Nutanix NCP-CI-AWS Practice Exams
Last updated on Oct 06,2026- Exam Code: NCP-CI-AWS
- Exam Name: Nutanix Certified Professional - Cloud Integration - AWS v6.7
- Certification Provider: Nutanix
- Latest update: Oct 06,2026
A company has just adopted Nutanix as their technology of choice and is preparing to deploy Nutanix Cloud Clusters (NC2).
Which step must be taken first to again access to the CN2 console?
- A . Navigate to cloud.nutanix.com
- B . Start a free trial via Billing Portal.
- C . Open a support case with Nutanix.
- D . Create a My Nutanix account
D
Explanation:
Before accessing the Nutanix Cloud Clusters (NC2) console, the first step is to create a My Nutanix account.
This account serves as the primary gateway for managing and accessing Nutanix services, including NC2.
Once the account is created, users can log in to the Nutanix portal, where they can manage their subscriptions, start trials, and access various Nutanix services, including the NC2 console.
Reference: Refer to the Nutanix documentation on getting started with NC2 and the My Nutanix account creation process.
Exhibit.
![]()
What does the exhibit indicate?
- A . No ongoing replication
- B . Ongoing replication
- C . Replication in paused state
- D . Replication in error state
A
Explanation:
The exhibit indicates a replication operation with specific details about the protection domain, remote site, and snapshot.
Key points to note are:
Bytes Completed: 0 bytes completed.
Complete Percent: 0.0%
Paused: false
Aborted: false
Given these details:
No ongoing replication: The operation has started, but there is no progress in terms of bytes completed or percentage completed. Since the status shows 0 bytes and 0 percent completed, it indicates that no data has been replicated yet.
Reference: Nutanix Protection Domain and Replication Documentation Nutanix Best Practices for Monitoring Replication
Which statement is true regarding AWS account requirements?
- A . IAMFullAccess permission gets configuration details for supported AWS resources.
- B . AWSCloudFormationFullAccess role is required to create a CloudFormation stack.
- C . An AWS root user can be used for any deployment or operations related to NC2.
- D . NC2 on AWS uses AWS Secrets Manager for maintaining any stored secrets.
B
Explanation:
To create a CloudFormation stack, the AWSCloudFormationFullAccess role is required.
This role grants the necessary permissions to create, update, and delete CloudFormation stacks, which are essential for deploying and managing AWS infrastructure using CloudFormation templates. CloudFormation stacks are often used to automate the deployment of complex infrastructures, including those required for NC2 on AWS.
Proper permissions ensure that the deployment process is seamless and adheres to the security and operational policies of the organization.
Reference: Refer to the AWS IAM documentation for details on the AWSCloudFormationFullAccess role and Nutanix documentation on prerequisites for deploying NC2 on AWS.
Which interface must be used to deploy NC2?
- A . Cloud Provider portal
- B . NC2 Tile within the my.nutanix.com portal
- C . Prism Central Dashboard
- D . Foundation running in a Cloud Virtual Machine
B
Explanation:
The NC2 Tile within the my.nutanix.com portal is the correct interface to deploy NC2. This portal provides an integrated and user-friendly interface specifically designed for deploying and managing Nutanix Clusters on AWS.
NC2 Deployment Interface:
NC2 Tile within the my.nutanix.com portal: This portal provides the necessary tools and options to deploy and manage NC2 clusters. It includes functionalities for setting up the clusters, configuring network settings, and managing resources.
Advantages:
User-Friendly Interface: Simplifies the deployment process with a guided setup.
Integrated Tools: Provides access to all necessary tools for managing the deployment and monitoring of NC2 clusters.
Reference: Nutanix Cloud Clusters on AWS Administration Guide
Nutanix my.nutanix.com Portal Documentation
Nutanix Best Practices for Cluster Deployment
An administrator is creating and destroying multiple clusters daily for a test/dev environment. The administrator wants ensure that every NC2 on AWS cluster deployed will allow full access from the on-premises CVM subnet.
What is most-efficient way to achive this?
- A . Modify the UVM Network Security Group of each cluster by setting the inbound allow address of the on-premises subnet.
- B . Modify the UVM Network Security Group of each cluster by setting the outbound allow address of the on-premises subnet.
- C . Create a Custom AWS Network Security Group using a key value of tag:nutanix:clusters:external and set the inbound allow address of the on-premises subnet.
- D . Create a Custom AWS Network Security Group using a key of tag:nutanix: clusters:external:cluster-uuid and set the value of the UUID for each deployed cluster. Set the inbound allow address of the on-premises subnet.
C
Explanation:
To ensure that every NC2 on AWS cluster deployed allows full access from the on-premises CVM subnet efficiently, the administrator should create a custom AWS Network Security Group.
Use a key value of tag:nutanix:clusters:external for the security group, and set the inbound allow address to the on-premises subnet.
This approach leverages AWS tags to manage security group rules dynamically and ensures that the necessary access permissions are applied automatically to all clusters with the specified tag.
This method reduces the need for manual configuration of each cluster’s security group, streamlining the process for a test/dev environment where clusters are frequently created and destroyed.
Reference: Refer to the AWS documentation on Network Security Groups and Nutanix documentation on best practices for securing NC2 clusters.
An administrator is tasked with providing VMs outbound internet connectivity in AWS.
Which components would the administrator need to create in the VPC to achieve this?
- A . Public Subnet NAT Gateway, Public EIP, Route Table
- B . Private Subnet NAT Gateway, Public EIP, Route Table
- C . Private Subnet Flow Gateway, Public EIP, Route Table
- D . Public Subnet Flow Gateway, Public EIP, Route Table
B
Explanation:
To provide VMs with outbound internet connectivity in AWS using a private subnet, the administrator needs to create the following components in the VPC:
Private Subnet: A private subnet is required to house the VMs that need outbound internet access but do not require direct inbound access from the internet.
NAT Gateway: A NAT (Network Address Translation) Gateway is necessary to allow instances in the private subnet to connect to the internet or other AWS services while preventing the internet from initiating a connection with those instances.
Public EIP (Elastic IP Address): An EIP is associated with the NAT Gateway to provide a persistent
public IP address that allows outbound internet traffic from the private subnet to be routed correctly.
Route Table: A route table is configured to route traffic from the private subnet to the NAT Gateway
for outbound internet access.
Reference: AWS NAT Gateway Documentation
AWS VPC Subnet Basics
Which address must AWS Directory Service be able to resolve when deploying a new NC2 cluster?
- A . gateway-internal-api.cloud.nutanix.com
- B . gateway-external-api. cloud, nutanix.com
- C . dovvnloads.cloud.nutanix.com
- D . apikeys.nutanix.com
B
Explanation:
When deploying a new NC2 cluster, the AWS Directory Service must be able to resolve the address gateway-external-api.cloud.nutanix.com.
This external API gateway is critical for the NC2 cluster to communicate with Nutanix services for operations such as management, updates, and licensing.
Ensuring that this address can be resolved allows the cluster to interact properly with the Nutanix cloud infrastructure and services.
Reference: Refer to the Nutanix documentation on network and DNS requirements for NC2 deployments, specifically the addresses that need to be resolvable for proper functionality.
An administrator needs the permissions to create and manage multiple organizations and clusters in NC2, as well as manage user access for the entire company.
What role should be assigned to meet the minimum requirements of this task?
- A . Organization Administrator
- B . Customer Administrator
- C . Customer Security Administrator
- D . Cluster Administrator
B
Explanation:
The role of "Customer Administrator" in Nutanix Cloud Integration with AWS (NC2) is designed to meet the requirements of creating and managing multiple organizations and clusters, as well as managing user access for the entire company.
Roles and Permissions:
Customer Administrator: This role has the broadest set of permissions, allowing the user to create and manage organizations, clusters, and user access across the entire company. It encompasses administrative control over multiple aspects of the NC2 environment.
Capabilities:
Organization Management: Ability to create and manage multiple organizations.
Cluster Management: Full control over creating, configuring, and managing clusters.
User Access Management: Manage user roles and permissions, ensuring that the right individuals
have access to the necessary resources.
Why Not Other Roles:
Organization Administrator: Limited to managing organizations but not clusters and user access at the company level.
Customer Security Administrator: Focuses on security aspects, lacking broader administrative capabilities.
Cluster Administrator: Limited to managing clusters without the ability to manage organizations and user access comprehensively.
Reference: Nutanix Cloud Clusters on AWS Administration Guide
Nutanix Role-Based Access Control Documentation
An administrator has been tasked with deploying an NC2 cluster on AWS with the requirement to protect workloads.
Which two options are valid to protect the workloads on this cluster? (Choose two.)
- A . Deploy one-node cluster in another availability zone.
- B . Create a second NCZ cluster in a different availability zone.
- C . Use an existing on-prem Nutanix cluster as a disaster recovery target.
- D . Deploy a cluster across two availability zones.
B
Explanation:
To protect workloads on an NC2 cluster on AWS, deploying strategies that ensure high availability and disaster recovery are essential.
The two valid options are:
Create a Second NC2 Cluster in a Different Availability Zone:
High Availability: Deploying a second NC2 cluster in a different availability zone ensures that workloads can be quickly recovered in case of an availability zone failure.
Disaster Recovery: This setup enables asynchronous replication between clusters, providing a robust disaster recovery solution.
Use an Existing On-Prem Nutanix Cluster as a Disaster Recovery Target:
Hybrid DR: Leveraging an existing on-premises Nutanix cluster for disaster recovery provides a cost-effective and efficient DR solution.
Replication: Set up replication policies to ensure data is consistently copied from the NC2 cluster on AWS to the on-premises cluster.
Why Not Other Options:
One-node cluster in another availability zone: Not a valid DR solution as a single-node cluster cannot provide the required resilience and high availability.
Deploy a cluster across two availability zones: While this can enhance availability, it is not a typical approach for Nutanix clusters which are designed to operate within a single availability zone for simplicity and performance reasons.
Reference: Nutanix Cloud Clusters on AWS Administration Guide
Nutanix Disaster Recovery Best Practices
AWS Availability Zones and Disaster Recovery Documentation
An administrator needs to backup Prism Central configuration data to an Amazon S3 bucket.
Which pcdr-cli command parameters is needed to satisfy this task?
- A . deployment-info
- B . protect
- C . list-protection-targets
- D . recover
B
Explanation:
To backup Prism Central configuration data to an Amazon S3 bucket, the pcdr-cli command with the protect parameter is used. This parameter is specifically designed for creating protection policies and backing up Prism Central data.
Reference: Nutanix Prism Central Documentation
Nutanix pcdr-cli Command Reference