Exam NCP-MCI-6.10 Topic 5 Question 93 Discussion

Actual exam question for Nutanix's NCP-MCI-6.10 exam
Question #: 93
Topic #: 5
An administrator recently attempted to enable Data-in-Transit Encryption on a scale-out Prism Central cluster to ensure service-level traffic is encrypted between cluster nodes. After attempting to enable the feature, it did not function because of firewall restrictions.
Which CVM-specific port must be allowed through the firewall for Data-in-Transit Encryption?

Suggested Answer: C Vote an answer

Data-in-Transit Encryption for Prism Central and CVMs requires specific internal communication ports to be open. Nutanix internal component documentation states:
"Port 2020 is used by the Nutanix encryption service for encrypted CVM-to-CVM communication during Data-in-Transit Encryption operations." This port is essential for establishing secure tunnels between control-plane services. Ports 2009 and 2010 are used by other CVM services (e.g., Stargate, Curator coordination) but not for transport encryption. Port 9440 is for Prism UI/API traffic, and while it must be accessible for management, it does not enable encrypted back- end service traffic.
Thus, the administrator must ensure that port 2020 is permitted to enable Data-in-Transit Encryption functionality.

by seishinagi07 at Jun 25, 2026, 08:45 AM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10