Pre-Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Nutanix NCP-NS-7.5 - Nutanix Certified Professional - Network and Security (NCP-NS) 7.5

Page: 1 / 4
Total 106 questions

An administrator creates an Isolation Policy in Prism Central to prevent communication between the Prod and Staging environments. The policy is in Enforce mode... but VMs in the two environments can still communicate. Which configuration issue most likely explains why the Isolation Policy is not blocking the traffic?

A.

The Isolation Policy does not specify any services/ports, so no traffic is matched for enforcement.

B.

Isolation Policies restrict north-south communication when associated with a VPC gateway, not east-west traffic between categories.

C.

An Application Policy allows traffic between the same categories, overriding this policy.

D.

The Prod and Staging categories have not been assigned to the VMs, so the policy does not apply.

What does placing a policy in Monitor mode accomplish?

A.

Visualizes discovered traffic that matches the policy.

B.

Blocks traffic that does not match the policy.

C.

Enables hitlogs for traffic that matches the policy.

D.

Redirects discovered traffic to a monitoring device.

An administrator creates a VPC named AppVPC1 in Nutanix Cloud Infrastructure (NCI) with separate subnets for the web, app, and database tiers. The database subnet must remain isolated from external networks; however, all tiers need to communicate with each other internally. What should the administrator configure to limit external access to only the web and app subnets?

A.

Enable NAT Gateway on the database subnet for outbound communication.

B.

Configure a routing policy in the VPC to deny external traffic to and from the database subnet.

C.

Attach the web and app subnets to the external network through an AHV managed bridge.

D.

Create Static Routes on the physical network to interconnect the VPC subnets.

An administrator has a VPC with multiple overlay subnets and a VPN gateway configured for site-to-site connectivity. During testing, the administrator noticed fragmented packets and poor performance. Which configuration change resolves this issue without disabling VPN?

A.

Increase MTU to 1500 on guest VMs

B.

Enable jumbo frames on VLAN subnets

C.

Reduce MTU to 1356 on guest VMs

D.

Disable Geneve encapsulation

An administrator has been tasked with creating a security policy to protect specific virtual network interfaces (vNICs) within a VM in a Flow Virtual Networking setup. How can the administrator ensure that only a specific vNIC is protected by the policy?

A.

Apply the policy to the VM, and then use network segmentation to isolate the vNIC.

B.

Use subnet categorization to create a vNIC-specific policy, securing the selected vNIC based on its associated subnet.

C.

Configure an entity group with a VM and a subnet, and apply the policy to the entity group, including categories for both VM and subnet.

D.

Create a general policy for all vNICs and assign it to the VM. The system will automatically select the vNIC to protect.

Which two options are supported as a Secured Entity in Flow Network Security Application Policies? (Choose two.)

A.

Subnet Category

B.

vNIC Category

C.

VPC Category

D.

VG Category

An administrator configures a VPN gateway with eBGP for dynamic route exchange. After setup, routes are not advertised to the remote peer. Which configuration is most likely missing?

A.

DHCP options for assigning IP addresses to remote endpoints.

B.

ASN configuration for the local gateway to identify its autonomous system.

C.

VLAN ID alignment between local and remote networks.

D.

Peer IP address required for establishing the BGP session.

A VPC admin creates a policy to allow traffic between two IP subnets but forgets to enable reverse direction. What happens in this scenario?

A.

Traffic is blocked completely because the policy is invalid.

B.

Policy is rejected by Prism Central during validation.

C.

Traffic flows bidirectionally because policies are stateful by default.

D.

Traffic flows only in one direction, blocking return traffic.

In Nutanix Flow, which action transitions a security policy from observing traffic to actively enforcing the rules?

A.

Disable Traffic Visualization for the policy.

B.

Enforce policy by setting its scope.

C.

Change policy mode from Monitor to Save.

D.

Change policy mode from Monitor to Enforce.

An organization plans to apply security controls based on user group membership in Active Directory. What configuration is required in Prism Central before VDI policies can be used?

A.

Map category assignments to roles using RBAC settings.

B.

Create the list of users and assign categories to them.

C.

Assign categories to identities in the Admin Center.

D.

Configure category values mapped to AD groups.