Pre-Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Nutanix NCP-NS-7.5 Practice Exam with Questions & Answers

Questions 1

An administrator needs to delegate the management of security policies to a dedicated SecOps team. To enforce the principle of least privilege, the administrator assigns the predefined Flow Policy Author role to a user on the team. The user confirms they can create, monitor, and enforce security policies. However, when attempting to build a new application security policy for a set of newly deployed VMs, the user reports they are unable to create a new category to group these VMs. The option is not available in the Prism Central UI. Which statement explains this behavior?

Options:
A.

The Flow Policy Author role must be cloned into a custom role before it can be used.

B.

The user's role must be assigned with a scope for the specific projects they manage.

C.

The user is missing the Flow Admin role, which is required for category management.

D.

The Flow Policy Author role can only apply policies to existing categories by design.

Nutanix NCP-NS-7.5 Premium Access
Questions 2

What type of policy would be used to block all traffic between VMs in the category Environment:Sandbox and VMs in the category Environment:Production?

Options:
A.

Quarantine Policy

B.

Application Policy

C.

Isolation Policy

D.

Shared Services Policy

Questions 3

How can the administrator discover the root cause of the issue?

Options:
A.

Confirm that Inter-VM connectivity is enabled within the VM networking settings and that VMs in the Database tier are configured correctly to accept inbound traffic.

B.

Check if traffic isolation has been configured on the Database tier and ensure that there is no policy preventing App tier communication with the Database tier.

C.

Check the security policies again to ensure that the rule allowing port 3306 from Web - > Database is applied and active, then check the policy enforcement mode to ensure it is in Enforcement Mode.

D.

Verify that the port 3306 is open on the external gateway and that SNAT is not being applied for internal communication.

Questions 4

An administrator has configured two VPCs with overlapping externally routable prefixes (ERPs). The two VPCs are associated to separate external networks that are part of the same physical routing domain. What outcome should the administrator expect?

Options:
A.

Routing conflicts and unreachable external paths

B.

NAT is always automatically enforced

C.

Prefixes are merged into a single advertised route

D.

The larger prefix takes priority automatically

Questions 5

Which step is required before placing the Flow Network Security software bundle on a local web server?

Options:
A.

Perform an inventory on the Nutanix cluster before transferring any bundle files to the web server.

B.

Extract the downloaded bundle using 7zip and upload it directly to Prism Central.

C.

Enable Direct Upload in Life Cycle Manager so the bundles can be transferred automatically to the Nutanix cluster.

D.

Set up a local web server and download both the required software LCM bundle and compatibility bundle.

Questions 6

Refer to Exhibit:

NCP-NS-7.5 Question 6

In the AD-VDI Departmental SecPol policy shown in the exhibit, ADGroup: Engineering is configured as a secured entity in a VDI Security Policy. Prism Central shows 2 / 2 active sessions under this group, but the administrator confirms that three Engineering users are currently logged in to persistent VDI desktops. The third user's VM shows no ADGroup assignment in its VM details in Prism Central, even after the user has successfully logged in. All three users are members of the same AD group, and the Domain Controller event logs confirm a successful interactive login for the third user. Which condition explains why the third user's VM is not being assigned the ADGroup: Engineering category?

Options:
A.

The Active Directory Service account used by Prism Central is locked.

B.

The third user's VM has been assigned an AppType category, preventing ID-Based categorization.

C.

The Flow Identity Service has been disabled in Prism Central for the VM the third user is logging in to.

D.

The Flow Network Security policy scope does not include the VLAN where the third user's VM resides.

Questions 7

Users have recently reported intermittent connectivity issues and slower-than-usual application performance for a Nutanix cluster to an administrator. The administrator needs to identify the root cause of these issues by analyzing the health of the infrastructure components. What action should the administrator take first to diagnose the root cause of the problem?

Options:
A.

Review cluster health status, checking for any warnings or alerts relevant to the performance issues.

B.

Enable network QoS to prioritize the performance of critical applications.

C.

Rebalance virtual machines across the cluster to balance resource load and improve performance.

D.

Reboot the Nutanix cluster nodes to clear any potential performance-related cache or memory issues.

Questions 8

An administrator has a requirement to capture application flow data for a policy in Monitor mode and export those events to an external SIEM for correlation with other logs. Which two actions are required to achieve this? (Choose two.)

Options:
A.

Enable IPFIX export on the monitored policy.

B.

Enable Policy Hit Logging on the monitored policy.

C.

Create a Flow Audit Policy on the monitored policy.

D.

Configure a remote syslog destination in Prism Central.

Questions 9

Refer to Exhibit:

NCP-NS-7.5 Question 9

An administrator is reviewing an enforced security policy "Secure 3-VM Inventory App", as shown in the exhibit. The policy's inbound rules are configured to allow traffic from specific sources to each tier of the application. The visualization shows one blocked traffic flow. Based on the information presented in the exhibit, which statement best describes this behavior?

Options:
A.

The AppTier: FrontEnd and AppTier: AppLogic entities are on different subnets.

B.

The Inventory App VM is being blocked from initiating a connection to the AppTier: Database category.

C.

The AppTier: Database category is being blocked from initiating a connection to the Inventory App VM.

D.

The security policy is blocking traffic because the Inventory App VM is using a port not allowed by the policy.

Questions 10

An enterprise has deployed a VPC called FinanceVPC using Nutanix Flow Virtual Networking. The Finance team needs the following connectivity: Internal servers in the VPC must reach an on-premises corporate data-center via a point-to-point encrypted link. Some servers in the VPC must also access the public internet with source NAT and receive inbound access via floating IPs. The corporate network uses overlapping IP space with other VPCs in the environment, so address translation is necessary for those workloads. The networking design must support routing via BGP for future site expansions and provide low-latency north-south connectivity. Which actions should the administrator take to satisfy this requirement?

Options:
A.

Use two No-NAT External Networks—one for the on-prem link and one for Internet access; configure static routes for both without NAT.

B.

Use a single No-NAT External Network for both on-prem and Internet access; configure BGP and direct routing out to the internet without NAT.

C.

Use a No-NAT External Network for the on-premises link and a NAT External Network for Internet access. Configure a VPN tunnel to the on-premises location and enable BGP on the VPC router for the on-premises link.

D.

Use a single NAT External Network for both the on-prem link and Internet access; configure a default route to the external network and enable SNAT and floating IPs for all traffic.

Exam Code: NCP-NS-7.5
Certification Provider: Nutanix
Exam Name: Nutanix Certified Professional - Network and Security (NCP-NS) 7.5
Last Update: Apr 26, 2026
Questions: 106