Get Ready to Pass the NCP-CI-Azure exam with Nutanix Latest Practice Exam [Q10-Q32]

Share

Get Ready to Pass the NCP-CI-Azure exam with Nutanix Latest Practice Exam

Get Prepared for Your NCP-CI-Azure Exam With Actual Nutanix Study Guide!

NEW QUESTION # 10


Which action shouldthe administrator take to troubleshoot the error shown in the exhibit?

  • A. Check the Azure subnet delegation status.
  • B. Check the Azure AD App registration Client Secret.
  • C. Check the PC VNet is peered correctly.
  • D. Check the NC2 organization permissions.

Answer: B

Explanation:
To troubleshoot the error shown in the exhibit where Azure credentials are not valid and the creation of the resource group failed, the administrator should:
* Verify that the Azure AD App registration has been correctly configured, especially the Client Secret.
* Ensure that the Client Secret is valid, has not expired, and matches what has been entered in the configuration.
This step is crucial because an invalid or expired Client Secret would prevent the validation of Azure credentials and the creation of necessary resources.
References
* Azure AD App Registration and Secrets Management
* Nutanix Cluster Configuration Documentation


NEW QUESTION # 11
What is an available log module when configuring a syslog server in the Prism Central Admin Center?

  • A. API Audit
  • B. Zookeeper
  • C. Acropolis
  • D. Prism

Answer: C

Explanation:
* Log Modules in Prism Central:When configuring a syslog server, different log modules can be selected to send logs to an external syslog server for centralized logging and analysis.
* Acropolis Logs:The Acropolis module captures logs related to the Acropolis Hypervisor (AHV), including virtual machine operations, storage operations, and other critical functions within the Nutanix environment.
References:
* Nutanix Prism Central Administration Guide
* Nutanix Acropolis Documentation


NEW QUESTION # 12
An administrator is planning an NC2 deployment in Azure and wants to connect the company's on-premises datacenter to the cloud environment.
What connectivity solution should the administrator use to avoid traffic between the locations flowing over the public internet?

  • A. Point-to-Site VPN
  • B. ExpressRoute
  • C. Site-to-Site VPN
  • D. VTEP Gateways

Answer: B

Explanation:
To connect the company's on-premises datacenter to the Azure cloud environment while avoiding traffic over the public internet, the administrator should use Azure ExpressRoute. ExpressRoute provides a private connection to Azure, offering more reliability, faster speeds, and lower latencies compared to typical internet connections. This service ensures that data traffic does not traverse the public internet, enhancing security and performance.References
* Azure ExpressRoute Overview


NEW QUESTION # 13
An administrator is tasked with adding an Azure account to the NC2 console. A requirement is to configure an Azure user that can open, close or extend a support tunnel for the Nutanix Support team.
Which permission must be assigned to the user?

  • A. Customer Auditor
  • B. Account Administrator
  • C. Cluster Auditor
  • D. Cluster Administrator

Answer: B

Explanation:
* Account Administrator Role:This role grants the necessary permissions for managing the Azure account, including the ability to open, close, or extend a support tunnel. These capabilities are crucial for the Nutanix Support team to perform diagnostics and troubleshooting efficiently.
* Permissions Included:The Account Administrator role encompasses broader account management rights, ensuring that the user can interact with various support and operational aspects of the NC2 environment within Azure.
References:
* Azure Role-Based Access Control (RBAC) Documentation
* Nutanix NC2 Support Tunnel Requirements


NEW QUESTION # 14
A nutanix user VPC called servers has three subnets called Tier1, tier2 and Darren-Tier3.
*Servers:10.0.0.0/16
* Tier1: 10.0.0.0/16
* Tier2: 10.0.0.0.128/25
* Darren-Tier3:10.0.4.0/24
An administrator wants to keep Darren-Tier3 isolated and not receive any outside traffic.
In order properly route for Tier1 and Tier2 coming from native subnets for Azure, what should the ERP be set to?

  • A. Transit VPC ERP set to 10.0.0.0/20 and Servers ERP set to 10.0.0.0/24
  • B. Transit VPC ERP set to 10.0.0.0/24 and Servers ERP set to 10.0.0.0/24
  • C. Transit VPC ERP set to 10.0.0.0/16 and Servers ERP set to 10.0.4.0/24
  • D. Transit VPC ERP set to 10.0.0.0/16 and Servers ERP set to 10.0.0.0/25

Answer: C

Explanation:
* ERP Configuration: ERP (External Route Prefix) settings determine how traffic is routed between subnets and VPCs.
* Objective: The goal is to isolate Darren-Tier3 while ensuring proper routing for Tier1 and Tier2.
* Transit VPC ERP: Setting it to 10.0.0.0/16 ensures that it covers the entire VPC range, allowing traffic within Tier1 and Tier2.
* Servers ERP: Setting it to 10.0.4.0/24 ensures isolation for Darren-Tier3 by limiting traffic to that specific subnet and preventing external traffic from reaching it.
* Conclusion: This configuration achieves the isolation of Darren-Tier3 while allowing proper routing for Tier1 and Tier2.
References:
* Nutanix Networking Documentation
* Azure Virtual Network Documentation


NEW QUESTION # 15
An administrator needs to extend an on-premises subnet to an NC2 cluster on Azure.
Which set of options should the administrator configure to complete this task?

  • A. Subnet Type: On-premises VLAN subnets and VPC subnets Traffic Type: IPv6 umcasi traffic and ARP On-premises Hypervisor: Hyper-V
  • B. Subnet Type: On-premises VLAN subnets and VPC subnets Traffic Type: IPv4 unicast traffic IPv6 unicast traffic and ARP On-premises Hypervisor: ESXi and AHV
  • C. Subnet Type: On-premises VLAN subnets and VPC subnets Traffic Type: IPv4 unicast traffic and ARP On-premises Hypervisor: AHV
  • D. Subnet Type: VPC subnets
    Traffic Type: IPv4 unicast traffic and ARP
    On-premises Hypervisor: ESXi, AHV, Hyper-V

Answer: B

Explanation:
To extend an on-premises subnet to an NC2 cluster on Azure, the administrator should configure:
* Subnet Type:Both on-premises VLAN subnets and VPC subnets. This ensures that the subnet can span both the on-premises environment and the Azure environment.
* Traffic Type:Support for IPv4 unicast traffic, IPv6 unicast traffic, and ARP is necessary to ensure
* proper communication and address resolution across the extended subnet.
* On-premises Hypervisor:ESXi and AHV are supported hypervisors for this type of configuration, allowing for a seamless extension of the subnet between these environments.
References
* Nutanix Hybrid Cloud Networking


NEW QUESTION # 16
Which interface must be used to deploy NC2?

  • A. Cloud Provider portal
  • B. NC2 Tile within the my.nutanix.com portal
  • C. Prism Central Dashboard
  • D. Foundation running in a Cloud Virtual Machine

Answer: B

Explanation:
* my.nutanix.com Portal:This portal provides access to various Nutanix services and features, including the NC2 deployment interface.
* NC2 Tile:The NC2 tile within the portal is specifically designed for deploying and managing Nutanix Cloud Clusters. It provides the necessary tools and settings to initiate and configure NC2 clusters on Azure or other cloud environments.
References:
* Nutanix NC2 Deployment Guide
* my.nutanix.com Portal Documentation


NEW QUESTION # 17
An administrator deploys a new NC2 cluster in Azure in a new subscription. No VPN or Express Route exists.
Which two actions will allow the administrator access to Prism Central to start the configuration? (Choose two.)

  • A. Deploy a Jump Host VM instance in the Prism Central VNet inside a delegated subnet.
  • B. Deploy a Jump Host VM instance in the Prism Central VNet inside a non-delegated subnet.
  • C. Deploy a Jump Host VM instance and NAT Gateway in an external VNet and peer the VNets.
  • D. Deploy a Jump Host VM instance in an external VNet and peer the VNets.

Answer: A,D

Explanation:
* Jump Host VM in External VNet with VNet Peering:
* Deploy Jump Host VM:Deploy a VM in an external VNet that is not within the same network as Prism Central.
* VNet Peering:Establish VNet peering between the external VNet and the Prism Central VNet.
This allows the Jump Host to communicate with Prism Central securely.
* Jump Host VM in Prism Central VNet Inside a Delegated Subnet:
* Deploy Jump Host VM:Deploy the Jump Host VM directly in the Prism Central VNet within a delegated subnet. This places the Jump Host in the same network environment as Prism Central, allowing direct access.
References:
* Azure VNet Peering Documentation
* Nutanix NC2 Networking and Access Configuration Guide


NEW QUESTION # 18
Which wen interface should be used to most efficiently terminate a Nutanix cloud cluster?

  • A. Prism Element Console
  • B. AWS Console
  • C. Prism Central Console
  • D. NC2 Console

Answer: D

Explanation:
To efficiently terminate a Nutanix cloud cluster, the NC2 (Nutanix Cloud Clusters) Console should be used.
The NC2 Console provides the necessary tools and interface specifically designed for managing and terminating Nutanix clusters within cloud environments, ensuring a seamless and efficient process.References
* Nutanix Cloud Clusters Documentation


NEW QUESTION # 19
An organization want to use existing Azure resources to deploy NC2.
What is a valid requirement to use existing Azure resources for this task?

  • A. A new Azure resource group must be created where all resources, such as VNets must be created.
  • B. The fastpathenabled tag must be added after creating a NAT gateway.
  • C. Azure NAT gateway must be attached to the cluster management Prism Central, and external Flow Gateway subnets.
  • D. More than two DNS servers must be used.

Answer: A

Explanation:
* Resource Group Requirement:When deploying NC2 on Azure, it is essential to organize resources such as VNets, subnets, and other components in a dedicated resource group. This helps in managing and maintaining the resources efficiently.
* New Resource Group:Creating a new Azure resource group ensures that all the necessary NC2 resources are isolated and managed together, avoiding conflicts with existing resources and providing a clear separation for administration and billing purposes.
References:
* Azure Resource Group Documentation
* Nutanix NC2 Deployment Guide


NEW QUESTION # 20
Exhibit.

AN NC2 on Azure Cluster was deployed with two Flow gateways in HA (FGW1 and FGW2). After a week of use. Four bare-metal nodes, were added to the NC2 cluster and additional workloads were added.
It was determined that additional bandwidth for north/South traffic would be needed. Two additional Flow gateways were added (FGW3 and FGW4) from the NC2 portal configuration menu.
The existing workloads prior to expansion on the NC2 cluster will be able to use which Flow Gateways using the No-Nat (routed) traffic path?

  • A. All Flow Gateways can be used after the existing workloads reboot.
  • B. FGW1&FGW2 only, new workloads can use FGW3 & FGW4.
  • C. Only the Flow Gateway that each workload was originally using.
  • D. All Flow Gateways can be used.

Answer: D

Explanation:
In the scenario presented, the NC2 cluster was initially deployed with two Flow Gateways (FGW1 and FGW2) in HA. After adding four bare-metal nodes and additional workloads, two more Flow Gateways (FGW3 and FGW4) were added to handle the increased bandwidth for north/south traffic. Given the configuration, the existing workloads can utilize all available Flow Gateways (FGW1, FGW2, FGW3, and FGW4) for No-NAT (routed) traffic paths. This setup allows for Equal Cost Multipath (ECMP) routing, distributing traffic load across all Flow Gateways.
References
* Nutanix Flow Networking


NEW QUESTION # 21
The cluster has the following configuration:
A Transit VPC exists as Default, but is additionally configured with a overlay-external-subnet-nonat overlay subnet The ERP for the Transit VPC is 10.1.1.0/25 A User VPC exists named User_VPC_Prod The ERP for the User VPC is 10.1.1.0/24 Outbound and inbound routes have been configured A User VM NO-NAT subnet has been configured in the User VPC The administrator has successfully created a VM and added the NIC associated with the NO-NAT subnet, but is not able to communication with other resources.
Which option will resolve this issue?

  • A. Check that the network ACLs for the NO-NAT subnet are not blocking the necessary traffic.
  • B. Ensure that the security groups associated with the VM allow traffic to and from the desired resources.
  • C. The ERP in the User VPC must be from a different CIDR range than the ERP in the transit VPC.
  • D. Verify that the route table associated with the User VPC has appropriate routes to the Transit VPC.

Answer: C

Explanation:
In this scenario, the issue arises from overlapping IP address ranges between the Transit VPC and the User VPC. Here's a detailed breakdown:
* Understanding ERPs (Elastic Routing Prefixes):
* The ERP for the Transit VPC is 10.1.1.0/25, which covers IP addresses from 10.1.1.0 to
10.1.1.127.
* The ERP for the User VPC is 10.1.1.0/24, which covers IP addresses from 10.1.1.0 to 10.1.1.255.
* IP Address Overlap:
* Since 10.1.1.0/25 is a subset of 10.1.1.0/24, there is a significant overlap in the IP address ranges of these two ERPs.
* This overlap can cause routing issues because the same IP address range is being used in both VPCs, leading to ambiguity in routing and communication.
* Communication Issue:
* When a VM in the User VPC tries to communicate with other resources, the network cannot accurately determine the correct route due to the overlapping IP address ranges.
* This overlap prevents proper routing and results in the VM being unable to communicate with other resources as intended.
* Resolution:
* To resolve this issue, the ERPs must be in different CIDR ranges. This means the IP address ranges for the Transit VPC and the User VPC should not overlap.
* For example, if the Transit VPC uses 10.1.1.0/25, the User VPC could use a different range such as 10.1.2.0/24 or any other range that does not overlap with 10.1.1.0/25.
By ensuring that the ERPs are in different CIDR ranges, the network can properly route traffic between the VPCs without any conflicts or ambiguities, thereby enabling the VM in the User VPC to communicate with other resources effectively.


NEW QUESTION # 22
Which address must Azure Directory Service be able to resolve when deploying a new NC2 cluster?

  • A. Download.cloud.nutanix.com
  • B. Gateway-internal-api-cloud.nutanix.com
  • C. Apikeys.nutanix.com
  • D. Gateway-external-api.cloud.nutanix.com

Answer: D

Explanation:
* Azure Directory Service Role: Azure Directory Service must be able to resolve specific Nutanix URLs to ensure proper communication and functionality during the deployment of an NC2 cluster.
* Critical Endpoint: The address "Gateway-external-api.cloud.nutanix.com" is critical for establishing external API communications required for the deployment and management of the NC2 cluster.
* DNS Resolution: Proper DNS resolution of this address ensures that the Azure Directory Service can interact with Nutanix services and APIs necessary for cluster operations.
* Verification Process:
* Ensure that DNS settings allow resolution of "Gateway-external-api.cloud.nutanix.com".
* Test connectivity and resolution prior to deployment to avoid issues.
* Importance: Without resolving this address, the deployment process might face connectivity issues, leading to potential deployment failures.
References:
* Nutanix NC2 on Azure Setup Guide
* Azure Active Directory Integration


NEW QUESTION # 23
An administrator ran into an issue during an NC2 cluster deployment on Azure. The administrator has logged a case with Nutanix Support.
Support has requested the following logs from NC2 on Azure in order to diagnose the deployment issue:
* Cluster_agent
* Host_agent
* Hostsetup
What action should the administrator take to ensure the collect the appropriate logs?

  • A. SSH to the PCVM and use the logbay collect command.
  • B. Login to Prism Element to access the CVM's console and run the logbay collect command.
  • C. SSH to the CVM and use the logbay collect command.
  • D. Login to Prism Element Web Console to generate a Logbay bundle.

Answer: B

Explanation:
To collect the appropriate logs (Cluster_agent, Host_agent, and Hostsetup) for diagnosing the deployment issue with Nutanix Support, the administrator should:
* Log in to Prism Element to access the Controller VM (CVM) console.
* Run thelogbay collectcommand from the CVM console. This command collects the necessary logs and packages them for support.
This method ensures that the correct logs are gathered in a format that Nutanix Support can analyze.
References
* Nutanix Support Documentation on Log Collection


NEW QUESTION # 24
Native Azure VMs exist in a subnet (10.20.80.0/20) in the Prism Central VNet that need access to the workload running on the Nutanix User.
What needs to be modified to allow access from the native Azure VMs to the workloads running in the Nutanix User VPC?

  • A. Adjust the Inbound Network Security Group on the Flow Gateway VM Internal NIC to allow traffic
    102030,0/20.
  • B. Remove the ERP value on the transit VPC and Nutanix User VPC.
  • C. Adjust the Inbound Network Security Group on the Flow Gateway VM External NIC to allow traffic
    102030.0/20.
  • D. Change the ERP value to the the subnet range of the native Azure VMs (10.20.80.0/20) on the Transit VPC and the Nutanix User VPC.

Answer: A

Explanation:
To allow access from the native Azure VMs to the workloads running in the Nutanix User VPC, the administrator needs to:
* Adjust the Inbound Network Security Group (NSG) on the Flow Gateway VM's Internal NIC.
* Specifically, allow traffic from the subnet range of the native Azure VMs (10.20.80.0/20) in the Inbound rules of the NSG associated with the Internal NIC of the Flow Gateway VM.
This configuration change permits the desired network traffic, ensuring that the native Azure VMs can communicate with the workloads in the Nutanix User VPC.References
* Azure Network Security Groups Overview
* Nutanix Networking and Security Best Practices


NEW QUESTION # 25
After creating a new Nutanix User VPC, what is needed to allow traffic to flow out of the Flow gateway VM when using the NATed Path?

  • A. Add a default route on the Transit VPC of 0.0.0.0/0 to the Flow Gateway.
  • B. Add a default route on the Transit VPC of 0.0.0.0/0 to the Flow Gateway.
  • C. Edit the External Flow Gateway Security Group on the External NIC to allow outbound traffic.
  • D. Edit the Internal Flow Gateway Security Group on the internal NIC to allow outbound taffic
  • E. Add a default route on the Nutanix User VPC of 0.0.0.0/0 to the External Overlay network.

Answer: E


NEW QUESTION # 26
An administrator must ensure that certain NC2 VMs can access Azure resources. The NC2 VM traffic must not traverse the internet.
How would the administrator achieve this?

  • A. By creating an Azure Private Endpoint for VMs in the host-mgmt subnet.
  • B. By creating an Azure Private Endpoint for VMs in a Delegated Subnet
  • C. By creating an Azure Private Endpoint for VMs in a NAT network via vWAN.
  • D. By creating an Azure Private Endpoint for VMs in a No-NAT network via vWAN.

Answer: B

Explanation:
* Azure Private Endpoint:A Private Endpoint provides secure connectivity to Azure resources by enabling private access through the Azure backbone network. This ensures that the traffic does not traverse the internet, providing enhanced security and performance.
* Delegated Subnet:By creating an Azure Private Endpoint for VMs in a delegated subnet, the administrator ensures that the VMs can access Azure resources directly and securely without using the public internet.
References:
* Azure Private Endpoint Documentation
* Nutanix NC2 Networking Configuration Guide


NEW QUESTION # 27
Exhibit.

An administrator is trying to create an NC2 cluster in Azure, but does not see the required region in the drop-down list.
Which two steps could the administrator take to resolve this issue? (Choose two.)

  • A. Check the list of regions specified under the NC2 organization cloud account.
  • B. Ensure that the Azure region is whitelisted for use by Microsoft in the subscription.
  • C. Check the Azure subscription is created in the correct region.
  • D. Check the NC2 Billingconsole to ensure the region is listed.

Answer: A,B

Explanation:
* Check the list of regions specified under the NC2 organization cloud account:The list of available regions in the NC2 console might be restricted based on the configuration of the cloud account associated with the NC2 organization. Verifying this list ensures that the desired region is included and available for cluster creation.
* Ensure that the Azure region is whitelisted for use by Microsoft in the subscription:Sometimes, specific regions need to be explicitly enabled or whitelisted in the Azure subscription for certain services. This step ensures that the required region is permitted for use within the Azure subscription, allowing the NC2 cluster to be created in that region.
References:
* Azure Subscription and Service Limits Documentation
* Nutanix NC2 Configuration and Setup Guide


NEW QUESTION # 28
An administrator is tasked with providing User VMs in Azure that are hosted within a Flow NAT network outbound internet connectivity.
In which order would the traffic flow through each component?

  • A. User VM >Floating IP Address > Flow Gateway > Azure LB
  • B. User VM > Delegated Subnet > Flow Gateway > Floating IP Address > Azure LB
  • C. User VM >Flow Gateway > Floating IP Address > Azure NAT GW
  • D. User VM > Delegated Subnet > Flow Gateway > Floating IP Address > Azure NAT GW

Answer: D

Explanation:
* User VM:The initial source of the traffic within the Azure environment.
* Delegated Subnet:Traffic from the User VM flows through the delegated subnet, which is configured to handle specific network traffic.
* Flow Gateway:The Flow Gateway manages and routes the traffic from the delegated subnet, providing network services and connectivity.
* Floating IP Address:The Flow Gateway assigns a floating IP address for the outbound traffic, facilitating NAT operations.
* Azure NAT Gateway:The traffic is then routed through the Azure NAT Gateway, which provides outbound internet connectivity for the User VMs, ensuring secure and efficient routing.
References:
* Azure Virtual Network NAT Documentation
* Nutanix NC2 Configuration Guide


NEW QUESTION # 29
An administrator just completed the initial account setup tasks for NC2 on Azure, such as creating a My Nutanix account, starting a 30-day free trial for NC2 on Azure, and setting up the Azure account and subscription.
Which two additional actions should the administrator take before creating a cluster? (Choose two.)

  • A. Creating an App Registration
  • B. Purchasing an Azure savings plan
  • C. Allowlisting the Azure Subscription
  • D. Configure VPN for connectivity

Answer: A,C

Explanation:
* Allowlisting the Azure Subscription:This step ensures that the Azure subscription is recognized and permitted by Nutanix Cloud Clusters (NC2). Without allowlisting, the necessary resources and permissions within the Azure subscription may not be available for NC2, potentially blocking the creation and management of clusters.
* Creating an App Registration:This involves setting up an application within Azure Active Directory (AAD) to enable secure communication between NC2 andAzure. The app registration process includes assigning permissions and obtaining necessary authentication credentials, facilitating the interaction and management of Azure resources by NC2.
References:
* Nutanix Documentation on NC2 Setup
* Azure Active Directory Application Registration Guide


NEW QUESTION # 30
An NC2 on Azure environment requires that outside networks are allowed to be routed to a Nutanix User VPC from outside the cluster when using a No-Nat path.
Which configuration will satisfy this requirement?

  • A. Externally routable IP address which shares the same address space of the Native Azure Subnet
  • B. Internally routable network address which shares the sameaddress space of the Nutanix setVPC
  • C. Internally routable network address which shares the same address space of the Native Azure Subnet
  • D. Externally routable IP address which shares the same address space of the Nutanix User VPC

Answer: D

Explanation:
* No-NAT Path Requirement:For a No-NAT path to function, the external networks must be able to route traffic directly to the Nutanix User VPC without translation.
* Externally Routable IP Address:The externally routable IP address ensures that traffic from outside networks can reach the Nutanix User VPC.
* Address Space Compatibility:Sharing the same address space as the Nutanix User VPC allows for seamless integration and communication between the external network and the User VPC.
References:
* Azure Virtual Network Documentation on IP Addressing
* Nutanix NC2 Configuration Guide on No-NAT Networking


NEW QUESTION # 31
A company wants to start using Nutanix Cloud Clusters (NC2) in Azure. The company has large spend commitments as part of a Microsoft Azure Consumption Commitment (MACC) totaling $15 million.
What approach should the administrator take to ensure the Nutanix licensing costs apply to the MACC?

  • A. Leverage existing Nutanix licenses
  • B. Purchase Nutanix licenses directly from Nutanix and contact Microsoft support.
  • C. Purchase Nutanix licenses through the Azure Marketplace.
  • D. Request a trial directly from Nutanix.

Answer: C


NEW QUESTION # 32
......

Pass Your Next NCP-CI-Azure Certification Exam Easily & Hassle Free: https://actualtests.passsureexam.com/NCP-CI-Azure-pass4sure-exam-dumps.html