Nutanix NCP-CI-AWS Practice Exams
Last updated on Oct 06,2026- Exam Code: NCP-CI-AWS
- Exam Name: Nutanix Certified Professional - Cloud Integration - AWS v6.7
- Certification Provider: Nutanix
- Latest update: Oct 06,2026
To manually create an AWS VPC with Public access to Prism Element for testing purposes, Which components must be created?
- A . VPC, Delegated Subnets, Route Tables, NAT Gateway, Internet Gateway, Load balancer
- B . VPC, Delegated Subnets, Route Tables, NAT Gateway, vNets, Load balancer
- C . VPC Subnets Route Tables NAT Gateway, Internet Gateway, Load balancer
- D . VPC Subnets Route subnets, Route Tables, NAT Gateway, Internet Gateway, VPN
A
Explanation:
To manually create an AWS VPC with Public access to Prism Element for testing purposes, the following components must be created:
VPC: A Virtual Private Cloud to provide an isolated network for the resources.
Delegated Subnets: Subnets within the VPC to segment the network and allocate IP ranges.
Route Tables: To define routing rules for the subnets to ensure proper traffic flow.
NAT Gateway: To enable instances in the private subnets to access the internet.
Internet Gateway: To allow direct internet access to instances in the public subnets.
Load Balancer: To distribute traffic across multiple instances for improved availability and redundancy.
Reference: Refer to the AWS documentation on VPC creation and Nutanix documentation on network setup for Prism Element access.
Which NC2 user role will allow full access to clusters created within an organization?
- A . Cluster Super Admin
- B . Organization Administrator
- C . Organization Security Administrator
- D . Cluster Administrator
B
Explanation:
In Nutanix Cloud Integration with AWS, specifically version 6.7, the role that allows full access to clusters created within an organization is the Organization Administrator.
The Organization Administrator role has the highest level of privileges within an organization, enabling the user to manage all aspects of the clusters, including creation, modification, and deletion.
This role is designed to oversee and control the entire organization’s resources, ensuring comprehensive management capabilities over all clusters and associated resources.
Reference: Refer to the Nutanix documentation on roles and permissions for NC2 on AWS for further details.
An administrator is seeking help with an ongoing NC2 issue. After reaching out to Nutanix support, the administrator is introduced to NC2 specialist who can help troubleshoot the problem.
- A . Ensure the specialist is assigned the RBAC role with proper permissions.
- B . Add the specialist as an admin user to the organizations.
- C . Confirm the Support Authorization on the organization is set to Full Access.
- D . Provide the specialist with the administrator’s login credentials.
AC
Explanation:
Ensure the specialist is assigned the RBAC role with proper permissions (Answer A): Role-Based Access Control (RBAC) ensures that the specialist has the necessary permissions to troubleshoot and manage the NC2 environment. This avoids unnecessary privilege escalations and maintains security.
Confirm the Support Authorization on the organization is set to Full Access (Answer C):
Setting the Support Authorization to Full Access allows the Nutanix support specialist to have the required access to investigate and resolve issues in the environment. This is essential for effective troubleshooting.
Reference: Nutanix RBAC Documentation
Nutanix Support Access Guide
A company has a large scale AWS deployment and has just finished installing their first NC2 on AWS cluster. The new cluster is now running workloads in production.
The cluster is configured with:
* 16 Nodes
* 8 Subnets
* 200 User VMs per subnet
* Nutanix Files
An administrator has been tasked with installing an EC2 instance on one of the subnets that is also used by the Nutanix, When the EC2 instance is powered on, an IP conflict occurs.
What action should the administrator take to resolve this issue?
- A . The IP address used by the NC2 VM should be blocked /excluded from EC2.
- B . The Instance Metadata of the NC2 instance needs to have the address reserved.
- C . Assign an elastic IP to the EC2 instance and reboot.
- D . The IP address used by the EC2 instance should be blocked / excluded from IPAM.
A
Explanation:
To resolve the IP conflict issue when an EC2 instance is powered on in a subnet also used by Nutanix NC2, the administrator should block or exclude the IP address used by the NC2 VM from being assigned to EC2 instances. This can be done by configuring the IP address management (IPAM) settings to ensure that the specific IP addresses allocated to the NC2 VMs are not used by EC2 instances, preventing IP conflicts and ensuring smooth operation of both environments.
Reference: Nutanix Cloud Clusters on AWS Deployment Guide
Nutanix Support & Insights
A company has a large scale AWS deployment and has just finished installing their first NC2 on AWS cluster. The new cluster is now running workloads in production.
The cluster is configured with:
* 16 Nodes
* 8 Subnets
* 200 User VMs per subnet
* Nutanix Files
An administrator has been tasked with installing an EC2 instance on one of the subnets that is also used by the Nutanix, When the EC2 instance is powered on, an IP conflict occurs.
What action should the administrator take to resolve this issue?
- A . The IP address used by the NC2 VM should be blocked /excluded from EC2.
- B . The Instance Metadata of the NC2 instance needs to have the address reserved.
- C . Assign an elastic IP to the EC2 instance and reboot.
- D . The IP address used by the EC2 instance should be blocked / excluded from IPAM.
A
Explanation:
To resolve the IP conflict issue when an EC2 instance is powered on in a subnet also used by Nutanix NC2, the administrator should block or exclude the IP address used by the NC2 VM from being assigned to EC2 instances. This can be done by configuring the IP address management (IPAM) settings to ensure that the specific IP addresses allocated to the NC2 VMs are not used by EC2 instances, preventing IP conflicts and ensuring smooth operation of both environments.
Reference: Nutanix Cloud Clusters on AWS Deployment Guide
Nutanix Support & Insights
An administrator is planning a new NC2 on AWS deployment. The workload VMs to be deployed on the new cluster have low storage and memory, but high CPU frequency (>3.0 GHz) requirements. The administrate! has also been tasked with ensuring that the cluster nodes have the lowest number of CPU cores to reduce application licensing requirements.
Which node type will satisfy this new deployment?
- A . i3.metal
- B . zld.metal
- C . i4i.metal
- D . m5d.metal
A
Explanation:
For a new NC2 on AWS deployment where workload VMs have low storage and memory requirements but high CPU frequency (>3.0 GHz) requirements, and the goal is to minimize the number of CPU cores to reduce application licensing costs, the i3.metal instance type is the most suitable.
i3.metal:
High CPU Frequency: i3.metal instances offer high-frequency Intel Xeon processors (up to 3.1 GHz) which meet the high CPU frequency requirement.
Low Storage and Memory: These instances come with a balanced amount of storage and memory, suitable for workloads with low requirements in these areas.
Minimized CPU Cores: i3.metal instances have fewer CPU cores compared to other high-frequency instances like i4i.metal, making them ideal for minimizing application licensing costs.
Other Instance Types:
z1d.metal: While also offering high CPU frequency, these instances typically come with a higher core count and more memory, which may not be optimal for minimizing licensing costs. i4i.metal: Designed for I/O intensive applications with higher core counts.
m5d.metal: Balanced instance type but with more cores and not as high CPU frequency as required.
Reference: AWS EC2 Instance Types Documentation
Nutanix Cloud Clusters on AWS Administration Guide
Nutanix Best Practices for Instance Selection
Which two options are prerequisites for deploying an NC2 on AWS cluster? (Choose two.)
- A . AWS Direct Connect
- B . A valid CIDR range
- C . A my.nutanix.com account
- D . An on-premises Prism Central environment
BC
Explanation:
A valid CIDR range: A CIDR (Classless Inter-Domain Routing) range is necessary for creating the subnets within the VPC. This range defines the IP address space for the cluster and its components. A my.nutanix.com account: This account is required to access Nutanix services, including the NC2 console, manage licenses, and perform other administrative tasks.
AWS Direct Connect and an on-premises Prism Central environment are not prerequisites for deploying an NC2 on AWS cluster. While Direct Connect can be used for enhanced network performance and connectivity, it is not a requirement for deployment. Similarly, having an on-premises Prism Central environment is not mandatory for NC2 deployment on AWS.
Reference: Refer to the Nutanix documentation on NC2 prerequisites and setup guides, and AWS documentation on VPC and subnet creation.
Which two statements are the most accurate regarding Cluster Protect? (Choose two.)
- A . An AWS subnet can be shared by VMs, Prism Central, and Multicloud Snapshort Technology (MST).
- B . Nutanix Guest Tools (NGT) is not required to be installed on User VMs.
- C . The dusters that are to be protected must be registered with the same instance of Prism Central.
- D . The Cluster Protect feature requires AOS version 6.7 or higher.
CD
Explanation:
The clusters that are to be protected must be registered with the same instance of Prism Central (Answer C):
For Cluster Protect to function correctly, all clusters intended for protection must be registered under the same Prism Central instance. This ensures consistent management and coordination of protection policies and operations across clusters.
The Cluster Protect feature requires AOS version 6.7 or higher (Answer D):
Cluster Protect is a feature that is available starting from AOS version 6.7. To utilize this feature, ensure that the Nutanix clusters are running this version or a newer one.
Reference: Nutanix Cluster Protection Documentation
Nutanix AOS Release Notes
An administrator is tasked with adding an AWS account to the NC2 console. A requirement is to configure an AWS IAM user with the appropriate permissions.
Which permission must be assigned to the user?
- A . lAMFullAccess
- B . lAMReadOnlyAccess
- C . AmazonEC2ReadOnlyAccess
- D . AmazonEC2FullAccess
D
Explanation:
To add an AWS account to the NC2 console, an AWS IAM user needs to be configured with the appropriate permissions to manage the EC2 resources. The required permission for the IAM user includes full access to manage EC2 instances, volumes, and related resources.
AmazonEC2FullAccess:
This permission grants full access to all EC2 resources, including the ability to create, modify, and delete instances, volumes, security groups, and more.
Essential for NC2 operations to manage the lifecycle of EC2 instances and associated components within the AWS environment.
Why Not Other Permissions:
IAMFullAccess: Grants full access to IAM resources but not specifically needed for EC2 operations. IAMReadOnlyAccess: Only provides read access to IAM resources, insufficient for managing EC2 instances.
AmazonEC2ReadOnlyAccess: Provides read-only access to EC2 resources, insufficient for creating or modifying instances and other resources.
Reference: AWS IAM Policies Documentation
Nutanix Cloud Clusters on AWS Administration Guide
Nutanix Best Practices for IAM User Permissions
An administrator has been tasked with ensuring NC2 VMs are able to access AWS resources. The NC2 VM traffic must not traverse the internet.
in which two ways would the administrator achieve this? (Choose two.)
- A . By using a Gateway Endpoint
- B . By using a NAT Gateway.
- C . By using an Interface Endpoint
- D . By using a VPC Peer.
CD
Explanation:
To ensure that NC2 VMs can access AWS resources without traversing the internet, the administrator can use AWS VPC Peering and Interface Endpoints. Both methods ensure that traffic stays within the AWS network, maintaining security and efficiency.
Interface Endpoint:
Interface Endpoints allow you to privately connect your VPC to supported AWS services. They use AWS PrivateLink to route traffic directly to services within the AWS network, bypassing the public internet.
Steps:
Create an interface endpoint for the required service in the AWS VPC console.
Ensure the security groups and route tables are configured to allow traffic to the interface endpoint.
VPC Peering:
VPC Peering allows the routing of traffic between VPCs using private IP addresses, without the need for internet gateways, NAT devices, or VPN connections.
Steps:
Create a VPC peering connection between the VPCs.
Update the route tables to direct traffic between the peered VPCs. Ensure security group rules allow the necessary traffic between VPCs.
Reference: AWS VPC Peering Documentation
AWS Interface Endpoint Documentation
Nutanix Cloud Clusters on AWS Administration Guide