Nutanix NCP-CI-Azure Practice Exams
Last updated on Oct 07,2026- Exam Code: NCP-CI-Azure
- Exam Name: Nutanix Certified Professional - Cloud Integration - Azure (NCP-CI-Azure v6.7)
- Certification Provider: Nutanix
- Latest update: Oct 07,2026
After creating a new Nutanix User VPC, what is needed to allow traffic to flow out of the Flow gateway VM when using the NATed Path?
- A . Add a default route on the Transit VPC of 0.0.0.0/0 to the Flow Gateway.
- B . Add a default route on the Transit VPC of 0.0.0.0/0 to the Flow Gateway.
- C . Add a default route on the Nutanix User VPC of 0.0.0.0/0 to the External Overlay network.
- D . Edit the External Flow Gateway Security Group on the External NIC to allow outbound traffic.
Edit the Internal Flow Gateway Security Group on the internal NIC to allow outbound taffic
C
Explanation:
NATed Path Configuration: When using the NATed Path, it is essential to ensure that traffic can flow out of the Flow gateway VM to external networks.
Default Route: Adding a default route on the Nutanix User VPC ensures that all outbound traffic is directed to the appropriate network gateway.
Configuration Steps:
Navigate to the routing settings of the Nutanix User VPC.
Add a default route with the destination of 0.0.0.0/0, pointing to the External Overlay network.
Security Group Settings:
Ensure that the External Flow Gateway Security Group on the External NIC allows outbound traffic. Ensure that the Internal Flow Gateway Security Group on the internal NIC allows outbound traffic (if needed for internal network flows).
Conclusion: Properly configuring the default route on the Nutanix User VPC enables outbound traffic flow via the NATed Path through the External Overlay network.
Reference: Nutanix Flow Gateway Configuration Guide
Azure VPC Routing Documentation
An administrator must ensure that certain NC2 VMs can access Azure resources. The NC2 VM traffic must not traverse the internet.
How would the administrator achieve this?
- A . By creating an Azure Private Endpoint for VMs in a Delegated Subnet
- B . By creating an Azure Private Endpoint for VMs in a NAT network via vWAN.
- C . By creating an Azure Private Endpoint for VMs in a No-NAT network via vWAN.
- D . By creating an Azure Private Endpoint for VMs in the host-mgmt subnet.
A
Explanation:
Azure Private Endpoint: A Private Endpoint provides secure connectivity to Azure resources by enabling private access through the Azure backbone network. This ensures that the traffic does not traverse the internet, providing enhanced security and performance.
Delegated Subnet: By creating an Azure Private Endpoint for VMs in a delegated subnet, the administrator ensures that the VMs can access Azure resources directly and securely without using the public internet.
Reference: Azure Private Endpoint Documentation
Nutanix NC2 Networking Configuration Guide
An administrator needs to open the following ports in the firewall between an on-premises cluster and azure for disaster recovery:
* 22
* 2009
* 2020
* 2049
* 3260
* 9440
Which rile-type should be created on the firewall for communication to be appropriately established?
- A . Outbound (TCP)
- B . Bi-directional (TCP)
- C . Bi-directional (ICMP)
- D . Outbound (ICMP)
B
Explanation:
Port Requirements: The specified ports (22, 2009, 2020, 2049, 3260, 9440) are commonly used for various services and require TCP communication. Port 22: SSH
Port 2009: Used for Nutanix internal communication
Port 2020: Nutanix services
Port 2049: NFS
Port 3260: iSCSI
Port 9440: Nutanix Prism management
Communication Type: To ensure proper disaster recovery setup, bi-directional communication is needed to allow traffic to flow both from on-premises to Azure and vice versa.
TCP Protocol: These ports use the TCP protocol, which provides reliable communication between devices.
Conclusion: Creating a bi-directional (TCP) rule on the firewall allows the necessary communication for
disaster recovery processes.
Reference: Nutanix Networking and Security Documentation
Azure Networking Documentation
Exhibit.

AN NC2 on Azure Cluster was deployed with two Flow gateways in HA (FGW1 and FGW2). After a week of use. Four bare-metal nodes, were added to the NC2 cluster and additional workloads were added.
It was determined that additional bandwidth for north/South traffic would be needed. Two additional Flow gateways were added (FGW3 and FGW4) from the NC2 portal configuration menu.
The existing workloads prior to expansion on the NC2 cluster will be able to use which Flow Gateways using the No-Nat (routed) traffic path?
- A . Only the Flow Gateway that each workload was originally using.
- B . All Flow Gateways can be used.
- C . All Flow Gateways can be used after the existing workloads reboot.
- D . FGW1&FGW2 only, new workloads can use FGW3 & FGW4.
B
Explanation:
In the scenario presented, the NC2 cluster was initially deployed with two Flow Gateways (FGW1 and FGW2) in HA. After adding four bare-metal nodes and additional workloads, two more Flow Gateways (FGW3 and FGW4) were added to handle the increased bandwidth for north/south traffic. Given the configuration, the existing workloads can utilize all available Flow Gateways (FGW1, FGW2, FGW3, and FGW4) for No-NAT (routed) traffic paths. This setup allows for Equal Cost Multipath (ECMP) routing, distributing traffic load across all Flow Gateways.
Reference: Nutanix Flow Networking
Which two options are prerequisites for deploying an NC2 cloud cluster in Azure? (Choose two.)
- A . An Azure Express Route circuit
- B . A valid CIDR range
- C . A my.nutanix.com account
- D . An on Premises Prism Central environment
B, C
Explanation:
Valid CIDR Range: When deploying an NC2 cloud cluster in Azure, a valid CIDR range is necessary to define the IP address space for the cluster and its associated networks. This range ensures that there are no conflicts with existing network configurations and provides sufficient addresses for the cluster resources.
My Nutanix Account: A my.nutanix.com account is required to access Nutanix services and manage NC2 deployments. This account allows administrators to log in, configure settings, and manage their Nutanix environment on Azure.
Reference: Nutanix NC2 on Azure Deployment Guide
Azure Virtual Network Documentation
An administrator has been tasked with scoping an NC2 on Azure deployment. One of the requirements is to ensure that the bare metal instance will support up to 20 TB of storage capacity.
Which bare metal instance should the administrator choose?
- A . ND96asr
- B . AN36P
- C . AN36
- D . HB176rs
B
Explanation:
Storage Capacity Requirement: The requirement specifies that the bare metal instance must support up to 20 TB of storage capacity.
Instance Selection: Among the provided options, the AN36P instance is designed to support higher storage capacities and performance needs.
AN36P Capabilities: The AN36P instance is optimized for storage-intensive applications and provides the necessary hardware specifications to handle up to 20 TB of storage. Comparison with Other Instances:
ND96asr: Typically optimized for GPU workloads rather than storage.
AN36: May not meet the 20 TB storage requirement.
HB176rs: Geared towards high-performance computing rather than large storage capacities. Conclusion: Based on the requirements and instance specifications, AN36P is the most suitable choice for supporting up to 20 TB of storage.
Reference: Nutanix NC2 Instance Types
Azure Virtual Machine Sizes
Which address must Azure Directory Service be able to resolve when deploying a new NC2 cluster?
- A . Download.cloud.nutanix.com
- B . Apikeys.nutanix.com
- C . Gateway-external-api.cloud.nutanix.com
- D . Gateway-internal-api-cloud.nutanix.com
C
Explanation:
Azure Directory Service Role: Azure Directory Service must be able to resolve specific Nutanix URLs to ensure proper communication and functionality during the deployment of an NC2 cluster.
Critical Endpoint: The address "Gateway-external-api.cloud.nutanix.com" is critical for establishing external API communications required for the deployment and management of the NC2 cluster. DNS Resolution: Proper DNS resolution of this address ensures that the Azure Directory Service can interact with Nutanix services and APIs necessary for cluster operations.
Verification Process:
Ensure that DNS settings allow resolution of "Gateway-external-api.cloud.nutanix.com".
Test connectivity and resolution prior to deployment to avoid issues.
Importance: Without resolving this address, the deployment process might face connectivity issues,
leading to potential deployment failures.
Reference: Nutanix NC2 on Azure Setup Guide
Azure Active Directory Integration
A company needs to establish connectivity between the on-premises datacenter and Azure. The company does not have the infrastructure for a dedicated connection.
Which method will best satisfy this requirement?
- A . Azure Virtual WAN
- B . VPN
- C . VNet Peering
- D . ExpressRoute
B
Explanation:
VPN for Connectivity: A VPN (Virtual Private Network) allows secure connectivity between the on-premises datacenter and Azure over the public internet without requiring dedicated infrastructure. Ease of Setup: VPNs are typically easier and quicker to set up compared to dedicated connections like ExpressRoute, making them suitable for organizations without existing dedicated connection infrastructure.
Reference: Azure VPN Gateway Documentation
Nutanix NC2 Connectivity Guide
An administrator deploys a new NC2 cluster in Azure in a new subscription. No VPN or Express Route exists.
Which two actions will allow the administrator access to Prism Central to start the configuration? (Choose two.)
- A . Deploy a Jump Host VM instance in an external VNet and peer the VNets.
- B . Deploy a Jump Host VM instance and NAT Gateway in an external VNet and peer the VNets.
- C . Deploy a Jump Host VM instance in the Prism Central VNet inside a delegated subnet.
- D . Deploy a Jump Host VM instance in the Prism Central VNet inside a non-delegated subnet.
A, C
Explanation:
Jump Host VM in External VNet with VNet Peering:
Deploy Jump Host VM:Deploy a VM in an external VNet that is not within the same network as Prism
Central.
VNet Peering:Establish VNet peering between the external VNet and the Prism Central VNet. This allows the Jump Host to communicate with Prism Central securely.
Jump Host VM in Prism Central VNet Inside a Delegated Subnet:
Deploy Jump Host VM: Deploy the Jump Host VM directly in the Prism Central VNet within a delegated subnet. This places the Jump Host in the same network environment as Prism Central, allowing direct access.
Reference: Azure VNet Peering Documentation
Nutanix NC2 Networking and Access Configuration Guide
Exhibit
An NC2 on Azure cluster was deployed with two Flow Gateway in HA (FHW1 and FGW2). After a week of use, four bare-metal nodes were added to the NC2 cluster and additional workloads were added. The existing workloads were using floating IPs to allow inbound traffic to communicate with the running workloads on the NC2 cluster.
It was determined that additional bandwidth for north/south traffic would be needed. Two additional Flow Gateways were added (FGW3 and FGW4) from the NC2 portal configuration menu.
The existing workloads prior to expansion on the NC2 cluster will be able to use which Flow Gateways using the NAT traffic path after the expansion?
- A . They will be able to use FGW3 and FGW4 once the NC2 workloads reboots.
- B . All four Flow Gateways using a MAC/Hash algorithm.
- C . Only the Flow Gateway each workload was using prior to expansion.
- D . All four Flow Gateways.
C
Explanation:
In the NC2 on Azure cluster scenario, the existing workloads were using floating IPs for inbound traffic before the addition of new Flow Gateways (FGW3 and FGW4). The NAT traffic path established initially will continue to direct traffic through the originally assigned Flow Gateways (FGW1 and FGW2). The existing workloads will not automatically utilize the new Flow Gateways (FGW3 and FGW4) without a reconfiguration or reboot, which reassigns the NAT paths.
Reference: Nutanix Flow Networking and Configuration Guide