

Answer: D


NEW QUESTION # 34
Which prerequisite is required before enabling Flow Network Security Next-Gen micro segmentation?

  • A. The environment must use ESXi as the hypervisor.
  • B. A Flow license is optional and cannot be installed later.
  • C. All workloads should be on VLAN networks.
  • D. Network Controller must be enabled in Prism Central.

Answer: D


NEW QUESTION # 35
An administrator is setting up a transit VPC to connect two VPCs and enable both internal (on-prem) and Internet connectivity.
Which is the best configuration to meet the requirement?

  • A. Configure the transit VPC with two No-NAT Overlay External Subnets for both Internet and on-prem traffic.
  • B. Configure the transit VPC with two NAT External Subnets to support redundancy for internet connectivity.
  • C. Configure the transit VPC with a single No-NAT External Subnet to handle both internal and internet traffic.
  • D. Configure the transit VPC with one NAT External Subnet and one No-NAT External Subnet, each serving different traffic types.

Answer: D


NEW QUESTION # 36
......

NCP-NS dumps Sure Practice with 108 Questions: https://www.freecram.com/Nutanix-certification/NCP-NS-exam-dumps.html

0
0
0
10