NCP-NS
75 questions 120 min Pass: 3000 / 6000 Official Nutanix Website Nutanix University
About this course
Target exam: Nutanix Certified Professional - Network & Security (NCP-NS) 7.5
Software under test:
- Flow Virtual Networking (FVN) 6.0
- Flow Network Security (FNS) 5.2
- Prism Central 7.3
Exam facts:
- 75 multiple-choice / multiple-response questions
- 120 minutes
- passing score 3000 (scaled 1000–6000)
- English & Japanese
- $200 USD
- valid 3 years
Structured as 5 sections · 17 chapters · 81 sub-sections, with a 300-question practice bank weighted by blueprint objective. All deliverables in English, grounded in the official Flow guides and the pinned ports/maximums CSVs.
How this course is built
Each sub-section follows the same frame, so it doubles as a study guide and a revision checklist:
- Why it matters - the blueprint objective the sub-section maps to.
- How it works - the mechanism, with a concrete example.
- Exam traps - the confusions and near-miss values the exam tests.
- Key facts - the numbers/limits to memorize.
Sources are cited inline; any figure not confirmable in the corpus is flagged ⚠️ rather than invented. The practice questions have 4 homogeneous options, one anchored answer, a rationale and a source, balanced across A/B/C/D.
Preparation course
Log in to start & track your progress
Part I - Configure Flow Virtual Networking
- 1.1 Determine whether a tenant or a transit VPC is required
- 1.2 Recognize the purpose/usage of the ERP (Externally Routable Prefix)
- 1.3 Identify the VPC Gateway nodes
- 1.4 Associate routed and private CIDRs
- 2.1 Determine when overlapping ERPs is necessary
- 2.2 Associate Scale-out VPC Gateway nodes to a VPC
- 2.3 Determine when to set the default route
- 2.4 Determine routes to be set during VPC creation
- 2.5 Assign a specific Router IP / SNAT IP to a VPC
- 2.6 Change the external network for a VPC
- 2.7 Create an Overlay External Network
- 2.8 Associate a VPC to a transit VPC Overlay External Network
- 2.9 Determine when to connect a VPC to a NAT or a No-NAT network
- 3.1 Create a network load balancer with a target group of VMs
- 3.2 Analyze BGP peering session status (advertised & received routes)
- 3.3 Define a Policy-Based Routing policy to redirect traffic to a security appliance
- 3.4 Assign a floating IP to a workload for external access (NAT connectivity)
- 3.5 Create resiliency within BGP neighbors
Part II - Configure Flow Network Security
- 4.1 Determine when monitoring mode is appropriate for policy creation
- 4.2 Configure syslog to ship logs externally / enable policy logging
- 4.3 Define/update a policy rule set using flow visualization / captured traffic
- 4.4 Recognize the purpose and use case for a shared services policy
- 5.1 Determine the appropriate policy type based on business needs
- 5.2 Configure Isolation policies between two or more entities
- 5.3 Configure Application policies with appropriate Secured Entities
- 5.4 Configure Group ID lookup for Active Directory
- 5.5 Configure VDI policies
- 5.6 Explain the use case for the quarantine function
- 6.1 Create a policy in Monitor mode and identify discovered traffic
- 6.2 Enforce a policy currently applied in Monitor mode
- 6.3 Clone a policy and apply to a different Scope
- 6.4 Identify the number of entities potentially impacted by enforcing a monitored policy
- 6.5 Describe the different policy lifecycle modes
Part III - Troubleshoot Flow Virtual Networking
- 7.1 Diagnose why a VM inside a VPC cannot reach the Internet
- 7.2 Diagnose why two VMs within the same VPC cannot communicate
- 7.3 Diagnose why a VM within a VPC cannot access the external network
- 7.4 Diagnose why a BGP neighbor is not receiving expected routes from the VPC
- 7.5 Identify and resolve network gateway status issues
- 7.6 Determine if a Gateway VM (VTEP, VPN, or BGP) is unhealthy
- 7.7 Verify that subnet extension is active and healthy
- 8.1 Diagnose BGP state using session logs
- 8.2 Determine which user made a particular change and when
- 8.3 Analyze IPFIX exports to identify connectivity issues
- 8.4 Interpret alerts and take corrective actions
- 9.1 Check the Network Controller's health
- 9.2 Recognize which actions can/cannot be performed when the Network Controller is unhealthy
- 9.3 Interpret Network Controller and FNS alerts
Part IV - Troubleshoot Flow Network Security
- 10.1 Determine if desired traffic is being prevented by a security policy
- 10.2 Verify VM membership in a policy component
- 10.3 Assess Security Policy Hitlogs (allowed vs denied traffic)
- 10.4 Identify policy priority conflicts (intra-tier vs inbound/outbound)
- 10.5 Determine root cause of packet loss when service insertion is in use
- 10.6 Troubleshoot routes-present-but-N/S-broken (MTU)
- 11.1 Pipe FNS Security Hit logs to an external syslog server
- 11.2 Determine conntrack table status via NCC health checks
- 11.3 Interpret FNS audit logs to diagnose an FNS issue
- 12.1 Verify AD is properly configured (URL, service account, credentials)
- 12.2 Enable ID-Based Security and manage referenced AD groups
- 12.3 Validate dynamic category assignment at login time
- 12.4 Validate that group memberships have been applied to a policy
Part V - Deploy and Upgrade a Flow Environment
- 13.1 Enable FNS from Prism Central
- 13.2 Create categories and associate them to VMs
- 13.3 Confirm versions are supported and up-to-date before enablement
- 13.4 Identify resources needed on nodes and Prism Central
- 14.1 Confirm the Network Controller is enabled and the right version
- 14.2 Ensure all clusters are compatible prior to enabling FVN
- 14.3 Set MTU on the virtual switch
- 14.4 Confirm Prism Central has adequate resources for deployment
- 15.1 Identify and take action on incompatible clusters
- 15.2 Determine if the Network Controller can be updated + dependencies
- 15.3 Determine if the FNS version can be upgraded + dependencies
- 16.1 Modify MTU to allow subnet extension / other features
- 16.2 Segregate East-West and North-South traffic
- 16.3 Segregate UVM, management, and/or replication traffic
- 17.1 Recognize which user roles can/cannot create a VPC
- 17.2 Create a custom role
- 17.3 Limit Custom-Admin to specific VPCs
- 17.4 Determine the appropriate system-defined FNS RBAC role for a user
- 17.5 Create an Authorization policy for FNS
- 17.6 Create an FNS RBAC custom role with granular permissions
- 17.7 Determine pre-configured permissions for system-defined FNS RBAC roles
Training
Source corpus mapping
| Document | Primary objectives served |
|---|---|
| ds-ebg-ncp-ns (Exam Blueprint Guide) | Structure / weighting (all) |
| Nutanix-Flow-Virtual-Networking-Guide v6.0 | 1.1, 1.2, 1.3, 3.1, 5.2 |
| Nutanix-Flow-Network-Security-Guide v5.2 | 2.1, 2.2, 2.3, 4.1, 4.2, 4.3, 5.1, 5.5 |
| Prism-Central-Guide vpc_7.3 | 2.2, 3.2, 3.3, 4.2, 4.3, 5.5 |
| Prism-Central-Admin-Center-Guide vpc_2024.2 | 5.2, 5.3 |
| Prism-Central-Alert-Reference vpc_7.3 | 3.2, 3.3, 4.1 |
| Web-Console-Guide-Prism v7.3 | 3.3, 5.4 |
| AHV-Admin-Guide v10.3 | 5.4 |
| Document | Primary objectives served |
|---|---|
| Enabling Jumbo MTU on AHV for UVMs (KB) | 5.4 |
| Life-Cycle-Manager-Guide v3.0 | 5.1, 5.3 |
| Flow-Security-Central-User-Guide | 2.1 |
| TN-2094-Flow | 1.1 |
| Configuration Maximums 5.2.0 (CSV) | 1.2, 2.2, 2.3 |
| Port_Details_List (CSV) | 1.3, 3.1 |
| Nutanix-Clusters-AWS · BP-2202-NC2-AWS-Networking | NC2 networking context (multi) |