[Sep 04, 2026] Verified NCP-CI-AWS dumps and 145 unique questions
NCP-CI-AWS Dumps for Pass Guaranteed - Pass NCP-CI-AWS Exam 2026
Nutanix NCP-CI-AWS Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
NEW QUESTION # 84
Which environment is able to verify whether Multicloud Snapshot Technology (MST) is supported in a new NC2 on AWS deployment as well as confirm the best installation process?
- A. OSM-based method
- B. Prism Central Marketplace
- C. YAML Templates
- D. Prism Element
Answer: B
Explanation:
ThePrism Central Marketplaceserves as the centralized hub for discovering, enabling, and managing various Nutanix services and integrated technologies. For administrators deploying NC2 on AWS, the Marketplace is the designated environment to verify the compatibility and support status ofMulticloud Snapshot Technology (MST). Within this interface, the system provides documentation and automated workflows that confirm the best installation process for the specific environment. This ensures that the required software versions and dependencies are met before attempting to protect workloads to cloud object storage like Amazon S3.
Utilizing the Marketplace simplifies the " Day Two " operational tasks by providing a validated path for deployment rather than relying on manual configuration or external templates.
NEW QUESTION # 85
An administrator is deploying a new NC2 cluster on AWS and needs to ensure full connectivity is established between the company's on-premises datacenter and the AWS cloud.
Which two AWS offering will satisfy this requirement? (Choose two.)
- A. Dedicated interconnect
- B. Direct Connect
- C. AWS VPN
- D. ExpressRoute
Answer: B,C
Explanation:
To establish full connectivity between the company's on-premises datacenter and the AWS cloud, the following AWS offerings will satisfy this requirement:
* AWS VPN: This service allows you to create a secure connection between your on-premises network or other remote network and your AWS VPC using an IPsec VPN tunnel. It is suitable for low to moderate bandwidth requirements and provides secure, encrypted connections.
* Direct Connect: AWS Direct Connect is a dedicated network connection from your premises to AWS. It provides a private, high-bandwidth, low-latency connection which is ideal for high-throughput applications and workloads that need consistent network performance.
AWS VPN Documentation
AWS Direct Connect Documentation
NEW QUESTION # 86
What are the supported NC2 on AWS instance types?
- A. i4i.4xlarge, i3.8xlarge, i7ie.2xlarge
- B. i7ie.24xlarge, i4i.32xlarge, i3.12xlarge
- C. i3.metal, t2.micro, g4dn.xlarge, M5d.medium
- D. i3.metal, i3en.metal, i4i.metal
Answer: D
Explanation:
Nutanix Cloud Clusters on AWS requires bare-metal EC2 instances to run the Nutanix AHV hypervisor and the Controller VMs (CVMs).
Nutanix supports specific " metal " instance types that provide the necessary hardware access for the hypervisor to manage resources efficiently. The primary supported instance types include thei3.metal, which is optimized for high I/O workloads; thei3en.metal, which offers more storage capacity and higher network bandwidth; and thei4i.metal, which utilizes the latest Intel Ice Lake processors for superior compute and storage performance. Other instance types listed, such as virtualized " xlarge " or " micro " instances, do not provide the bare-metal access required to run the Nutanix software stack in an NC2 environment.
NEW QUESTION # 87
An administrator has recently deployed an NC2 on AWS cluster in the North Virginia region in availability zone us-east-1z. The clusters UUID is 0005F487-4962-91EA-4C98-C4284D123835.
The cluster is consuming IPs from a 10.78.2.0/24 range.
The AWS VPC has these available CIDR ranges:
* 70.73.0.0/16
* 10.79.107.0/24
* 10.0.0.0/22
The following subnets have been configured in the NC2 AWS VPC:
The following tags have been applied to a Custom Network Security Group:
The Custom Network Security Group is allowing all inbound traffic from the 10.0.0.0/22 network. Which two subnets would be able to receive inbound traffic from AWS instances on a 10.0.0.0/22 network segment " ?
(Choose two.)
- A. SQL
- B. VDl
- C. Server01
- D. Tier01
Answer: C,D
Explanation:
To determine which subnets would be able to receive inbound traffic from AWS instances on a 10.0.0.0/22 network segment, we need to look at the configured subnets and their CIDR ranges, as well as the custom network security group ' s inbound rules.
* Available CIDR ranges in VPC:
* 70.73.0.0/16
* 10.79.107.0/24
* 10.0.0.0/22
* Configured Subnets in NC2 AWS VPC:
* VDI: 10.78.130.0/22
* SQL: 10.78.3.0/24
* Server01: 10.78.2.0/24
* Server02: 10.79.120.0/24
* Tier01: 10.19.101.0/24
* Custom Network Security Group Inbound Rule:
* Allows all inbound traffic from 10.0.0.0/22.
Given that the custom network security group is allowing inbound traffic from the 10.0.0.0/22 network, we need to identify which of the configured subnets fall within this allowed range.
Analysis:
* The subnets 10.78.130.0/22, 10.78.3.0/24, 10.78.2.0/24, 10.79.120.0/24, and 10.19.101.0/24 do not overlap with 10.0.0.0/22. Therefore, none of these subnets would naturally fall within the 10.0.0.0/22 range directly.
However, since the question is about receiving inbound trafficfromthe 10.0.0.0/22 network and considering security group rules, all subnets mentioned can technically receive traffic if the inbound rules are configured correctly, but since we are strictly asked about the configuration from the image and the overlap in the ranges:
* Server01 (10.78.2.0/24)andTier01 (10.19.101.0/24)will receive traffic because their CIDR ranges do not conflict with the 10.0.0.0/22 range, thus allowing traffic without additional restrictions.
Nutanix Clusters on AWS Administration Guide
AWS VPC and Subnet documentation
Network Security Group rules configuration in Nutanix documentation
NEW QUESTION # 88
An administrator has been tasked with performing a test migrating from an NC2 environment to a Nutanix on-premises environment.
Where should the administrator perform this task?
- A. Nutanix Cloud Services Portal
- B. On-premises Prism Central
- C. NC2 Prism Element
- D. NC2 Prism Central
Answer: D
Explanation:
When performing a migration from an NC2 environment to a Nutanix on-premises environment, the task should be performed using the NC2 Prism Central. This is because NC2 Prism Central provides a centralized management interface that allows administrators to manage and migrate workloads between cloud and on-premises environments seamlessly.
Reference:
Nutanix Cloud Clusters (NC2) Documentation
Nutanix Community Guide
NEW QUESTION # 89
The cluster is configured as follows:
* 8 nodes
* Prism Central Deployed
* Files Deployed
Following the deployment, the administrator experiences network connectivity issues.
Which reason explains the connectivity issues?
- A. The 192.168.5.0/24 range is reserved for internal cluster usage.
- B. The 192.168.5.0/24 range does not have enough IP addresses available.
- C. The 192.168.5.0/24 range is not a valid CIDR range.
- D. The 192.168.5.0/24 range is reserved by IANA,
Answer: A
Explanation:
* The 192.168.5.0/24 range is often reserved for internal cluster communication within Nutanix deployments.
* Using this CIDR range for other purposes could lead to network conflicts and connectivity issues, as it might interfere with the internal operations and communication channels of the Nutanix cluster.
* Ensuring that the CIDR range is not overlapping with any reserved ranges is crucial for maintaining proper network connectivity and cluster functionality.
Refer to the Nutanix documentation on network configuration and best practices for NC2 deployments to confirm reserved IP ranges and their appropriate use.
NEW QUESTION # 90
An administrator has deployed an NC2 cluster on AWS to an existing environment for VDI.
Afterwards, the corporate security teams direct the administrator to reuse an existing AWS subnet, 10.79.4.0/24 that has two EC2 instances: EC2-1 (10.79.4.200) and EC2-2 (10.79.4.201). The security team indicates that this directive is to avoid overlap with the AHV IPAM.
Which two configuration actions should the administrator take to ensure there are no configuration issues? (Choose two.)
- A. aCLI > net.add_to_ip_bfacklist 10.79.4.200 aCLI > net.add_to_ip_blacklist 10.79.4.201
- B. Deploy two VMs on the NC2 cluster and assign 10.79.4.200 and 10.79.4.201 as the assigned IPs in Prism Element
- C. aCLI > net.de/ete_from_ip_blacklist 10.79.4.200 aCLI > net.defete_fromjp_blacklist 10.79.4.201
- D. Configure the AHV JPAM to use DHCP range 10.79.4.2 -10.79.4.253.
Answer: A,D
Explanation:
To avoid IP address conflicts and ensure there are no configuration issues when reusing an existing AWS subnet, the administrator should take the following actions:
aCLI > net.add_to_ip_blacklist 10.79.4.200 aCLI > net.add_to_ip_blacklist 10.79.4.201 (Answer A):
This command adds the specified IP addresses to the blacklist, preventing AHV IPAM from assigning these addresses to any VMs. This ensures that the existing EC2 instances with IPs 10.79.4.200 and 10.79.4.201 are not allocated to other VMs in the NC2 cluster.
Configure the AHV IPAM to use DHCP range 10.79.4.2 -10.79.4.253 (Answer D):
By configuring the AHV IPAM to use a specific DHCP range, you ensure that the IP addresses assigned to the EC2 instances (10.79.4.200 and 10.79.4.201) are not included in the DHCP pool. This prevents IP address conflicts within the subnet.
Reference:
Nutanix aCLI Reference
Nutanix NC2 on AWS Documentation
AWS VPC and Subnet Basics
NEW QUESTION # 91
To manually create an AWS VPC with Public access to Prism Element for testing purposes, Which components must be created?
- A. VPC Subnets Route Tables NAT Gateway, Internet Gateway, Load balancer
- B. VPC, Delegated Subnets, Route Tables, NAT Gateway, vNets, Load balancer
- C. VPC Subnets Route subnets, Route Tables, NAT Gateway, Internet Gateway, VPN
- D. VPC, Delegated Subnets, Route Tables, NAT Gateway, Internet Gateway, Load balancer
Answer: D
Explanation:
* To manually create an AWS VPC with Public access to Prism Element for testing purposes, the following components must be created:
* VPC: A Virtual Private Cloud to provide an isolated network for the resources.
* Delegated Subnets: Subnets within the VPC to segment the network and allocate IP ranges.
* Route Tables: To define routing rules for the subnets to ensure proper traffic flow.
* NAT Gateway: To enable instances in the private subnets to access the internet.
* Internet Gateway: To allow direct internet access to instances in the public subnets.
* Load Balancer: To distribute traffic across multiple instances for improved availability and redundancy.
Refer to the AWS documentation on VPC creation and Nutanix documentation on network setup for Prism Element access.
NEW QUESTION # 92
An administrator has been tasked with ensuring NC2 VMs are able to access AWS resources. The NC2 VM traffic must not traverse the internet.
in which two ways would the administrator achieve this? (Choose two.)
- A. By using a Gateway Endpoint
- B. By using a VPC Peer.
- C. By using a NAT Gateway.
- D. By using an Interface Endpoint
Answer: B,D
Explanation:
To ensure that NC2 VMs can access AWS resources without traversing the internet, the administrator can use AWS VPC Peering and Interface Endpoints. Both methods ensure that traffic stays within the AWS network, maintaining security and efficiency.
Interface Endpoint:
Interface Endpoints allow you to privately connect your VPC to supported AWS services. They use AWS PrivateLink to route traffic directly to services within the AWS network, bypassing the public internet.
Steps:
Create an interface endpoint for the required service in the AWS VPC console.
Ensure the security groups and route tables are configured to allow traffic to the interface endpoint.
VPC Peering:
VPC Peering allows the routing of traffic between VPCs using private IP addresses, without the need for internet gateways, NAT devices, or VPN connections.
Steps:
Create a VPC peering connection between the VPCs.
Update the route tables to direct traffic between the peered VPCs.
Ensure security group rules allow the necessary traffic between VPCs.
Reference:
AWS VPC Peering Documentation
AWS Interface Endpoint Documentation
Nutanix Cloud Clusters on AWS Administration Guide
NEW QUESTION # 93
An administrator needs to create user VM subnets for multiple NC2 clusters in AWS.
What would be the best approach to take?
- A. Create guest-VM subnets for each cluster.
- B. Use the cluster management subnet dedicated to each cluster.
- C. Create guest-VM VNets for each cluster.
- D. Create guest-VM subnets to be shared by all clusters.
Answer: A
Explanation:
When creating user VM subnets for multiple NC2 clusters in AWS, the best approach is to create guest-VM subnets for each cluster. This ensures that each cluster has its own dedicated subnets, which simplifies network management and avoids potential IP conflicts.
Advantages of Dedicated Subnets:
Isolation: Each cluster operates in its own subnet, providing better isolation and security.
Management: Easier to manage and troubleshoot network issues when each cluster has its own subnets.
Scalability: More scalable as each subnet can be managed and expanded independently.
Steps to Create Guest-VM Subnets:
Identify the IP range for each subnet.
In the AWS VPC console, create a new subnet for each cluster using the identified IP ranges.
Associate the new subnets with the respective clusters during or after the cluster deployment process.
Why Not Shared Subnets:
Shared subnets could lead to IP conflicts and make network management more complex, especially as the number of clusters grows.
Reference:
Nutanix Cloud Clusters on AWS Administration Guide
AWS VPC Subnet Creation Documentation
NEW QUESTION # 94
During the deployment of the first NC2 cluster on AWS, Flow Virtual Networking automatically creates a transit VPC that contains a subnet. By default, what is the name of this subnet?
- A. overlay-internal-subnet-nonat
- B. overlay-external-subnet-nonat
- C. overlay-external-subnet-nat
- D. overlay-internal-subnet-nat
Answer: B
Explanation:
WhenFlow Virtual Networking (FVN)is enabled for an NC2 cluster, Nutanix orchestrates the creation of aTransit VPCto handle traffic between the overlay and external networks. The core subnet created within this Transit VPC is namedoverlay-external-subnet-nonat. This subnet is critical as it serves as the entry and exit point for traffic that should not be subjected to address translation, such as traffic moving between the cloud overlay and an on-premises data center via a Transit Gateway or VPN. While administrators can manually add a NAT-enabled subnet later, the " nonat " variant is the primary default used to ensure that internal corporate communications remain transparent across the hybrid cloud boundary.
NEW QUESTION # 95
Which container type supports the hibernate and resume feature in NC2 on AWS?
- A. AES containers
- B. Standard DSF containers
- C. Volumes-only containers
- D. Nearline storage containers
Answer: C
Explanation:
Hibernation is a key cost-optimization feature of NC2 that allows bare-metal nodes to be powered down while preserving the cluster ' s data state in cloud storage. For this functionality to be supported, the data must reside in a specific storage architecture. Only Volumes-only containers support the hibernate and resume feature in NC2 on AWS. These containers are specifically engineered to allow the Nutanix Distributed Storage Fabric (DSF) to safely offload data and metadata to Amazon S3 during the hibernation process and successfully re- integrate it into new bare-metal instances upon resumption. Standard storage containers or AES-optimized containers do not currently support the data mobility and offloading workflows required to preserve cluster state when the physical compute nodes are completely de-provisioned from the AWS environment.
NEW QUESTION # 96
An administrator needs to recover a cluster protected using the Cluster Protect feature. The Prism Central instance was not on the failed cluster.
Which steps, in order, should the administrator perform to recover the cluster?
Answer:
Explanation:
Explanation:
The steps, in order, to recover a cluster protected using the Cluster Protect feature when the Prism Central instance was not on the failed cluster are as follows:
* Step 1: Set the cluster to the Failed state using the NC2 console to start the recovery workflow.
* Step 2: Redeploy the cluster using the NC2 console.
* Step 3: Redeploy the Multicloud Snapshot Technology.
* Step 4: Recover UVM data by running CLI commands.
* Set the cluster to the Failed state using the NC2 console to start the recovery workflow: This step involves marking the cluster as failed to initiate the recovery process.
* Redeploy the cluster using the NC2 console: Once the cluster is marked as failed, the next step is to redeploy it using the tools available in the NC2 console.
* Redeploy the Multicloud Snapshot Technology: After the cluster is redeployed, the Multicloud Snapshot Technology needs to be redeployed to ensure data consistency and availability.
* Recover UVM data by running CLI commands: The final step is to recover the User VM (UVM) data by executing the necessary CLI commands to restore the data from the snapshots or backups.
Nutanix Documentation on Cluster Protect and Recovery Processes
Nutanix Support and Insights
Nutanix Cloud Clusters on AWS Administration
NEW QUESTION # 97
When onboarding to NC2 on AWS, which specific permission must the AWS User have for the account, and which roles must be supported for a successful deployment?
- A. CreateRoleFullAccess, IAMFullAccess, AWSCloudFormationFullAccess
- B. IAMFullAccess, AWSCloudFormation, CreateRole
- C. CreateRole, IAMFullAccess, AWSCloudFormationFullAccess
- D. AWSCloudFormation, CreateRoleFullAccess, IAMAccess
Answer: A
Explanation:
Successful onboarding of an AWS environment into the Nutanix Cloud Clusters ecosystem requires a precise set of administrative permissions to be present on the account used for initial configuration. Specifically, the AWS user must haveCreateRoleFullAccessto allow the automated scripts to generate the necessary service- linked roles. Additionally, the user must possessIAMFullAccessto manage identity policies andAWSCloudFormationFullAccessto execute the deployment templates. This specific combination ensures that the NC2 portal can correctly configure the " Cross-Account Role " which serves as the primary communication bridge between the Nutanix management plane and the AWS infrastructure APIs. Failing to provide any of these three core permissions will result in an " Insufficient Permissions " alert during the cloud account registration process.
NEW QUESTION # 98
An administrator is tasked with deploying a VM in an NC2 cluster on AWS that needs to by accessed by resources within the on-premises datacenter.
The cluster has the following characteristics:
* 8 nodes
* Resides in the us-east-1a Availability Zone
* Contains 13 Subnets
* Has access to a Direct Connect connection
* Subnet that the User VM (UVM) is being deployed to:UserVM_subnet
There are multiple VMs within the cluster and the UserVM_subnet has access to the on-premises resources.
The administrator deploys the machine, but communication is not possible.
What is the most likely resolution for this situation?
- A. The AWS Internal Management Security Group requires the new application ' s ports adding to outbound traffic.
- B. The AWS User Management Security Group requires the new application ' s ports adding to and traffic
- C. The AWS UVM Security Group requires the new application ' s ports adding to inbound traffic.
- D. The AWS IGW requires the new application ' s ports adding to inbound traffic.
Answer: C
Explanation:
* For a VM deployed in an NC2 cluster on AWS to be accessed by resources within the on-premises datacenter, the security group associated with the User VM (UVM) subnet must allow inbound traffic on the specific ports required by the application.
* If the security group rules do not permit inbound traffic on these ports, the communication will fail, even if other network configurations are correct.
* The administrator should ensure that the UVM Security Group includes rules to allow inbound traffic for the application ' s required ports, facilitating proper communication between the VM and on- premises resources.
Refer to the AWS documentation on security group configurations and Nutanix NC2 documentation for details on configuring network access and security group rules.
NEW QUESTION # 99
What is the correct sequence of steps in the Replace Host operation in an NC2 cluster on AWS?
- A. Power off old host - > Add new host - > Migrate VMs
- B. Snapshot VMs - > Remove host - > Re-add host
- C. Remove old host - > Add new host - > Migrate VMs
- D. Add new host - > Migrate VMs - > Remove old host
Answer: D
Explanation:
To ensure continuous availability and maintain the specified Replication Factor (RF) during maintenance or hardware issues, Nutanix follows a proactive " provision before removal " logic for host replacement in the cloud. The correct operational sequence begins with adding a new host to the cluster first. This step expands the cluster ' s capacity and ensures there is a destination ready for data synchronization. Once the new host is fully integrated into the storage fabric, the system migrates the virtual machines and their associated data away from the degraded or old host. Only after the old host has been completely evacuated and the cluster returns to a healthy, balanced state does the NC2 console conclude the operation by removing the old host from the cluster configuration.
NEW QUESTION # 100
......
Latest 100% Passing Guarantee - Brilliant NCP-CI-AWS Exam Questions PDF: https://examcollection.bootcamppdf.com/NCP-CI-AWS-exam-actual-tests.html