100% Reliable NCP-CI-AWS Exam Dumps Test Pdf Exam Material [Q43-Q65]

Share

100% Reliable Microsoft NCP-CI-AWS Exam Dumps Test Pdf Exam Material

Based on Official Syllabus Topics of Actual Nutanix NCP-CI-AWS Exam


Nutanix NCP-CI-AWS Exam Syllabus Topics:

TopicDetails
Topic 1
  • Deploying an NC2 on AWS Environment: This portion assesses your knowledge of cloud cluster deployment, cloud provider network configuration, and your skills in addressing cluster deployment challenges.
Topic 2
  • Managing an NC2 on AWS Environment: This exam component tests your understanding of node and cluster management tasks, along with your ability to oversee cluster and cloud resource health.
Topic 3
  • Configuring an NC2 on AWS Environment: This section examines your proficiency in setting up cloud networking and security measures, as well as addressing connectivity issues.
Topic 4
  • Prepare the AWS cloud environment: This exam segment evaluates your ability to set up the AWS cloud environment, initiate NC2 service subscription, establish implementation criteria, and recognize networking prerequisites.

 

NEW QUESTION # 43
An administrator is deploying a new cluster on AWS and would like to ensure the data is encrypted. Due to cost constraints, the deployment will leverage the native local key manager (LKM).
What is the minimal number of nodes needed to support the Nutanix native LKM?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: C

Explanation:
To support Nutanix's native Local Key Manager (LKM) for data encryption in a cost-effective manner, a minimum of three nodes is required. This ensures that there is enough redundancy and reliability for the encryption services to function properly, complying with best practices for distributed key management.
Reference:
Nutanix Support & Insights
Nutanix Cloud Clusters on AWS Administration


NEW QUESTION # 44
An organization wants to control network traffic at the individual User VM (UVM) subnet level.
Which action will help achieve this goal?

  • A. Modify the internal management security group.
  • B. Create a custom security group.
  • C. Modify the default UVM security group.
  • D. Modify the user management security group.

Answer: B

Explanation:
To control network traffic at the individual User VM (UVM) subnet level, creating a custom security group is the appropriate action. This approach allows for fine-grained control over inbound and outbound traffic rules that can be applied to specific subnets or individual instances within those subnets.
Custom Security Group:
Custom security groups enable administrators to define specific traffic rules tailored to the needs of individual subnets or VMs. This includes specifying allowed IP ranges, ports, and protocols.
By applying these custom security groups to the UVMs, the organization can control access and enhance security according to their policies and requirements.
Steps to Create a Custom Security Group:
Navigate to the AWS Management Console and go to the VPC service.
Select "Security Groups" under the "Security" section.
Click on "Create Security Group" and define the name, description, and VPC.
Add inbound and outbound rules according to the desired traffic control policies.
Attach the custom security group to the UVMs or subnets in question.
Reference:
Nutanix Cloud Clusters on AWS Administration Guide
AWS Security Group Documentation
Nutanix Best Practices for Security Groups


NEW QUESTION # 45
Which entity should be contacted for cloud hardware supported (EC2 instances, VPC, etc) related to NC2?

  • A. Internal IT Operations team
  • B. Public Cloud Vendor
  • C. Nutanix
  • D. Partner

Answer: B

Explanation:
For issues related to cloud hardware support such as EC2 instances, VPC, etc., the public cloud vendor (AWS in this case) should be contacted. AWS provides support and documentation for their infrastructure and services, ensuring that users can get assistance for any hardware or cloud-specific queries.
Reference:
Nutanix Support & Insights


NEW QUESTION # 46
The cluster is configured as follows:
* 8 nodes
* Prism Central Deployed
* Files Deployed
Following the deployment, the administrator experiences network connectivity issues.
Which reason explains the connectivity issues?

  • A. The 192.168.5.0/24 range is reserved for internal cluster usage.
  • B. The 192.168.5.0/24 range does not have enough IP addresses available.
  • C. The 192.168.5.0/24 range is reserved by IANA,
  • D. The 192.168.5.0/24 range is not a valid CIDR range.

Answer: A

Explanation:
The 192.168.5.0/24 range is often reserved for internal cluster communication within Nutanix deployments.
Using this CIDR range for other purposes could lead to network conflicts and connectivity issues, as it might interfere with the internal operations and communication channels of the Nutanix cluster.
Ensuring that the CIDR range is not overlapping with any reserved ranges is crucial for maintaining proper network connectivity and cluster functionality.
Reference:
Refer to the Nutanix documentation on network configuration and best practices for NC2 deployments to confirm reserved IP ranges and their appropriate use.


NEW QUESTION # 47
An administrator is deploying an NC2 cluster into an existing AWS VPC.
The cluster deployment fails, with the following error message:

Why has the deployment failed?

  • A. The administrator has not configured the Security Group to manage the shared subnet.
  • B. Outbound Internet access is not configured on the VPC.
  • C. Shared subnets are not supported for Nutanix clusters.
  • D. The administrator has not created the necessary Security Group.

Answer: D

Explanation:
The administrator has not created the necessary Security Group:
The error message indicates that the creation of network interfaces in a shared subnet requires specifying a security group. This means that the necessary security group has not been created or assigned to the network interfaces.
Creating the appropriate security group and ensuring it is associated with the network interfaces during cluster deployment should resolve this issue.
Reference:
Refer to AWS documentation on security groups and network interface configuration and Nutanix documentation on prerequisites for deploying NC2 clusters in an existing AWS VPC.


NEW QUESTION # 48
When creating an NC2 cluster in AWS, what are the required permissions for the account used to run the CloudFormation script?

  • A. lAMUserSSHKeys, AWS_ConfigRole, AWSCIoudFormationFullAccess
  • B. lAMFullAccess, AmazonEC2FullAccess, AWSCIoudFormationFullAccess
  • C. lAMAccess, AWS_ConfigRole, AWSCIoudFormationFullAccess
  • D. IAMAccess, AmazonCloudDirectoryFullAccess, AWSCIoudFormationFullAccess

Answer: B

Explanation:
When creating an NC2 cluster in AWS, the account used to run the CloudFormation script requires specific permissions to ensure the deployment is successful. The required permissions are:
IAMFullAccess: Provides full access to IAM resources.
AmazonEC2FullAccess: Allows full access to EC2 resources.
AWSCIoudFormationFullAccess: Grants full access to manage AWS CloudFormation stacks.
These permissions are necessary to create, manage, and deploy the required AWS resources for the NC2 cluster.
Reference:
Nutanix Support & Insights
AWS IAM Documentation


NEW QUESTION # 49
Exhibit.

An administrator is attempting, but failing to create an NC2 cluster in AWS. The administrator checks the configuration in the NC and notices the configuration shown in the exhibit.
What action should the administrator take to resolve the issue?

  • A. Recreate the AWS CloudFormation stack.
  • B. Create a new cloud account in the organization.
  • C. Restart Genesis on a Prism Central instance.
  • D. Grant the administrator's account access to the NC2 organization.

Answer: B

Explanation:
The exhibit shows two cloud accounts, one for Azure and one for AWS, with their statuses indicated. The AWS cloud account status is marked as "U" (which likely stands for "Unavailable" or "Unreachable"). This indicates that the AWS cloud account configuration is not properly connected or accessible.
Status Check:
The AWS cloud account is marked with an "U" status, meaning it is not active or accessible.
This status prevents the creation of an NC2 cluster because the necessary cloud resources cannot be allocated or managed without a proper connection.
Action:
The best course of action is to create a new cloud account in the organization. This involves setting up the cloud account details correctly and ensuring it is properly configured to communicate with Nutanix and AWS.
Steps to Create a New Cloud Account:
Log in to the Nutanix console.
Navigate to the "Organizations" section.
Select "Add Cloud Account" and provide the required AWS credentials and permissions.
Ensure the new cloud account is active and correctly configured.
Reference:
Nutanix Cloud Clusters on AWS Administration Guide
Nutanix Best Practices for Cloud Account Management


NEW QUESTION # 50
Which interface must be used to deploy NC2?

  • A. Prism Central Dashboard
  • B. Foundation running in a Cloud Virtual Machine
  • C. NC2 Tile within the my.nutanix.com portal
  • D. Cloud Provider portal

Answer: C

Explanation:
The NC2 Tile within the my.nutanix.com portal is the correct interface to deploy NC2. This portal provides an integrated and user-friendly interface specifically designed for deploying and managing Nutanix Clusters on AWS.
NC2 Deployment Interface:
NC2 Tile within the my.nutanix.com portal: This portal provides the necessary tools and options to deploy and manage NC2 clusters. It includes functionalities for setting up the clusters, configuring network settings, and managing resources.
Advantages:
User-Friendly Interface: Simplifies the deployment process with a guided setup.
Integrated Tools: Provides access to all necessary tools for managing the deployment and monitoring of NC2 clusters.
Reference:
Nutanix Cloud Clusters on AWS Administration Guide
Nutanix my.nutanix.com Portal Documentation
Nutanix Best Practices for Cluster Deployment


NEW QUESTION # 51
An administrator wants to route the outbound and inbound traffic from the NC2 cluster through a proxy server. Which two statements are correct about using a proxy server? (Choose two.)

  • A. The proxy server must be configured only while creating a cluster because the proxy server settings cannot be configured after the cluster is deployed.
  • B. The proxy configuration can be changed while tasks for adding or removing nodes are in progress.
  • C. NC2 clusters using Flow Virtual Networking do not support a proxy server.
  • D. A proxy server is only supported with AOS 6.7.1.6 or higher versions and only with user-created VPCs.

Answer: C,D


NEW QUESTION # 52
An administrator is creating and destroying multiple clusters daily for a test/dev environment. The administrator wants ensure that every NC2 on AWS cluster deployed will allow full access from the on-premises CVM subnet.
What is most-efficient way to achive this?

  • A. Modify the UVM Network Security Group of each cluster by setting the inbound allow address of the on-premises subnet.
  • B. Modify the UVM Network Security Group of each cluster by setting the outbound allow address of the on-premises subnet.
  • C. Create a Custom AWS Network Security Group using a key value of tag:nutanix:clusters:external and set the inbound allow address of the on-premises subnet.

Answer: C

Explanation:
D/ Create a Custom AWS Network Security Group using a key of tag:nutanix: clusters:external:cluster-uuid and set the value of the UUID for each deployed cluster. Set the inbound allow address of the on-premises subnet.
To ensure that every NC2 on AWS cluster deployed allows full access from the on-premises CVM subnet efficiently, the administrator should create a custom AWS Network Security Group.
Use a key value of tag:nutanix:clusters:external for the security group, and set the inbound allow address to the on-premises subnet.
This approach leverages AWS tags to manage security group rules dynamically and ensures that the necessary access permissions are applied automatically to all clusters with the specified tag.
This method reduces the need for manual configuration of each cluster's security group, streamlining the process for a test/dev environment where clusters are frequently created and destroyed.
Reference:
Refer to the AWS documentation on Network Security Groups and Nutanix documentation on best practices for securing NC2 clusters.


NEW QUESTION # 53
An administrator has deployed NC2 on AWS. The cluster deployment completed successfully.
After deployment, the administrator created a subnet in AWS, added it as a network in Prism Element, deployed Prism Central using the newly-configured network, and registered the cloud cluster with it.
The on-premises network and AWS are connected via a Site-to-Site VPN. Cluster nodes, CVM, and Prism Central can communicate with each other, but cannot be accessed from the on-premises network.
What two issues might be the cause of this problem? (Choose two.)

  • A. Traffic from the on-premises network is not permitted by VM and Management security groups.
  • B. The AWS VPC traffic is blocked by a firewall in the on-premises network.
  • C. The AHV firewall is blocking traffic from the on-premises network.
  • D. AWS Direct Connect must be used to establish connection between AWS and on-premises

Answer: A,B

Explanation:
Traffic from the on-premises network is not permitted by VM and Management security groups:
Ensure that the security groups assigned to the VMs and management interfaces in AWS allow inbound traffic from the on-premises network. Without appropriate security group rules, the traffic will be blocked.
The AWS VPC traffic is blocked by a firewall in the on-premises network:
Check if the firewall on the on-premises network is configured to allow traffic from the AWS VPC. Firewalls may have restrictive rules that block incoming traffic, preventing communication.
Reference:
Refer to AWS documentation on security groups and firewalls and Nutanix documentation on configuring networking for NC2 clusters.


NEW QUESTION # 54
An administrator needs to recover a cluster protected using the Cluster Protect feature. The Prism Central instance was not on the failed cluster.
Which steps, in order, should the administrator perform to recover the cluster?

Answer:

Explanation:

Reference:
Nutanix Documentation on Cluster Protect and Recovery Processes
Nutanix Support & Insights
Nutanix Cloud Clusters on AWS Administration


NEW QUESTION # 55
An administrator needs the permissions to create and manage multiple organizations and clusters in NC2, as well as manage user access for the entire company.
What role should be assigned to meet the minimum requirements of this task?

  • A. Organization Administrator
  • B. Customer Administrator
  • C. Cluster Administrator
  • D. Customer Security Administrator

Answer: B

Explanation:
The role of "Customer Administrator" in Nutanix Cloud Integration with AWS (NC2) is designed to meet the requirements of creating and managing multiple organizations and clusters, as well as managing user access for the entire company.
Roles and Permissions:
Customer Administrator: This role has the broadest set of permissions, allowing the user to create and manage organizations, clusters, and user access across the entire company. It encompasses administrative control over multiple aspects of the NC2 environment.
Capabilities:
Organization Management: Ability to create and manage multiple organizations.
Cluster Management: Full control over creating, configuring, and managing clusters.
User Access Management: Manage user roles and permissions, ensuring that the right individuals have access to the necessary resources.
Why Not Other Roles:
Organization Administrator: Limited to managing organizations but not clusters and user access at the company level.
Customer Security Administrator: Focuses on security aspects, lacking broader administrative capabilities.
Cluster Administrator: Limited to managing clusters without the ability to manage organizations and user access comprehensively.
Reference:
Nutanix Cloud Clusters on AWS Administration Guide
Nutanix Role-Based Access Control Documentation


NEW QUESTION # 56
When configuring an alert email in Prism Central deployed within an NC2 environment, what is required in order for the emails to be sent properly?

  • A. A whitelisted public cloud console endpoint
  • B. SMTP server configured in Prism Central settings
  • C. Cluster Super Admin permissions
  • D. Name servers configured in Prism Central

Answer: B

Explanation:
To ensure that alert emails are sent properly from Prism Central within an NC2 environment, configuring an SMTP server in the Prism Central settings is required. The SMTP server facilitates the sending of email notifications for alerts and other communications.
SMTP Configuration:
Prism Central requires an SMTP server to send email alerts. This involves specifying the SMTP server address, port, and authentication details if needed.
The configuration must include the email address from which the alerts will be sent and the recipient addresses.
Steps to Configure SMTP Server in Prism Central:
Log in to Prism Central.
Navigate to the "Settings" menu.
Select "Email Server" under the "Alerts" section.
Enter the SMTP server details, including the server address, port, and authentication credentials.
Test the configuration to ensure emails are sent correctly.
Reference:
Nutanix Prism Central Administration Guide
Nutanix Support Documentation on Email Alert Configuration
Best Practices for Configuring SMTP Servers in Cloud Environments


NEW QUESTION # 57
What role is needed to create a cluster?

  • A. Customer Administrator
  • B. Cluster Super Admin
  • C. Cluster Administrator
  • D. Customer Security Administrator

Answer: B

Explanation:
To create a cluster in Nutanix Cloud Integration with AWS, the role needed is Cluster Super Admin.
The Cluster Super Admin role provides the highest level of privileges required to perform critical operations such as creating, managing, and deleting clusters.
This role is essential for overseeing the cluster setup and configuration processes, ensuring the user has full control over the cluster lifecycle.
Reference:
Refer to the Nutanix documentation on roles and permissions for NC2 on AWS for further details on the capabilities and required permissions for cluster creation.


NEW QUESTION # 58
An administrator is planning an NC2 deployment and wants to connect to AWS Services privately from the corporate VPC without going through the public internet.
Which connectivity solution should the administrator use?

  • A. Gateway Endpoint
  • B. Point-to-Site VPN
  • C. VTEP Gateways
  • D. Site-to-Site VPN

Answer: A

Explanation:
Gateway Endpoint:
A Gateway Endpoint in AWS allows you to connect to supported AWS services privately without going through the public internet. This setup provides secure and efficient connectivity directly from the corporate VPC to the required AWS services.
Gateway Endpoints support services such as Amazon S3 and DynamoDB and are ideal for scenarios where private connectivity to these services is needed.
Reference:
Refer to the AWS documentation on VPC endpoints, specifically Gateway Endpoints, and the Nutanix documentation on configuring private connectivity for NC2 deployments.


NEW QUESTION # 59
An administrator is tasked with providing VMs outbound internet connectivity in AWS.
Which components would the administrator need to create in the VPC to achieve this?

  • A. Public Subnet NAT Gateway, Public EIP, Route Table
  • B. Private Subnet NAT Gateway, Public EIP, Route Table
  • C. Public Subnet Flow Gateway, Public EIP, Route Table
  • D. Private Subnet Flow Gateway, Public EIP, Route Table

Answer: B

Explanation:
To provide VMs with outbound internet connectivity in AWS using a private subnet, the administrator needs to create the following components in the VPC:
Private Subnet: A private subnet is required to house the VMs that need outbound internet access but do not require direct inbound access from the internet.
NAT Gateway: A NAT (Network Address Translation) Gateway is necessary to allow instances in the private subnet to connect to the internet or other AWS services while preventing the internet from initiating a connection with those instances.
Public EIP (Elastic IP Address): An EIP is associated with the NAT Gateway to provide a persistent public IP address that allows outbound internet traffic from the private subnet to be routed correctly.
Route Table: A route table is configured to route traffic from the private subnet to the NAT Gateway for outbound internet access.
Reference:
AWS NAT Gateway Documentation
AWS VPC Subnet Basics


NEW QUESTION # 60
Which two statements are the most accurate regarding Cluster Protect? (Choose two.)

  • A. The dusters that are to be protected must be registered with the same instance of Prism Central.
  • B. The Cluster Protect feature requires AOS version 6.7 or higher.
  • C. An AWS subnet can be shared by VMs, Prism Central, and Multicloud Snapshort Technology (MST).
  • D. Nutanix Guest Tools (NGT) is not required to be installed on User VMs.

Answer: A,B

Explanation:
The clusters that are to be protected must be registered with the same instance of Prism Central (Answer C):
For Cluster Protect to function correctly, all clusters intended for protection must be registered under the same Prism Central instance. This ensures consistent management and coordination of protection policies and operations across clusters.
The Cluster Protect feature requires AOS version 6.7 or higher (Answer D):
Cluster Protect is a feature that is available starting from AOS version 6.7. To utilize this feature, ensure that the Nutanix clusters are running this version or a newer one.
Reference:
Nutanix Cluster Protection Documentation
Nutanix AOS Release Notes


NEW QUESTION # 61
An administrator is tasked with deploying a VM in an NC2 cluster on AWS that needs to by accessed by resources within the on-premises datacenter.
The cluster has the following characteristics:
* 8 nodes
* Resides in the us-east-1a Availability Zone
* Contains 13 Subnets
* Has access to a Direct Connect connection
* Subnet that the User VM (UVM) is being deployed to:UserVM_subnet
There are multiple VMs within the cluster and the UserVM_subnet has access to the on-premises resources.
The administrator deploys the machine, but communication is not possible.
What is the most likely resolution for this situation?

  • A. The AWS UVM Security Group requires the new application's ports adding to inbound traffic.
  • B. The AWS IGW requires the new application's ports adding to inbound traffic.
  • C. The AWS Internal Management Security Group requires the new application's ports adding to outbound traffic.
  • D. The AWS User Management Security Group requires the new application's ports adding to and traffic

Answer: A

Explanation:
For a VM deployed in an NC2 cluster on AWS to be accessed by resources within the on-premises datacenter, the security group associated with the User VM (UVM) subnet must allow inbound traffic on the specific ports required by the application.
If the security group rules do not permit inbound traffic on these ports, the communication will fail, even if other network configurations are correct.
The administrator should ensure that the UVM Security Group includes rules to allow inbound traffic for the application's required ports, facilitating proper communication between the VM and on-premises resources.
Reference:
Refer to the AWS documentation on security group configurations and Nutanix NC2 documentation for details on configuring network access and security group rules.


NEW QUESTION # 62
In which two ways should an NC2 on AWS cluster be hibernated manually? (Choose two.)

  • A. Log into Prism Element navigate to Settings and select Hibernate/Resume.
  • B. Log into Prism, Central, navigate to Planning, find hibernate and resume.
  • C. Log into NC2 console, find the cluster name and select Hibernate/Resume from the ellipses.
  • D. Select the cluster under NC2 console and Select Hibernate/Resume on the cluster sur page.

Answer: C,D

Explanation:
To manually hibernate an NC2 on AWS cluster, the administrator can use the following methods:
Select the cluster under NC2 console and Select Hibernate/Resume on the cluster sur page: Navigate to the specific cluster in the NC2 console and use the provided Hibernate/Resume option.
Log into NC2 console, find the cluster name and select Hibernate/Resume from the ellipses: Access the NC2 console, locate the cluster name, and select the Hibernate/Resume option from the ellipses (three dots) menu.
These options allow for the manual control of the cluster's hibernation state directly within the NC2 console interface.
Reference:
Nutanix Cloud Clusters on AWS Administration
Nutanix Support & Insights


NEW QUESTION # 63
An administrator is planning an NC2 deployment and wants to connect to AWS Services privately from the corporate VPC without going through the public internet.
Which connectivity solution should the administrator use?

  • A. Gateway Endpoint
  • B. Point-to-Site VPN
  • C. VTEP Gateways
  • D. Site-to-Site VPN

Answer: A


NEW QUESTION # 64
A company has just adopted Nutanix as their technology of choice and is preparing to deploy Nutanix Cloud Clusters (NC2).
Which step must be taken first to again access to the CN2 console?

  • A. Open a support case with Nutanix.
  • B. Create a My Nutanix account
  • C. Navigate to cloud.nutanix.com
  • D. Start a free trial via Billing Portal.

Answer: B

Explanation:
Before accessing the Nutanix Cloud Clusters (NC2) console, the first step is to create a My Nutanix account.
This account serves as the primary gateway for managing and accessing Nutanix services, including NC2.
Once the account is created, users can log in to the Nutanix portal, where they can manage their subscriptions, start trials, and access various Nutanix services, including the NC2 console.
Reference:
Refer to the Nutanix documentation on getting started with NC2 and the My Nutanix account creation process.


NEW QUESTION # 65
......

Free NCP-CI-AWS Dumps are Available for Instant Access: https://www.test4engine.com/NCP-CI-AWS_exam-latest-braindumps.html

View All NCP-CI-AWS Actual Exam Questions Answers and Explanations for Free: https://drive.google.com/open?id=1GPgycTtMG6Bq_vl_aFHfaSuzuObEmPIV