NCP-AIN: blueprint map, gaps and a study plan
S6·E4Booking the exam is a design decision · NVIDIA office, end of an enablement day, calendar open on a laptop
Builds on: The triage toolkit: resources, optics and what tcpdump will not tell you, Scenario: 'the fabric is slow and adaptive routing does nothing', Scenario: sizing, quoting and defending a Dell AI pod fabric
Before you read: what do you already know?
3 quick questions. Wrong answers are fine and expected; trying first makes the lesson stick.
After this lesson you can
- State the NCP-AIN exam mechanics and domain weights from the official page and flag the published discrepancy.
- Map each of the 24 blueprint objectives to a lesson in this course as covered, partially covered or not covered.
- Judge which uncovered objectives can be closed by study and which need hardware or a different course.
- Produce a dated study plan built on rebuilding runbooks rather than memorising objective text.
Episode 4 — Booking the exam is a design decision
The Hall C expansion signed this morning. The enablement day is over, the room has emptied, and the last thing said to you was in a briefing room down the corridor, where the NVIDIA PM answered the third-hall question with “not announced” and then asked, off the slide, whether you were certified. Now the certification page is on half your screen and your calendar on the other, and the temptation is to book NCP-AIN four weeks out because the Spectrum material feels close.
Read the page properly first: 120 minutes, 70 to 75 questions, two years of validity, and a recommended-training list where two of the three courses are InfiniBand ones.[1] That list is naming your gap before the domain weights do — and the weights say InfiniBand is 30% of the exam, the same share as Spectrum.[1]
You also note a conflict rather than swallowing it. A regional page describes the exam as roughly 65 questions in 90 minutes, while the page you fetched says otherwise, so you record both with dates and plan to re-check the week you book.[1] It is the habit that kept Hall C honest: cite what you read, name what conflicts, date both.
Certifications exist as a credibility artefact — NVIDIA states the prerequisite as two to three years of operational data-centre experience, so the badge is a claim about hands, not about reading.[1] Which means honest preparation is an audit, not a syllabus.
Book the exam against your gaps, not against your confidence. Segment 1 pins down the mechanics you can verify today.
1The mechanics, verified today
Start with the facts you can check in five minutes, because they are the ones people quote wrongly. The official certification page gives the exam code NCP-AIN, a duration of 120 minutes, 70 to 75 questions, a price of $400, English as the language, validity of two years from issuance, and online remotely proctored delivery.[1] The stated prerequisite is two to three years of operational experience working in a data center with NVIDIA hardware solutions.[1] The page also lists the recommended training: InfiniBand Essentials, InfiniBand Network Administration and Cumulus Linux Essentials.[1]
Two of those three recommended courses are InfiniBand, which tells you something about the blueprint before you read a single objective.
There is one discrepancy worth carrying in your notes. A regional NVIDIA page snippet describes the exam as roughly 65 questions in 90 minutes, while the page fetched for this lesson on 7 September 2026 says 120 minutes and 70 to 75 questions.[1] Prepare against the fetched page, record the conflict with its date, and re-check the mechanics the week you book. That habit is the same one that keeps you honest in front of a customer: cite what you read, name what conflicts, date both.
The domain weights come from the same page: AI Data Center Design and Optimization 5%, NVIDIA Spectrum Networking 30%, NVIDIA InfiniBand Networking 30%, Kubernetes Integration 5%, Troubleshooting Tools 20%, and Automation and Configuration 10%.[1] The exam study guide, document 4417000 dated MAY26, expands each domain into the objective wording used through the rest of this lesson.[2]
- Profile doca-all is "other profiles" in the matrix → Level 2. Every component is in cycle 25 (Oct 2025 → Jul 2026 (3.2 → 3.5)) → supported until the next October GA.
- This is exactly the Spectrum-X validated stack v2.3.1 combination (Sep 2026).
- ⚠ Any FW or mode change on PowerEdge needs a full power cycle, not a warm reboot (Dell KB 000300192; NVIDIA modes page).
Matrix (policy): doca-ofed ↔ FW/BF-FW-Bundle = L1 · doca-ofed ↔ BF-Bundle = L1 · other profiles ↔ FW or BF-Bundle = L2 · DOCA-DPU ↔ BF-FW-Bundle = L2 · DOCA Services ↔ BF-Bundle/FW = L2. source ↗
⚠ = not confirmed on a fetched primary source (hover for why). Facts as of DOCA 3.5.0 (Sep 2026). Selections are saved.
2What this course actually covers
The blueprint has 24 objectives across six domains.[2] Here is the honest map for the domains this course teaches.
NVIDIA Spectrum Networking, 30%. Objective 2.1, configuring Spectrum-X switches for RoCE, is covered fully by the RoCE classification and nv set qos roce lessons, which teach the mode list, the DSCP-to-switch-priority defaults and the buffer pool split.[12] Objective 2.2, enabling and verifying QoS, ECN, PFC, adaptive routing and telemetry, is covered across the PFC and ECN lesson, the RoCE verification playbook, the adaptive routing lesson and the OTLP and HFT lesson.[12][13] Objective 2.3, multi-tenancy BGP-EVPN, is covered by the EVPN tenancy lesson. Objective 2.4, using NVIDIA Air, is covered by the day-0 lesson and by the no-hardware lab of every module.[7] Objectives 2.5 and 2.6, diagnosing congestion or loss with in-band telemetry and WJH and using NetQ for monitoring, are covered by the WJH and NetQ lessons and by the triage toolkit.[5][6] Objective 2.7, installing DOCA, belongs to the DOCA course and is not taught here. Objective 2.8, SuperNIC configuration, is partial: host-side work through mlxconfig, mlxreg and DOCA PCC is covered, but there is no NVIDIA SuperNIC configuration guide in this course’s sources.
Troubleshooting Tools, 20%. Objective 5.1 names cl-resource-query verbatim and is covered fully.[2][4] Objective 5.2, WJH for real-time event analysis, is covered fully.[5] Objective 5.3, verifying low-latency interconnects between GPUs, CPUs and storage, is partial: host RDMA benchmarking appears in the labs, GPU-to-storage validation does not. Objectives 5.4 and 5.5, UFM system health and the ib_* tool family, are not covered.
Automation and Configuration, 10%. Objective 6.1, managing configurations through NVUE templates, maps onto the nv config surface — patch, replace, translate, verify and the revision model — and is covered.[9] Objective 6.2, Ansible playbooks, is partial and depends on the nvidia.nvue collection material being added to the course sources.
3The gaps, stated plainly
Roughly 40% of the exam is outside this course, and pretending otherwise would be the most expensive thing this lesson could do.
| Objective | Domain weight context | Status here | What closes it |
|---|---|---|---|
| 1.2 rail-optimized topologies | part of 5% | Not covered | External research; the notes contain multiplane but no rail-optimized topology definition or scalable-unit numbers |
| 2.7 install NVIDIA DOCA | part of 30% | Not covered here | The DOCA course |
| 2.8 SuperNIC functionality | part of 30% | Partial | Host-side config is covered; no NVIDIA SuperNIC configuration guide in these sources |
| 3.1 IB initial configuration and HA | 30% domain | Not covered | InfiniBand Essentials and InfiniBand Network Administration[1] |
| 3.2 PKeys for IB multi-tenancy | 30% domain | Not covered | Same |
| 3.3 IB QoS and adaptive routing | 30% domain | Not covered | Same |
| 3.4 UFM link and bandwidth monitoring | 30% domain | Not covered | Same |
| 4.1 deploy Network Operator | part of 5% | Partial | The five CRDs, the multiplane matrix and the RA version field are covered; an actual deployment walkthrough is not[10] |
| 4.2 verify Network Operator functionality | part of 5% | Not covered | A Kubernetes cluster with RDMA-capable NICs |
| 5.3 verify low-latency interconnects | part of 20% | Partial | Host RDMA benchmarks are in the labs; GPU-to-storage validation is not |
| 5.4 UFM system health | part of 20% | Not covered | InfiniBand training plus UFM access |
| 5.5 ib_write_lat, ib_write_bw, ibping, ibstat, ibdiagnet, ibnodes, iblinkinfo | part of 20% | Partial | ibstat, ib_write_bw and ib_write_lat run on the Dell lab’s ConnectX and BlueField-3 hosts; the fabric tools need an InfiniBand fabric |
Two of those rows are worth extra attention because they look closable and are not. The InfiniBand domain is a whole discipline — subnet managers, partitioning, UFM — and NVIDIA’s own recommended-training list points at two dedicated courses for it.[1] And objective 4.2 needs a running cluster: the Network Operator page defines the five CRDs that describe a Spectrum-X Kubernetes deployment, including NicConfigurationTemplate with its explicit RA version field, but reading them is not verifying them.[10]
There is also a hardware-shaped gap that no reading closes. In a virtual Cumulus Linux switch, ACLs, ISSU, PTP, port security, SPAN and ERSPAN, QoS including shaping and buffer management and packet marking, WJH, NAT, adaptive routing, storm control, OpenTelemetry and ASIC monitoring are all unsupported, and sensor output is artificial.[8] DSX Air is the sanctioned simulator now that Cumulus VX is no longer released as a standalone image, and it is excellent for the control plane and the command surface — but an exam answer about buffer behaviour has to come from documentation and reasoning, not from something you watched happen in a simulation.[11][7]
4A study plan that survives contact with a work week
The plan below is built on the two things the learning evidence supports most strongly for this kind of material: retrieval practice and spaced, interleaved review. It deliberately does not include re-reading.
Week 1 — audit and consolidate. Complete the 24-objective audit table for yourself, marking covered, partial or not covered with the lesson id. Then rebuild, from a blank NVUE prompt with no notes, three runbooks: enable and verify RoCE end to end; enable and verify adaptive routing including the eligibility rules; and the triage sweep from resources to BER to WJH to netq check.[12][13][4][5][6] Anything you cannot rebuild becomes a flashcard the same day.
Week 2 — the partials. Close the cheap gaps: read the Network Operator Spectrum-X page until you can name the five CRDs and say which one carries the RA version; practise nv config patch, replace, translate and verify against a real revision so objective 6.1 is muscle memory rather than a definition.[10][9] Run ibstat, ib_write_bw and ib_write_lat on the Dell-lab hosts and write down the exact output fields, because those three appear in objective 5.5 and you can actually reach them.[2]
Weeks 3 and 4 — the uncovered domain. InfiniBand, from the two NVIDIA Academy courses named on the certification page, at a fixed number of hours per week rather than “when there is time”.[1] Interleave one Ethernet retrieval session per week so the 60% you already have does not decay while you learn the 30% you do not.
Week 5 — measure. Sit a 70-question, 120-minute mock assembled from the six module checkpoints and weighted to the exam’s own percentages: roughly 21 Spectrum, 21 InfiniBand, 14 troubleshooting, 7 automation and 7 split between AI data centre design and Kubernetes - each is 5%, which is 3.5 questions, so round one to 3 and the other to 4 rather than both to 4.[1] Turn every miss into a flashcard, and turn every high-confidence miss into a runbook rebuild, because a confident wrong answer is a broken mental model rather than a forgotten fact.
Standing rule. Re-check the exam mechanics on the certification page the week you book, and re-check the RA row before you answer any version question, in the exam or on a call.[1][3]
⚠ = not confirmed on a fetched primary source (hover for why). Facts as of DOCA 3.5.0 (Sep 2026). Selections are saved.
5Produce the audit and the plan
The deliverable is two artefacts: an audit table you can defend line by line, and a dated plan with named external material.
Audit, worked rows.
| Objective (verbatim) | Verdict | Lesson id or gap | Evidence for the verdict |
|---|---|---|---|
| 2.1 “Configure NVIDIA Spectrum-X switches for RDMA over Converged Ethernet (RoCE)…” | Covered | spectrumx-m3-01-roce-classification, spectrumx-m3-02-nv-set-qos-roce |
Mode list, DSCP-to-SP defaults, pool split all taught from the 5.18 RoCE page[12] |
| 2.5 “Diagnose congestion or packet loss using in-band telemetry and NVIDIA What Just Happened (WJH) services.” | Covered | spectrumx-m5-01-wjh, spectrumx-m6-01-triage-toolkit |
Channels, triggers, drop filters, the SPAN and NetQ-agent constraints[5] |
| 5.1 “Use tools like cl-resource-query to check resource allocation in Spectrum-X environments.” | Covered | spectrumx-m6-01-triage-toolkit |
Both resource views, the watermark columns and the half-resource-mode interaction[4] |
| 4.1 “Deploy the NVIDIA Network Operator…” | Partial | spectrumx-m4-05-multiplane-isolation |
CRDs and the RA version field are taught; no deployment walkthrough[10] |
| 3.2 “Configure partition keys (PKeys) to ensure secure multi-tenancy in InfiniBand networks.” | Not covered | Gap: InfiniBand domain | No InfiniBand content or hardware in this course[2] |
Plan, worked.
- Gap 1, InfiniBand domain (3.1-3.4, 30%). External: InfiniBand Essentials and InfiniBand Network Administration from the certification page’s recommended list.[1] Schedule: weeks 3-4, six hours per week. Evidence of completion: I can describe subnet-manager election, PKey partitioning and a UFM health workflow without notes.
- Gap 2, UFM and ib_ tools (5.4, 5.5, part of 20%).* Partly closable at home:
ibstat,ib_write_bwandib_write_latrun on the Dell-lab ConnectX and BlueField-3 hosts;ibping,ibnodes,iblinkinfoandibdiagnetneed an InfiniBand fabric, so they are documentation-only and must be marked as such.[2] - Gap 3, Network Operator verification (4.2, part of 5%). Read the five CRDs and the multiplane matrix; mark hands-on verification as not attempted rather than claiming it.[10]
- Gap 4, rail-optimized topologies (1.2). Research task with a deadline, or the objective stays marked not covered.
- Standing checks. Re-fetch the certification page before booking; re-read the current RA row before any version answer.[1][3]
Complete the audit for the objectives below and give each a verdict with its evidence.
| Objective | Verdict | Lesson id or gap | Evidence |
|---|---|---|---|
| 2.2 QoS, ECN, PFC, adaptive routing and telemetry | ______ | ____________________ | ____________________ |
| 2.4 “Use NVIDIA Air to simulate network environments…” | ______ | ____________________ | Air is now ______ Air; note that ____________________ features cannot be exercised in simulation |
| 2.8 SuperNIC functionality | ______ | ____________________ | Host-side config through mlxconfig and mlxreg is taught; missing is ____________________ |
| 5.3 verify low-latency interconnects GPU/CPU/storage | ______ | ____________________ | ____________________ |
| 6.1 NVUE templates | ______ | ____________________ | Maps onto nv config ______, ______, ______ and ______ |
Then write two plan entries in the worked format: one for a gap you can close with reading, and one for a gap that needs hardware you do not have. Each entry needs a schedule and a stated evidence-of-completion.
Do the whole audit, then defend it. Produce a dated coverage audit for all 24 blueprint objectives with covered, partially covered or not covered and a lesson id or a named gap for each. Then produce a study plan covering the uncovered portion, naming for each gap the specific external material that closes it and the evidence you will accept that it is closed.
Finally, write one paragraph you would be willing to say out loud to a Dell SE who asks “so are you certified yet?” — an honest statement of what you can do today, what you are studying, and what you will not claim.
Acceptance criteria. Every “covered” verdict names a lesson and a source, not a feeling. Every “not covered” verdict names the material that closes it and a date. The plan schedules the InfiniBand domain as new material with dedicated hours, not as revision. At least one objective is explicitly marked as documentation-only because the hardware does not exist in your lab. The spoken paragraph contains no claim you could not defend with a citation.
Episode 4 — Case closed: the date on the calendar
The exam goes in five weeks out, not four, because the audit says roughly 40% of the blueprint sits outside this course and the InfiniBand domain is new material with its own tools rather than revision.[2][1] Weeks one and two rebuild runbooks from a blank prompt; weeks three and four are the two InfiniBand courses at fixed hours; week five is one timed mock weighted to the published percentages.[1]
Hall C closes with it. The second pod ships on the RA row you quoted, the network lead starts a second notebook, and the night operator has labelled the new crash cart before it arrives. The standing rule goes on a sticky note: re-check the mechanics the week you book, and the RA row before any version question.[1][3]
Lab
Pre-flight inventory. On the two Dell-lab hosts record: adapter model and firmware (ethtool -i <ifname>), ibstat output including port state and rate, ibv_devinfo for the device attributes, the link type of each port, and the DOCA-Host or OFED version. All steps here are read-only diagnostics; nothing is configured, flashed or reset.
ibstat. Run it on both hosts and record every field: CA name, firmware version, port state, physical state, rate and link layer. Expected: link layer reports Ethernet on a RoCE deployment. Objective 5.5 namesibstat, so know what each field means and which of them changes when a cable is unplugged.[2]ibv_devinfo. Record device capabilities and per-port attributes. Map them onto the RoCE classification you learned in module 3, particularly the GID table and the active MTU.[12]ib_write_bw. Run server and client between the two hosts and record bandwidth, message size and the exact output columns. Expected: line-rate-shaped numbers for large messages. If not: check MTU, GID index and CPU affinity before concluding anything about the fabric.ib_write_lat. Same pair, and record the latency distribution fields the tool prints. Objective 5.3 is about verifying low-latency interconnects, so the fields you can name are the answer surface.[2]- Mark the boundary. Write down explicitly that
ibping,ibnodes,iblinkinfo,ibdiagnetand UFM were studied from documentation only because there is no InfiniBand fabric in this lab. Expected: this line appears in your audit table as evidence, not as a covered verdict.[2] - Optional (customer or partner lab, read-only). If an InfiniBand fabric is available, add
ibping,ibnodes,iblinkinfoandibdiagnetplus a UFM system-health walkthrough, and upgrade those audit rows with the date you ran them. Rollback: none required; all six commands are read-only. Do not runibdiagneton a production fabric without the owner’s agreement, because it generates fabric-wide queries and writes report files.
Goal. Finish the audit, measure yourself once, and leave with a dated plan.
- Audit. Build the 24-row table. For each objective record covered, partially covered or not covered, plus the lesson id or the gap. Expected: the Spectrum, Troubleshooting and Automation domains are mostly covered; the InfiniBand domain is entirely not covered.[2] If not: re-read the objective wording — several objectives look Ethernet-shaped but name UFM or
ib_*tools. - Weighted mock. Assemble a 70-question, 120-minute mock from the six module checkpoints weighted to the exam’s own percentages: roughly 21 Spectrum, 21 InfiniBand, 14 troubleshooting, 7 automation and 7 split between AI data centre design and Kubernetes - each is 5%, which is 3.5 questions, so round one to 3 and the other to 4 rather than both to 4.[1] You will not have 21 InfiniBand items from this course, and that hole is the point: record it as an unanswerable block rather than substituting Ethernet questions.
- Score and convert. Turn every miss into a flashcard the same day. Turn every high-confidence miss into a runbook rebuild rather than a card.
- Rebuild without notes. From a blank DSX Air topology, rebuild the RoCE enablement and verification runbook and the adaptive-routing enablement and verification runbook.[12][13] Expected: the commands parse and the show output confirms your intent. If not: check the release with
nv show system version. State the limit: simulation cannot exercise adaptive routing, QoS buffer behaviour, WJH or ASIC monitoring, so this validates syntax and defaults only.[8] - Dated plan. Write the plan with named external material for every gap, hours per week, and evidence of completion. Put a re-check date on the exam mechanics.[1]
Retrieval check
10 questions from memory. Answer before looking anything up; misses become flashcards.
Explain it to a Dell SE
Explain to a colleague who is also preparing, in five sentences, why finishing this course does not mean you are ready to sit NCP-AIN.
Sources
Facts in this lesson were checked against NVIDIA NCP-AIN certification page re-fetched 2026-09-07 (120 minutes, 70-75 questions, $400, two-year validity, six domains with weights); study guide doc 4417000 MAY26; Cumulus Linux 5.18 and NetQ 5.1 docs. Dates are when each page was fetched.
- NVIDIA-Certified Professional: AI Networking (NCP-AIN) certification page · fetched 2026-09-07
- NVIDIA-Certified Professional: AI Networking Exam Study Guide (doc 4417000, MAY26) · fetched 2026-09-07
- NVIDIA Spectrum-X Validated Solution Stack · fetched 2026-09-07
- Resource Diagnostics | Cumulus Linux 5.18 · fetched 2026-09-07
- What Just Happened (WJH) | Cumulus Linux 5.18 · fetched 2026-09-07
- Validation Tests Reference | Cumulus NetQ 5.1 · fetched 2026-09-07
- NVIDIA DSX Air User Guide · fetched 2026-09-07
- Cumulus Linux in a Virtual Environment | Cumulus Linux 5.18 · fetched 2026-09-07
- NVUE Reference: config commands · fetched 2026-09-07
- NVIDIA Spectrum-X Ethernet Networking Platform | Network Operator 26.4.0 · fetched 2026-09-07
- What's New | Cumulus Linux 5.18 · fetched 2026-09-07
- RDMA over Converged Ethernet - RoCE | Cumulus Linux 5.18 · fetched 2026-09-07
- Equal Cost Multipath Load Sharing (including Adaptive Routing) | Cumulus Linux 5.18 · fetched 2026-09-07
The same idea elsewhere
Other lessons that cover this ground, sometimes from another course's angle.
- NCP-AIN: what this course covers and what it does notRoCE course · Same ground: blueprint, gaps and method
- NCP-AIN: mapping the blueprint and closing the gapsRA course · Same ground: gaps, air and NCP-AIN
- NCP-AIN prep: blueprint, drills and honest gapsInfiniBand course · Same ground: blueprint, gaps and NCP-AIN