Pre-Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

NCP-NS-7.5 Exam Dumps - Nutanix NCP-NS Questions and Answers

Question # 14

An administrator is configuring a Nutanix environment for Flow Network Security Next-Gen. Where should the MTU be set to ensure that Geneve encapsulation overhead is properly accounted for?

Options:

A.

On the CVM's virtual network interfaces

B.

On the AHV host's physical network interfaces

C.

On the virtual switch within Prism Central

D.

On the upstream virtual router

Buy Now
Question # 15

Which two options are supported as a Secured Entity in Flow Network Security Application Policies? (Choose two.)

Options:

A.

Subnet Category

B.

vNIC Category

C.

VPC Category

D.

VG Category

Buy Now
Question # 16

An administrator is deploying a multi-tier (web, app, database) application on a Nutanix cluster using AHV. The administrator needs to allow internal communication between tiers and provide external access to the web tier. How should the administrator satisfy this requirement?

Options:

A.

Create separate VLAN networks for each tier and configure routing on the physical network.

B.

Create a VPC with a single subnet and assign workloads of each tier to this subnet.

C.

Create separate VPCs for each tier and connect them to the same external NAT network and configure routing policies for inter-tier traffic.

D.

Create a VPC with subnets for each tier and configure the Externally Routable Prefix to include only web subnets.

Buy Now
Question # 17

When cloning a Flow Network Security policy, what should be verified before enabling Enforce mode?

Options:

A.

The cloned policy's secured entities reference the intended categories.

B.

The cloned policy is configured to a different scope than the source policy.

C.

The cloned policy must first be saved before it can be enforced.

D.

The cloned policy must be renamed before it can be enforced.

Buy Now
Question # 18

A customer wants to migrate VMs from a VLAN Basic Subnet to an Overlay Subnet with the same IP prefix. Which migration approach ensures minimal disruption?

Options:

A.

Perform cold migration, acknowledging that ingress/egress connections will not be preserved.

B.

Enable trunk mode on VLAN to allow multiple subnets on the same interface.

C.

Change IPAM mode to unmanaged to allow manual IP assignment.

D.

Create a Layer 2 connectivity between the subnets and perform live migration.

Buy Now
Question # 19

While configuring third-party services (Service Insertion) in Flow Network Security Next-Gen, an administrator notices dropped packets when redirecting traffic through a network function. Which configuration change would address this issue?

Options:

A.

Reduce the MTU size to 1400 to match Geneve encapsulation.

B.

Disable Geneve tunneling on the virtual switch.

C.

Increase the MTU by an additional 58 bytes for the Geneve header.

D.

Keep the default MTU at 1500. Encapsulation is handled automatically.

Buy Now
Question # 20

An administrator is using Flow Network Security to secure a 3-tier application and has already created and assigned the categories. The administrator does not have the details of the rules that need to be allowed to secure the application. How can the administrator use Flow Network Security to monitor the traffic and help with the policy creation without impacting the applications connectivity?

Options:

A.

Use service insertion to redirect traffic through a monitoring service to capture the application traffic and create the Flow Network Security policy based on data captured in monitoring service.

B.

Create the Policy in Save mode, review the discovered traffic, allow the required traffic flows, and move Policy to Enforce mode.

C.

Create the Policy in Monitor mode, review the discovered traffic, allow the required traffic flows, and move Policy to Enforce mode.

D.

Redirect the traffic to a Syslog server and monitor the traffic on the syslog server and then create the Flow Network Security policy based on monitored data in syslog server.

Buy Now
Question # 21

An administrator has configured a VPC and associated a NAT external network. A virtual machine connected to a subnet within this VPC is required to be accessible externally. What action must the administrator take to accomplish this?

Options:

A.

Configure a static route on the VPC's routing table.

B.

Create a Network Security Group allowing inbound traffic.

C.

Assign a Floating IP address to the virtual machine.

D.

Attach a second interface to the virtual machine.

Buy Now
Question # 22

How can the administrator discover the root cause of the issue?

Options:

A.

Confirm that Inter-VM connectivity is enabled within the VM networking settings and that VMs in the Database tier are configured correctly to accept inbound traffic.

B.

Check if traffic isolation has been configured on the Database tier and ensure that there is no policy preventing App tier communication with the Database tier.

C.

Check the security policies again to ensure that the rule allowing port 3306 from Web - > Database is applied and active, then check the policy enforcement mode to ensure it is in Enforcement Mode.

D.

Verify that the port 3306 is open on the external gateway and that SNAT is not being applied for internal communication.

Buy Now
Question # 23

While configuring a new security policy in a Nutanix microsegmentation environment, an administrator wants the policy to remain flexible even if virtual machines change subnets or obtain new IP addresses. Which configuration approach should the administrator use when defining the policy scope?

Options:

A.

Configure the policy only on specific VLAN IDs.

B.

Use VM categories to define the secured and allowed entities.

C.

Apply the policy after setting static routes for each VM.

D.

Assign IP addresses manually to all VMs included in the policy.

Buy Now
Exam Code: NCP-NS-7.5
Exam Name: Nutanix Certified Professional - Network and Security (NCP-NS) 7.5
Last Update: Apr 26, 2026
Questions: 106
NCP-NS-7.5 pdf

NCP-NS-7.5 PDF

$25.5  $84.99
NCP-NS-7.5 Engine

NCP-NS-7.5 Testing Engine

$28.5  $94.99
NCP-NS-7.5 PDF + Engine

NCP-NS-7.5 PDF + Testing Engine

$40.5  $134.99