Nutanix NCP-CI-AWS Practice Exams
Last updated on Oct 06,2026- Exam Code: NCP-CI-AWS
- Exam Name: Nutanix Certified Professional - Cloud Integration - AWS v6.7
- Certification Provider: Nutanix
- Latest update: Oct 06,2026
An administrator needs to backup Prism Central configuration data to an Amazon S3 bucket.
Which pcdr-cli command parameters is needed to satisfy this task?
- A . deployment-info
- B . protect
- C . list-protection-targets
- D . recover
B
Explanation:
To backup Prism Central configuration data to an Amazon S3 bucket, the pcdr-cli command with the protect parameter is used. This parameter is specifically designed for creating protection policies and backing up Prism Central data.
Reference: Nutanix Prism Central Documentation
Nutanix pcdr-cli Command Reference
An administrator needs to understand which of the services implemented on their NC2 AWS deployment will be protected with Cluster protect.
Which service of feature is Cluster Protect able to both protect and recover its associated metadata?
- A . Object
- B . VM templates
- C . Files
- D . Categories
BC
Explanation:
Cluster Protect in an NC2 environment can protect and recover the following services and their associated metadata:
VM Templates: Ensures that templates used for creating virtual machines are backed up and recoverable.
Files: Protects data stored in Nutanix Files, ensuring that file services are backed up and can be restored as needed.
Reference: Nutanix Support & Insights
Nutanix Cloud Clusters on AWS Administration
An organization wants to control network traffic at the individual User VM (UVM) subnet level.
Which action will help achieve this goal?
- A . Create a custom security group.
- B . Modify the default UVM security group.
- C . Modify the user management security group.
- D . Modify the internal management security group.
A
Explanation:
To control network traffic at the individual User VM (UVM) subnet level, creating a custom security group is the appropriate action. This approach allows for fine-grained control over inbound and outbound traffic rules that can be applied to specific subnets or individual instances within those subnets.
Custom Security Group:
Custom security groups enable administrators to define specific traffic rules tailored to the needs of individual subnets or VMs. This includes specifying allowed IP ranges, ports, and protocols.
By applying these custom security groups to the UVMs, the organization can control access and enhance security according to their policies and requirements. Steps to Create a Custom Security Group:
Navigate to the AWS Management Console and go to the VPC service.
Select "Security Groups" under the "Security" section.
Click on "Create Security Group" and define the name, description, and VPC. Add inbound and outbound rules according to the desired traffic control policies. Attach the custom security group to the UVMs or subnets in question.
Reference: Nutanix Cloud Clusters on AWS Administration Guide
AWS Security Group Documentation
Nutanix Best Practices for Security Groups
An administrator is deploying a new NC2 cluster on AWS and needs to ensure full connectivity is established between the company’s on-premises datacenter and the AWS cloud.
Which two AWS offering will satisfy this requirement? (Choose two.)
- A . ExpressRoute
- B . AWS VPN
- C . Direct Connect
- D . Dedicated interconnect
BC
Explanation:
To establish full connectivity between the company’s on-premises datacenter and the AWS cloud, the following AWS offerings will satisfy this requirement:
AWS VPN: This service allows you to create a secure connection between your on-premises network or other remote network and your AWS VPC using an IPsec VPN tunnel. It is suitable for low to moderate bandwidth requirements and provides secure, encrypted connections.
Direct Connect: AWS Direct Connect is a dedicated network connection from your premises to AWS. It provides a private, high-bandwidth, low-latency connection which is ideal for high-throughput applications and workloads that need consistent network performance.
Reference: AWS VPN Documentation
AWS Direct Connect Documentation
An administrator has deployed an NC2 cluster on AWS to an existing environment for VDI. Afterwards, the corporate security teams direct the administrator to reuse an existing AWS subnet, 10.79.4.0/24 that has two EC2 instances: EC2-1 (10.79.4.200) and EC2-2 (10.79.4.201). The security team indicates that this directive is to avoid overlap with the AHV IPAM.
Which two configuration actions should the administrator take to ensure there are no configuration issues? (Choose two.)
- A . aCLI > net.add_to_ip_bfacklist 10.79.4.200 aCLI > net.add_to_ip_blacklist 10.79.4.201
- B . Deploy two VMs on the NC2 cluster and assign 10.79.4.200 and 10.79.4.201 as the assigned IPs in Prism Element
- C . aCLI > net.de/ete_from_ip_blacklist 10.79.4.200 aCLI > net.defete_fromjp_blacklist 10.79.4.201
- D . Configure the AHV JPAM to use DHCP range 10.79.4.2 -10.79.4.253.
AD
Explanation:
To avoid IP address conflicts and ensure there are no configuration issues when reusing an existing AWS subnet, the administrator should take the following actions:
aCLI > net.add_to_ip_blacklist 10.79.4.200 aCLI > net.add_to_ip_blacklist 10.79.4.201 (Answer A): This command adds the specified IP addresses to the blacklist, preventing AHV IPAM from assigning these addresses to any VMs. This ensures that the existing EC2 instances with IPs 10.79.4.200 and 10.79.4.201 are not allocated to other VMs in the NC2 cluster.
Configure the AHV IPAM to use DHCP range 10.79.4.2 -10.79.4.253 (Answer D):
By configuring the AHV IPAM to use a specific DHCP range, you ensure that the IP addresses assigned to the EC2 instances (10.79.4.200 and 10.79.4.201) are not included in the DHCP pool. This prevents IP address conflicts within the subnet.
Reference: Nutanix aCLI Reference
Nutanix NC2 on AWS Documentation
AWS VPC and Subnet Basics
An administrator is experiencing problems with several operations, including VM IP address assignment validations, VM power-on and VM power-off operations.
Whenever a related operation is performed, an alert is generated in the NC2 console indicating that the Cloud API endpoints are unavailable.
The issue was further investigated and it was determined that NC2 is unable to make API calls to the underlying cloud infrastructure due to network connectivity misconfigurations.
Which two connectivity misconfigurations could be causing this issue? (Choose two.)
- A . AWS VPC endpoints are used for connectivity to AWS services.
- B . Subnets are connected to the Internet via NAT gateways.
- C . Route tables for cloud subnets contain incorrect route entries.
- D . IAM roles and policies are incorrectly configured.
CD
Explanation:
Route tables for cloud subnets contain incorrect route entries:
If the route tables associated with the cloud subnets contain incorrect route entries, the NC2 cluster might not be able to reach the necessary AWS services or endpoints. Correct route entries are crucial for ensuring proper communication between the NC2 cluster and the underlying AWS infrastructure.
IAM roles and policies are incorrectly configured:
Incorrectly configured IAM roles and policies can prevent NC2 from making API calls to AWS services. These roles and policies must be properly set up to allow the necessary permissions for NC2 to interact with AWS resources and perform required operations.
Reference: Refer to the AWS documentation on route table configuration and IAM roles and policies, and Nutanix documentation on NC2 cloud connectivity and permissions.
An administrator is experiencing problems with several operations, including VM IP address assignment validations, VM power-on and VM power-off operations.
Whenever a related operation is performed, an alert is generated in the NC2 console indicating that the Cloud API endpoints are unavailable.
The issue was further investigated and it was determined that NC2 is unable to make API calls to the underlying cloud infrastructure due to network connectivity misconfigurations.
Which two connectivity misconfigurations could be causing this issue? (Choose two.)
- A . AWS VPC endpoints are used for connectivity to AWS services.
- B . Subnets are connected to the Internet via NAT gateways.
- C . Route tables for cloud subnets contain incorrect route entries.
- D . IAM roles and policies are incorrectly configured.
CD
Explanation:
Route tables for cloud subnets contain incorrect route entries:
If the route tables associated with the cloud subnets contain incorrect route entries, the NC2 cluster might not be able to reach the necessary AWS services or endpoints. Correct route entries are crucial for ensuring proper communication between the NC2 cluster and the underlying AWS infrastructure.
IAM roles and policies are incorrectly configured:
Incorrectly configured IAM roles and policies can prevent NC2 from making API calls to AWS services. These roles and policies must be properly set up to allow the necessary permissions for NC2 to interact with AWS resources and perform required operations.
Reference: Refer to the AWS documentation on route table configuration and IAM roles and policies, and Nutanix documentation on NC2 cloud connectivity and permissions.
An administrator has deployed an NC2 on AWS cluster and doesn’t have connectivity back to the on-premises environment yet. The administrator wants to SSH into a CVM to edit a security setting and has deployed a Jump Host into an existing public subnet.
What action must the administrator still take to gain access to the CVM?
- A . Edit the CVM iptables to allow SSH.
- B . Edit the User Management Network Security Group to allow SSH from the Jump Host IP.
- C . Edit the UVM security group to allow SSH from the Jump Host IP and remove Cluster Lockdown.
- D . Create Custom Network Security Group at the subnet level and add the IP address of the Jump Host
B
Explanation:
To SSH into a Controller VM (CVM) in an NC2 on AWS cluster without on-premises connectivity, the administrator needs to ensure that the security settings allow SSH access from the Jump Host. This involves editing the User Management Network Security Group to permit SSH traffic from the Jump Host IP.
Deploy Jump Host:
Ensure the Jump Host is deployed in a public subnet with an Elastic IP (EIP) assigned for external access.
Edit User Management Network Security Group:
Locate the security group associated with the user management network.
Modify the inbound rules to allow SSH (port 22) from the Jump Host’s IP address. This ensures that the Jump Host can establish an SSH connection to the CVM.
Steps to Edit Security Group:
Navigate to the EC2 dashboard in the AWS Management Console.
Select "Security Groups" under the "Network & Security" section.
Find and select the appropriate security group.
Edit the inbound rules to add a new rule:
Type: SSH
Protocol: TCP
Port Range: 22
Source: Custom IP (enter the Jump Host’s public IP address)
Additional Configuration:
Ensure that the CVM itself allows SSH connections and that no internal firewall rules block the traffic.
Reference: Nutanix Cloud Clusters on AWS Administration Guide
AWS Security Group Documentation
Nutanix Best Practices for Secure Access
A company wants to start using Nutanix Cloud Clusters (NC2) in AWS. The company has large spend commitments as part of an AWS Enterprise Discount Program (EDP) totaling $15 million.
What approach should the administrator take to ensure that Nutanix licensing costs to the EDP commitment?
- A . Purchase Nutaniz licenses through the AWS Marketplace.
- B . Purchase Nutanix licenses directly from Nutanix and contact AWS support.
- C . Leverage existing Nutanix licenses.
- D . Request a trial license directly from Nutanix
A
Explanation:
Given the company’s large spend commitments as part of an AWS Enterprise Discount Program (EDP) totaling $15 million, purchasing Nutanix licenses through the AWS Marketplace ensures that the costs contribute to the EDP commitment.
This approach integrates the Nutanix license costs into the overall AWS spend, thereby maximizing the benefits of the EDP.
Purchasing directly from Nutanix or leveraging existing licenses might not count towards the AWS EDP commitment, and trial licenses are typically for evaluation purposes and do not contribute to the committed spend.
Reference: Refer to the Nutanix and AWS documentation on licensing and marketplace purchases, and EDP program details.
A company wants to start using Nutanix Cloud Clusters (NC2) in AWS. The company has large spend commitments as part of an AWS Enterprise Discount Program (EDP) totaling $15 million.
What approach should the administrator take to ensure that Nutanix licensing costs to the EDP commitment?
- A . Purchase Nutaniz licenses through the AWS Marketplace.
- B . Purchase Nutanix licenses directly from Nutanix and contact AWS support.
- C . Leverage existing Nutanix licenses.
- D . Request a trial license directly from Nutanix
A
Explanation:
Given the company’s large spend commitments as part of an AWS Enterprise Discount Program (EDP) totaling $15 million, purchasing Nutanix licenses through the AWS Marketplace ensures that the costs contribute to the EDP commitment.
This approach integrates the Nutanix license costs into the overall AWS spend, thereby maximizing the benefits of the EDP.
Purchasing directly from Nutanix or leveraging existing licenses might not count towards the AWS EDP commitment, and trial licenses are typically for evaluation purposes and do not contribute to the committed spend.
Reference: Refer to the Nutanix and AWS documentation on licensing and marketplace purchases, and EDP program details.