Nutanix NCP-NS-7.5 Exam Overview:
| Certification Vendor: | Nutanix |
|---|---|
| Exam Name: | Nutanix Certified Professional - Network and Security (NCP-NS) 7.5 Exam |
| Exam Number: | NCP-NS-7.5 |
| Exam Price: | $200 USD |
| Real Exam Qty: | 75 |
| Related Certifications: | Nutanix Certified Professional (NCP) |
| Available Languages: | Japanese, English |
| Passing Score: | 3000 (scaled score 1000–6000) |
| Certificate Validity Period: | 2 years |
| Exam Format: | Scenario-based questions, Multiple choice |
| Exam Duration: | 120 minutes |
| Recommended Training: | Nutanix Network & Security Administration (NNSA) |
| Exam Registration: | Nutanix Certification Portal |
| Sample Questions: | Nutanix NCP-NS-7.5 Sample Questions |
| Exam Way: | Online proctored or onsite testing center |
| Pre Condition: | Approx. 2 years of network/security experience; 6+ months working with Nutanix Flow; recommended: Nutanix Network & Security Administration (NNSA) training |
| Official Syllabus URL: | https://www.nutanix.com/en_sg/support-services/training-certification/certifications/certification-details-nutanix-certified-professional-network-security |
Nutanix NCP-NS-7.5 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Troubleshoot Flow Network and Security | 15% | - Troubleshoot network connectivity issues
|
| Deploy and Upgrade Flow Environment | 10% | - Prepare cluster for Flow deployment
|
| Manage Flow Operations and Monitoring | 20% | - Manage user roles and access control
|
| Configure Flow Network Security | 30% | - Implement microsegmentation and security policies
|
| Configure Flow Virtual Networking | 25% | - Manage external networks and transit connectivity
- Create and manage VPC and overlay networks
|
Nutanix Certified Professional - Network and Security (NCP-NS) 7.5 Sample Questions:
Question 1
An administrator needs to ensure all web traffic (HTTP/HTTPS) from a specific subnet (10.100.20.0/24) is redirected through a third-party virtual firewall inside the VPC for Layer 7 inspection before reaching the internet. The firewall VM has an IP of 10.100.30.5 and is connected to a different subnet. What should be done to enforce this specific traffic path?
A. Configure a Policy-Based Route (PBR) on the VPC with a re-route IP 10.100.30.5.
B. Move the Firewall VM into the same subnet and set the default GW of the web servers to 10.100.30.5.
C. Create a Network Policy with a high priority with the source 10.100.20.0/24, destination of 10.100.30.5 on port 80 & 443.
D. Create a FNS policy with an allow rule for the FW IP 10.100.30.5.
Question 2
An administrator has observed the following message: Which two statements most accurately describe the security hitlog captured above? (Choose two.)
A. This is a security hit log on the rule name "Production-External-WebTier".
B. 10.38.174.57 is sending a packet destined to UDP 123.
C. The source ip address is 10.38.174.5 and source port is TCP/123.
D. 86.108.190.23 is sending a packet on UDP 123.
Question 3
What type of policy would be used to block all traffic between VMs in the category Environment:Sandbox and VMs in the category Environment:Production?
A. Quarantine Policy
B. Isolation Policy
C. Shared Services Policy
D. Application Policy
Question 4
An administrator sets up a VPN between two Nutanix VPCs in different Availability Zones. After deployment, the VPN tunnel shows as Up, but traffic between the VPCs is not flowing. Which configuration step is most likely missing?
A. NAT policy on each of the VPC routers
B. IPsec encryption settings on the VPN profile
C. MTU adjustment on the AHV hosts
D. Static routes for remote subnets on the VPC
Question 5
An enterprise has deployed a VPC called FinanceVPC using Nutanix Flow Virtual Networking. The Finance team needs the following connectivity: Internal servers in the VPC must reach an on-premises corporate data- center via a point-to-point encrypted link. Some servers in the VPC must also access the public internet with source NAT and receive inbound access via floating IPs. The corporate network uses overlapping IP space with other VPCs in the environment, so address translation is necessary for those workloads. The networking design must support routing via BGP for future site expansions and provide low-latency north-south connectivity. Which actions should the administrator take to satisfy this requirement?
A. Use a single No-NAT External Network for both on-prem and Internet access; configure BGP and direct routing out to the internet without NAT.
B. Use a No-NAT External Network for the on-premises link and a NAT External Network for Internet access. Configure a VPN tunnel to the on-premises location and enable BGP on the VPC router for the on-premises link.
C. Use two No-NAT External Networks-one for the on-prem link and one for Internet access; configure static routes for both without NAT.
D. Use a single NAT External Network for both the on-prem link and Internet access; configure a default route to the external network and enable SNAT and floating IPs for all traffic.
Solutions:
| Question 1 Answer: A | Question 2 Answer: B,C | Question 3 Answer: B | Question 4 Answer: D | Question 5 Answer: B |
We're so confident of our products that we provide no hassle product exchange.


By Lance

