A Review Of Accurate NCP-CI-Azure Training Materials

Validated of NCP-CI-Azure actual test materials and dump for Nutanix certification for IT engineers, Real Success Guaranteed with Updated NCP-CI-Azure pdf dumps vce Materials. 100% PASS Nutanix Certified Professional - Cloud Integration - Azure (NCP-CI-Azure v6.7) exam Today!

Page: 1 / 6
Total 75 questions Full Exam Access
Question 1
An administrator needs the permission to create and manage multipleorganizations and clusters in NC2, as well as manage user access for the entire company.
What role should be assigned to meet the minimum requirements of this task?
My answer: -
Reference answer: A
Reference analysis:

✑ Role Requirements: The task involves creating and managing multiple organizations and clusters, along with managing user access across the company.
✑ Role Capabilities: The "Customer Administrator" role is designed to provide extensive administrative capabilities, including:
✑ Comparison of Roles:
✑ Conclusion: The "Customer Administrator" role meets all the requirements for managing organizations, clusters, and user access comprehensively.
References:
✑ Nutanix Role-Based Access Control Documentation
✑ NC2 on Azure User Roles Guide

Question 2
A nutanix user VPC called servers has three subnets called Tier1, tier2 and Darren-Tier3.
*Servers:10.0.0.0/16
* Tier1: 10.0.0.0/16
* Tier2: 10.0.0.0.128/25
* Darren-Tier3:10.0.4.0/24
An administrator wants to keep Darren-Tier3 isolated and not receive any outside traffic. In order properly route for Tier1 and Tier2 coming from native subnets for Azure, what
should the ERP be set to?
My answer: -
Reference answer: D
Reference analysis:

✑ ERP Configuration: ERP (External Route Prefix) settings determine how traffic is routed between subnets and VPCs.
✑ Objective: The goal is to isolate Darren-Tier3 while ensuring proper routing for Tier1 and Tier2.
✑ Transit VPC ERP: Setting it to 10.0.0.0/16 ensures that it covers the entire VPC range, allowing traffic within Tier1 and Tier2.
✑ Servers ERP: Setting it to 10.0.4.0/24 ensures isolation for Darren-Tier3 by limiting
traffic to that specific subnet and preventing external traffic from reaching it.
✑ Conclusion: This configuration achieves the isolation of Darren-Tier3 while allowing proper routing for Tier1 and Tier2.
References:
✑ Nutanix Networking Documentation
✑ Azure Virtual Network Documentation

Question 3
An organization uses a Pay As. You Go subscription plan and wants to pay directly to Nutanix.
What is a valid payment method available to pay directly to Nutanix?
My answer: -
Reference answer: A
Reference analysis:

✑ Payment Method Options:When using a Pay As You Go subscription plan and opting to pay directly to Nutanix, wire transfer is a valid and secure payment method.
✑ Direct Payment:Wire transfers allow for the direct transfer of funds from the organization's bank account to Nutanix, ensuring a straightforward and efficient payment process.
References:
✑ Nutanix Billing and Payment Documentation
✑ Pay As You Go Subscription Payment Methods Guide

Question 4
An organization wants to use a Jump Host to access Prism Element and Prism Central within an NC2 cluster on Azure.
Which statement is true?
My answer: -
Reference answer: B
Reference analysis:

✑ Jump Host Deployment:A Jump Host is a secure server used to access other systems in a network. In the context of an NC2 cluster on Azure, it serves as an intermediary for accessing Prism Element and Prism Central.
✑ Flexible Deployment Options:The Jump Host can be deployed in either the Prism Central VNet or an external VNet, providing flexibility in network design and access strategies. This allows the organization to choose the most suitable network for deploying the Jump Host based on their security and connectivity requirements.
References:
✑ Nutanix NC2 on Azure Deployment Guide
✑ Azure Virtual Network Configuration Documentation

Question 5
A new subnet needs to be created within Flow Virtual Networking to accommodate a new type of workload in the company??s NC2 Azure instance.
Which type of network will satisfy this task?
My answer: -
Reference answer: B
Reference analysis:

✑ Flow Virtual Networking: Nutanix Flow Virtual Networking allows for the creation of overlay networks to segment and manage network traffic.
✑ Network Types:
✑ Requirement: Creating a subnet for new workloads within Flow Virtual Networking suggests using an overlay network for logical separation and management.
✑ Conclusion: An overlay network within Flow Virtual Networking will satisfy the task of accommodating a new type of workload in the NC2 Azure instance.
References:
✑ Nutanix Flow Networking Guide
✑ Azure Virtual Network Documentation

Question 6
When configuring permissions for an Azure subscription, which role is required to delegate minimum permissions for the Azure AD App registration?
My answer: -
Reference answer: A
Reference analysis:

✑ Azure AD App Registration: When setting up an application registration in Azure AD, specific permissions are required to delegate access.
✑ User Access Administrator Role: This role has the necessary permissions to manage user access to Azure resources, including delegating permissions for app registrations.
✑ Comparison of Roles:
✑ Conclusion: The Azure User Access Administrator role is required to delegate minimum permissions for Azure AD App registration.
References:
✑ Azure Role-Based Access Control Documentation
✑ Azure AD App Registration Guide

Question 7
An administrator is tasked with configuring connectivity between an on-premises datacenter and Azure.
Which two connectivity options are supported? (Choose two.)
My answer: -
Reference answer: AC
Reference analysis:

For configuring connectivity between an on-premises datacenter and Azure, the two supported options are:
✑ VPN (Virtual Private Network):Site-to-Site VPN allows you to create a secure
connection from your on-premises network to Azure over the public internet using IPsec/IKE protocols.
✑ ExpressRoute:Provides a private connection between your on-premises
infrastructure and Azure, ensuring traffic does not traverse the public internet. Both options provide secure and reliable connectivity, with ExpressRoute offering enhanced performance and security due to its private connection.References
✑ Azure VPN Gateway
✑ Azure ExpressRoute Overview

Question 8
An administrator is deploying an NC2 cluster in Azure and observes on NC2 console that nodes will not progress and continue in a Booting state.
What is the most likely cause for the node not continuing to deploy?
My answer: -
Reference answer: C
Reference analysis:

✑ Azure Subscription Validation: When deploying an NC2 cluster, the Azure subscription must be validated and allowlisted by Microsoft. This is a crucial step to ensure that the necessary permissions and configurations are set up for the deployment.
✑ Booting State Issue: If the nodes are stuck in the Booting state, it often indicates that the subscription has not been properly validated and allowlisted. This prevents the deployment from progressing as required resources and permissions are not fully accessible.
✑ Checking Allowlisting Status: Administrators should verify that their subscription has been allowlisted by contacting Azure support or checking the status through the Azure portal.
✑ Resolution: Once the subscription is validated and allowlisted by Microsoft, the deployment should proceed without the nodes getting stuck in the Booting state.
References:
✑ Nutanix NC2 on Azure Documentation
✑ Azure Subscription Management

Question 9
A nutanix User VPC named Servers has a subnet named Tier1: Servers: 10.0.0.0/20
Tier1: 10.0.0.0/25
Tier is using floating IPS to allow inbound traffic to the web servers that are hosted for a payroll system.
The company requires that the Network Security Group allow other Native Azure instances running in subnet AD (10.20.0.0/24) in the Prism Central VNet to be able to contact the web servers.
Which statement is true regarding this company requirement?
My answer: -
Reference answer: B
Reference analysis:

✑ Flow Gateway Network Security Group (NSG):NSGs control the traffic flow to and from network interfaces associated with VMs and other resources. Configuring the NSG correctly is crucial for ensuring that required traffic is allowed.
✑ Internal NIC Configuration:To allow Native Azure instances in the Prism Central VNet (10.20.0.0/24) to access the web servers in the Tier1 subnet, the internal NIC of the Flow Gateway must be configured to allow traffic from 10.20.0.0/24. This ensures that inbound traffic from these instances is permitted and properly routed to the web servers.
References:
✑ Azure Network Security Group Documentation
✑ Nutanix Flow Gateway Configuration Guide

Question 10
Native Azure VMs exist in a subnet (10.20.80.0/20) in the Prism Central VNet that need access to the workload running on the Nutanix User.
What needs to be modified to allow access from the native Azure VMs to the workloads running in the Nutanix User VPC?
My answer: -
Reference answer: D
Reference analysis:

To allow access from the native Azure VMs to the workloads running in the Nutanix User VPC, the administrator needs to:
✑ Adjust the Inbound Network Security Group (NSG) on the Flow Gateway VM's
Internal NIC.
✑ Specifically, allow traffic from the subnet range of the native Azure VMs (10.20.80.0/20) in the Inbound rules of the NSG associated with the Internal NIC of the Flow Gateway VM.
This configuration change permits the desired network traffic, ensuring that the native Azure VMs can communicate with the workloads in the Nutanix User VPC.References
✑ Azure Network Security Groups Overview
✑ Nutanix Networking and Security Best Practices

Question 11
An administrator must ensure that certain NC2 VMs can access Azure resources. The NC2 VM traffic must not traverse the internet.
How would the administrator achieve this?
My answer: -
Reference answer: A
Reference analysis:

✑ Azure Private Endpoint:A Private Endpoint provides secure connectivity to Azure resources by enabling private access through the Azure backbone network. This ensures that the traffic does not traverse the internet, providing enhanced security and performance.
✑ Delegated Subnet:By creating an Azure Private Endpoint for VMs in a delegated subnet, the administrator ensures that the VMs can access Azure resources directly and securely without using the public internet.
References:
✑ Azure Private Endpoint Documentation
✑ Nutanix NC2 Networking Configuration Guide

Question 12
Which address must Azure Directory Service be able to resolve when deploying a new NC2 cluster?
My answer: -
Reference answer: C
Reference analysis:

✑ Azure Directory Service Role: Azure Directory Service must be able to resolve specific Nutanix URLs to ensure proper communication and functionality during the deployment of an NC2 cluster.
✑ Critical Endpoint: The address "Gateway-external-api.cloud.nutanix.com" is critical for establishing external API communications required for the deployment and management of the NC2 cluster.
✑ DNS Resolution: Proper DNS resolution of this address ensures that the Azure Directory Service can interact with Nutanix services and APIs necessary for cluster operations.
✑ Verification Process:
✑ Importance: Without resolving this address, the deployment process might face connectivity issues, leading to potential deployment failures.
References:
✑ Nutanix NC2 on Azure Setup Guide
✑ Azure Active Directory Integration

Question 13
An administrator ran into an issue during an NC2 cluster deployment on Azure. The administrator has logged a case with Nutanix Support.
Support has requested the following logs from NC2 on Azure in order to diagnose the deployment issue:
* Cluster_agent
* Host_agent
* Hostsetup
What action should the administrator take to ensure the collect the appropriate logs?
My answer: -
Reference answer: B
Reference analysis:

To collect the appropriate logs (Cluster_agent, Host_agent, and Hostsetup) for diagnosing the deployment issue with Nutanix Support, the administrator should:
✑ Log in to Prism Element to access the Controller VM (CVM) console.
✑ Run thelogbay collectcommand from the CVM console. This command collects the necessary logs and packages them for support.
This method ensures that the correct logs are gathered in a format that Nutanix Support can analyze.References
✑ Nutanix Support Documentation on Log Collection

Question 14
Which wen interface should be used to most efficiently terminate a Nutanix cloud cluster?
My answer: -
Reference answer: C
Reference analysis:

To efficiently terminate a Nutanix cloud cluster, the NC2 (Nutanix Cloud Clusters) Console should be used. The NC2 Console provides the necessary tools and interface specifically designed for managing and terminating Nutanix clusters within cloud environments, ensuring a seamless and efficient process.References
✑ Nutanix Cloud Clusters Documentation

Question 15
An administrator is trying to determine which type of DNS server to deploy for a networking
infrastructure in Azure.
Which DNS server option would require either VPN or ExpressRoute connectivity?
My answer: -
Reference answer: C
Reference analysis:

✑ DNS Server Options:
✑ Connectivity Requirements:
✑ Conclusion: An on-premises DNS server would require VPN or ExpressRoute connectivity to be accessible and integrated with the Azure environment.
References:
✑ Azure DNS Overview
✑ VPN Gateway Configuration
✑ ExpressRoute Overview

Question 16
An administrator needs to configure the correct outbound requirement for a successful cluster deployment in Azure.
Which destination must have an outbound rule to meet this requirement?
My answer: -
Reference answer: B
Reference analysis:

✑ Outbound Rule Necessity: For successful cluster deployment, certain outbound connections must be allowed to ensure proper download and configuration of resources.
✑ Critical Destination: "Https://downloads.cloud.nutanix.com/*" is a critical endpoint from which the Nutanix software and updates are downloaded during the cluster
deployment process.
✑ Functionality: Ensuring an outbound rule for this destination allows the deployment to fetch necessary files and updates, enabling smooth cluster setup and operation.
✑ Other Destinations:
✑ Conclusion: Outbound connectivity to "Https://downloads.cloud.nutanix.com/*" is essential for downloading deployment resources.
References:
✑ Nutanix NC2 on Azure Network Configuration Guide
✑ Azure Network Security Documentation

Question 17
Exhibit
NCP-CI-Azure dumps exhibit
An NC2 on Azure cluster was deployed with two Flow Gateway in HA (FHW1 and FGW2). After a week of use, four bare-metal nodes were added to the NC2 cluster and additional workloads were added. The existing workloads were using floating IPs to allow inbound traffic to communicate with the running workloads on the NC2 cluster.
It was determined that additional bandwidth for north/south traffic would be needed. Two
additional Flow Gateways were added (FGW3 and FGW4) from the NC2 portal configuration menu.
The existing workloads prior to expansion on the NC2 cluster will be able to use which Flow Gateways using the NAT traffic path after the expansion?
My answer: -
Reference answer: C
Reference analysis:

In the NC2 on Azure cluster scenario, the existing workloads were using floating IPs for inbound traffic before the addition of new Flow Gateways (FGW3 and FGW4). The NAT traffic path established initially will continue to direct traffic through the originally assigned Flow Gateways (FGW1 and FGW2). The existing workloads will not automatically utilize the new Flow Gateways (FGW3 and FGW4) without a reconfiguration or reboot, which reassigns the NAT paths.
References
✑ Nutanix Flow Networking and Configuration Guide

Question 18
The cluster has the following configuration:
A Transit VPC exists as Default, but is additionally configured with a overlay-external- subnet-nonat overlay subnet
The ERP for the Transit VPC is 10.1.1.0/25 A User VPC exists named User_VPC_Prod The ERP for the User VPC is 10.1.1.0/24
Outbound and inbound routes have been configured
A User VM NO-NAT subnet has been configured in the User VPC
The administrator has successfully created a VM and added the NIC associated with the NO-NAT subnet, but is not able to communication with other resources.
Which option will resolve this issue?
My answer: -
Reference answer: A
Reference analysis:

In this scenario, the issue arises from overlapping IP address ranges between the Transit VPC and the User VPC. Here??s a detailed breakdown:
✑ Understanding ERPs (Elastic Routing Prefixes):
✑ IP Address Overlap:
✑ Communication Issue:
✑ Resolution:
By ensuring that the ERPs are in different CIDR ranges, the network can properly route traffic between the VPCs without any conflicts or ambiguities, thereby enabling the VM in the User VPC to communicate with other resources effectively.

Question 19
What action is performed in Azure when an instance is reported as being in a terminated state, but NC2 expects it to be in a running state?
My answer: -
Reference answer: D
Reference analysis:

✑ Instance Termination Detection:When an instance in Azure is reported as being in a terminated state but NC2 expects it to be running, the system will automatically take corrective actions.
✑ Host Condemnation and Replacement:NC2 will condemn the host, marking it as unusable, and will then trigger the replacement process to ensure that the cluster maintains its required capacity and performance levels. This automatic handling ensures minimal disruption to the workloads running on the cluster.
References:
✑ Nutanix NC2 Automated Management Features
✑ Azure Instance State Documentation

Page: 1 / 6
Total 75 questions Full Exam Access