A financial services company is deploying a new Nutanix cluster and must comply with a strict security policy that requires all management traffic to be isolated. The administrator has already configured a separate VLAN for the CVMs and hypervisor hosts. Which additional step is crucial for securing the remote management interface of the nodes?
Answer and explanation
Correct answer: B
The IPMI/BMC interface provides out-of-band management capabilities, including remote power control and console access. Placing it on the same VLAN as CVMs or user traffic creates a security risk. Best practice dictates that IPMI/BMC ports should be configured on a completely separate, isolated, and secured management VLAN to prevent unauthorized access to the physical hardware layer.
Question 2
Multiple answers
During a routine health check, an administrator notices that the cluster's metadata disk usage is consistently high. Which TWO actions can help mitigate this issue? (Select TWO)
Answer and explanation
Correct answers: B, E
Each VM snapshot creates a significant amount of metadata. A large accumulation of snapshots is a primary cause of high metadata disk usage. Deleting them reduces the metadata footprint. Adding nodes with larger SSDs expands the total metadata capacity across the cluster, providing a long-term solution to accommodate growth.
Question 3
True or False: When creating a VM template from a VM on an AHV cluster, the source VM must be powered off to ensure data consistency.
Answer and explanation
Correct answer: A
This statement is true. To create a VM template, which is a deployable base image, the source virtual machine must be in a powered-off state. This ensures that the file system is static, in-memory data is flushed to disk, and the resulting template is application-consistent.
Question 4
An administrator is tasked with performing a one-click upgrade of the AOS software on a production cluster. They have successfully run the latest Nutanix Cluster Check (NCC) and resolved all failures. What is the next step the Life Cycle Manager (LCM) will perform after the administrator initiates the upgrade?
Answer and explanation
Correct answer: A
The LCM orchestrates a rolling upgrade to maintain cluster availability. After pre-upgrade checks, it selects one CVM, places it into maintenance mode, upgrades the AOS on that node, and then restarts the CVM. Once the CVM is back online and stable, LCM proceeds to the next node in the cluster, repeating the process until all nodes are upgraded.
Question 5
Case Study:
A mid-sized healthcare provider, HealthForward, runs its electronic health record (EHR) system on a 5-node Nutanix AHV cluster. Due to regulatory compliance (HIPAA), all patient data must be encrypted at rest. The security team has mandated the use of an external Key Management Server (KMS) that is already deployed in their datacenter. The cluster currently uses self-encrypting drives (SEDs), but software-based encryption was not enabled during the initial deployment.
The systems administrator is now tasked with enabling data-at-rest encryption on the existing cluster to meet the new compliance requirement. The primary goals are to ensure all existing and future data is encrypted, integrate with the corporate KMS, and minimize disruption to the live EHR application. The administrator has already verified network connectivity between the CVMs and the external KMS.
What is the correct high-level process for the administrator to enable data-at-rest encryption on this cluster?
Answer and explanation
Correct answer: B
Nutanix data-at-rest encryption can be enabled on a live cluster. The process is performed online without requiring downtime. After configuring the external KMS in Prism Element, the Distributed Storage Fabric (DSF) initiates a background process that re-encrypts all existing data. This is a rolling process that manages I/O to minimize performance impact on running applications like the EHR system.
Question 6
An administrator manages a multi-cluster Nutanix environment using Prism Central. They need to ensure that a specific critical software image (e.g., a golden image for a database server) is available across three different clusters, but not on a fourth development cluster. Which Prism Central feature should be used to achieve this?
Answer and explanation
Correct answer: B
Image Placement Policies in Prism Central are designed specifically for this purpose. They allow an administrator to control how images are distributed across multiple registered clusters. By creating a policy and selecting the desired clusters, Prism Central will automatically replicate and maintain the specified image on only those clusters, ensuring consistency and availability where needed.
Question 7
An administrator is reviewing the hardware health of a Nutanix cluster from the Prism Element dashboard and notices a red alert indicating a disk failure on one of the nodes. The cluster is configured with Replication Factor 2 (RF2). What is the immediate status of the data that was on the failed disk?
Answer and explanation
Correct answer: C
With RF2, the Nutanix Distributed Storage Fabric (DSF) maintains two copies of all data on different nodes/disks. When one disk fails, the data remains fully accessible from its replica. DSF will then automatically start a rebuild process to create a new replica on another healthy disk to restore the cluster to full resiliency.
Question 8
A new administrator joins an IT team and needs to understand the basic architecture of the Nutanix storage system. Which component is responsible for presenting storage to the hypervisor as a central pool of resources aggregated from all nodes in the cluster?
Answer and explanation
Correct answer: D
The Distributed Storage Fabric (DSF) is the core component of the Nutanix platform that aggregates the local storage (SSDs, HDDs) from all nodes into a single, cluster-wide storage pool. It presents this pool to the hypervisor (like AHV or ESXi) via standard protocols (iSCSI or NFS), making it appear as a centralized SAN, but with the benefits of data locality and distributed performance.
Question 9
What is the primary function of Nutanix Pulse?
Answer and explanation
Correct answer: C
Nutanix Pulse is the telemetry service that, when enabled, automatically and securely sends system-level diagnostic information (like health status, system alerts, and configuration data) to Nutanix Support. This allows for proactive support, faster case resolution, and automated analysis of cluster health without manual intervention.
Question 10
An administrator needs to deploy a new virtual machine that will host a file server. To simplify future management and policy application, the administrator wants to group this VM with other infrastructure-related VMs. Which Nutanix construct should be used to logically group these VMs?
Answer and explanation
Correct answer: C
Categories in Prism Central provide a flexible way to logically group entities like VMs using a key-value pair system (e.g., Department: IT, Environment: Production). Once a VM is assigned to a category, policies for security (Flow), data protection, and image placement can be applied to the entire category, simplifying management at scale.