Cisco CCNP Data Center 300-620 Practice Test Questions and Exam Dumps Part2 Q21-40

View Full Cisco CCNP Data Center 300-620 Exam Dumps and Practice Test Dumps.

 

Question 21

Which protocol is used by ACI leaf and spine switches to exchange endpoint and routing information within the fabric?

  1. BGP
  2. OSPF
  3. IS-IS
  4. EIGRP

Correct Answer: 1

Explanation

Cisco ACI uses a combination of protocols and mechanisms internally to build and maintain the fabric. BGP is used as part of the control-plane architecture for exchanging endpoint and routing information between fabric components. The ACI fabric abstracts much of this complexity from administrators through APIC’s policy-based management model. OSPF and EIGRP are traditional routing protocols but are not the primary internal fabric control-plane mechanism in ACI. IS-IS is also not the protocol administrators normally configure for the ACI fabric. Understanding the underlying control plane helps administrators troubleshoot fabric connectivity and forwarding behavior.

Question 22

Which protocol does ACI use as the primary data-plane encapsulation between leaf switches?

  1. VXLAN
  2. GRE
  3. MPLS
  4. IPsec

Correct Answer: 1

Explanation

Cisco ACI uses VXLAN-based encapsulation in its fabric data plane. Traffic entering a leaf can be encapsulated and transported across the spine layer to the destination leaf, where it is decapsulated and delivered to the endpoint. This encapsulation allows ACI to provide scalable forwarding and tenant segmentation across the fabric. GRE, MPLS, and IPsec are different tunneling or encapsulation technologies and are not the primary ACI fabric data-plane mechanism. Administrators generally do not manually configure individual VXLAN tunnels between every leaf and spine because the ACI fabric and APIC automate the required fabric behavior.

Question 23

Which ACI object is used to associate a bridge domain with a routing domain?

  1. Contract
  2. VRF
  3. Filter
  4. Application profile

Correct Answer: 2

Explanation

A VRF provides the Layer 3 routing context for bridge domains in Cisco ACI. A bridge domain is associated with a VRF so that its Layer 3 traffic participates in the appropriate routing domain. This structure allows multiple bridge domains to share a routing context while separate VRFs provide logical isolation. Contracts control communication policy between EPGs, filters define traffic criteria, and application profiles organize EPGs. Administrators should verify the VRF association when troubleshooting routing problems between bridge domains. Incorrect VRF assignments can prevent expected Layer 3 communication even when the underlying physical fabric connectivity is operating normally.

Question 24

What is the primary purpose of an ACI VLAN pool?

  1. To define VLAN IDs that can be allocated to domains
  2. To create APIC users
  3. To define routing protocols
  4. To store endpoint information

Correct Answer: 1

Explanation

A VLAN pool defines a range or collection of VLAN IDs that ACI can allocate for a particular connectivity domain. VLAN pools are commonly associated with physical, external bridged, or virtualization-related domains depending on the deployment design. They help automate VLAN assignment and provide a controlled set of encapsulations that can be used by EPGs. VLAN pools do not define APIC users, routing protocols, or endpoint information. Administrators should ensure that the VLAN ranges are appropriate for the environment and do not conflict with existing network requirements. Correct VLAN pool configuration is an important part of endpoint attachment and domain configuration.

Question 25

Which ACI object associates EPGs with external or virtualization connectivity requirements?

  1. Domain
  2. Contract
  3. Filter
  4. VRF

Correct Answer: 1

Explanation

Domains in Cisco ACI define connectivity information that allows EPGs to be associated with specific physical, external bridged, routed, or virtualization environments. A domain can be associated with a VLAN pool and relevant access policies, depending on the domain type. Contracts control communication between EPGs, filters define traffic conditions, and VRFs provide routing contexts. Correct domain association is essential when binding EPGs to interfaces, virtual machines, or external networks. If an EPG is not associated with an appropriate domain and interface policy configuration, endpoints may fail to establish the expected connectivity even when the EPG and bridge domain themselves are correctly configured.

Question 26

Which ACI domain type is commonly used to connect physical servers directly to leaf switch interfaces?

  1. VMM domain
  2. Physical domain
  3. L3Out domain
  4. Management domain

Correct Answer: 2

Explanation

A physical domain is used to associate ACI endpoint groups with physical infrastructure connected to leaf switch interfaces. It can be associated with a VLAN pool and access policies that define how physical interfaces are configured for endpoint connectivity. A VMM domain is intended for virtualization integration, while L3Out-related configurations support external routed connectivity. Management connectivity is handled through separate management constructs. Physical domains are commonly used for bare-metal servers, appliances, and other physical devices. Administrators must correctly associate the physical domain with the EPG and interface policy group so that endpoints receive the expected VLAN encapsulation and connectivity.

Question 27

Which ACI domain type integrates the fabric with a virtualization platform such as VMware?

  1. Physical domain
  2. VMM domain
  3. L3Out
  4. Bridge domain

Correct Answer: 2

Explanation

A Virtual Machine Manager, or VMM, domain provides integration between ACI and supported virtualization platforms such as VMware. Through VMM integration, APIC can coordinate networking policy with virtual machines and virtual networking constructs. This allows EPGs and other ACI policies to be associated with virtual workloads without treating every virtual machine as a traditional physical interface. A physical domain is designed for physical endpoint connectivity, while L3Out provides routed external connectivity. Bridge domains are Layer 2 forwarding constructs rather than virtualization integration objects. Correct VMM configuration is important for maintaining consistent policy between ACI and the virtualization environment.

Question 28

What is the purpose of an ACI interface policy group?

  1. To group interface-related policies for assignment to ports
  2. To create user authentication rules
  3. To define tenant hierarchy
  4. To store endpoint addresses

Correct Answer: 1

Explanation

An interface policy group combines interface-related policies that can be applied to a particular leaf interface or group of interfaces. Depending on the policy group type, it can include settings such as link-level policies, CDP, LLDP, port channels, and other interface behaviors. This approach simplifies configuration because administrators can create reusable policy combinations instead of configuring every interface independently. Interface policy groups do not define tenants, authentication rules, or endpoint databases. Properly associating policy groups with interface profiles and selectors is essential for endpoint connectivity. A consistent policy-group design also makes large ACI deployments easier to manage and troubleshoot.

Question 29

Which ACI object determines which leaf switch interfaces receive a particular interface policy?

  1. Interface profile
  2. Contract
  3. VRF
  4. Tenant

Correct Answer: 1

Explanation

An interface profile is used to organize interface configuration and can contain interface selectors that identify specific leaf switch interfaces. These selectors can then associate interfaces with interface policy groups. This structure allows administrators to apply consistent interface behavior to selected ports without manually configuring each physical interface. Contracts control endpoint communication, VRFs provide routing contexts, and tenants define administrative boundaries. When troubleshooting interface connectivity, administrators should verify the interface profile, interface selector, policy group, and associated domain configuration. A missing or incorrect association at any of these levels can prevent an endpoint from receiving the expected ACI connectivity.

Question 30

Which ACI policy is commonly used to configure link aggregation between a leaf switch and a connected device?

  1. Port channel policy
  2. DNS policy
  3. AAA policy
  4. Route control policy

Correct Answer: 1

Explanation

A port channel policy is used to define link aggregation behavior for interfaces participating in a port channel. In ACI, interface policy groups can incorporate port channel settings so that multiple physical links operate as a logical connection. Depending on the design, administrators can configure appropriate static or dynamic aggregation behavior. DNS and AAA policies serve different management functions, while route control policies influence routing behavior. Correct port channel configuration is important because mismatched aggregation settings between ACI and the connected device can cause connectivity or link-state problems. Administrators should verify both sides of the connection when troubleshooting port-channel issues.

Question 31

Which protocol can be enabled on ACI interfaces to assist with discovering directly connected Cisco devices?

  1. CDP
  2. FTP
  3. SMTP
  4. NTP

Correct Answer: 1

Explanation

Cisco Discovery Protocol, or CDP, can be enabled on ACI interfaces to provide information about directly connected Cisco devices. CDP can help administrators identify neighboring devices and verify physical connectivity during deployment and troubleshooting. FTP is used for file transfer, SMTP handles email transport, and NTP synchronizes time. Interface policies can be used to control CDP behavior in ACI. Administrators should understand that discovery protocols provide operational information but do not themselves establish endpoint connectivity. Reviewing CDP information can nevertheless be useful when verifying that cables, interfaces, and connected Cisco infrastructure correspond to the intended physical topology.

Question 32

Which protocol can provide neighbor discovery information for multivendor network devices?

  1. CDP
  2. LLDP
  3. HSRP
  4. BFD

Correct Answer: 2

Explanation

Link Layer Discovery Protocol, or LLDP, is a standards-based neighbor discovery protocol that can operate with devices from different vendors. It allows network devices to advertise information such as system identity, port information, and capabilities to directly connected neighbors. CDP provides similar discovery functionality but is Cisco proprietary. HSRP provides gateway redundancy, while BFD detects forwarding failures rapidly. In an ACI environment, LLDP can help administrators validate physical connectivity and identify neighboring infrastructure. Configuring and monitoring LLDP through appropriate interface policies can simplify troubleshooting and provide useful visibility into the fabric’s physical connections.

Question 33

Which ACI policy controls how endpoints are learned and retained after they become inactive?

  1. Endpoint retention policy
  2. Contract filter
  3. VLAN pool
  4. DNS policy

Correct Answer: 1

Explanation

Endpoint retention policies influence how endpoint information is handled when an endpoint becomes inactive or is no longer observed in the fabric. Proper endpoint lifecycle management helps ACI maintain an accurate representation of connected workloads. Contract filters control permitted traffic, VLAN pools provide encapsulation resources, and DNS policies manage name-resolution behavior. Administrators may review endpoint retention behavior when troubleshooting stale endpoint information or unexpected endpoint entries. The exact behavior depends on the configured policy and ACI software version. Understanding endpoint lifecycle settings can help administrators distinguish between actual connectivity problems and endpoint information that remains temporarily visible.

Question 34

Which ACI object defines the subnet and gateway associated with a bridge domain?

  1. EPG
  2. Bridge domain subnet
  3. Contract
  4. Interface profile

Correct Answer: 2

Explanation

A subnet configured under a bridge domain defines the Layer 3 address and gateway information associated with that bridge domain. When Layer 3 routing is enabled, the bridge domain can provide gateway functionality for endpoints connected to the relevant EPGs. EPGs group endpoints, contracts control communication policies, and interface profiles define interface-level configuration. Administrators should ensure that the subnet configuration matches the intended addressing design and does not conflict with other networks. When troubleshooting endpoint gateway problems, checking the bridge domain’s routing settings and subnet configuration is an important step because incorrect values can prevent proper Layer 3 communication.

Question 35

Which ACI component maintains the centralized configuration and policy database for the fabric?

  1. Leaf switch
  2. Spine switch
  3. APIC
  4. Border router

Correct Answer: 3

Explanation

The APIC maintains the centralized management and policy model for the Cisco ACI fabric. It stores and distributes the configuration information that defines tenants, VRFs, bridge domains, EPGs, contracts, domains, and many other policy objects. Leaf and spine switches execute the resulting fabric behavior, while external routers provide connectivity outside the ACI environment. APIC’s centralized policy model allows administrators to manage the fabric consistently rather than configuring each switch independently. In an APIC cluster, controller redundancy provides continued management availability. Administrators should therefore monitor APIC health and cluster status as part of normal ACI operations.

Question 36

Which ACI object is used to represent an external routed connection to another Layer 3 network?

  1. L3Out
  2. EPG
  3. VLAN pool
  4. Application profile

Correct Answer: 1

Explanation

An L3Out represents external Layer 3 connectivity from the ACI fabric to another routed network. It defines the external network connection and can use routing protocols or static routing according to the deployment requirements. L3Out configuration includes components such as external routed nodes, interfaces, logical node profiles, and external endpoint groups. EPGs organize application endpoints, VLAN pools provide VLAN resources, and application profiles organize EPGs. Administrators should carefully configure the routing relationships and external subnets when deploying an L3Out because incorrect external connectivity settings can affect communication between ACI workloads and outside networks.

Question 37

Which routing protocol is commonly supported for dynamic routing over an ACI L3Out?

  1. FTP
  2. OSPF
  3. CDP
  4. LLDP

Correct Answer: 2

Explanation

OSPF can be used as a dynamic routing protocol with an ACI L3Out to exchange routes between the ACI fabric and external Layer 3 networks. ACI supports several external routing options depending on the design and software capabilities. FTP is a file-transfer protocol, while CDP and LLDP are neighbor-discovery protocols. When configuring OSPF through an L3Out, administrators must ensure that the external device and ACI configuration use compatible area, authentication, interface, and network settings. Verifying adjacency and learned routes is important after deployment to confirm that the intended external routing relationship has been established successfully.

Question 38

Which ACI feature can be used to control route advertisement toward an external network?

  1. Route control policy
  2. VLAN pool
  3. Endpoint group
  4. Interface policy group

Correct Answer: 1

Explanation

Route control policies can be used with ACI external connectivity to influence which routes are advertised or accepted. These policies provide additional control over external routing behavior and can help administrators implement requirements such as route filtering or selective advertisement. VLAN pools manage VLAN resources, EPGs group endpoints, and interface policy groups control interface-related behavior. When implementing route control, administrators should carefully evaluate the desired prefixes and direction of policy application. Incorrect route filtering can unintentionally prevent required networks from being advertised or accepted. Testing the resulting routing table and external advertisements is an important validation step.

Question 39

Which ACI feature provides logical separation of routing tables for different tenants or applications?

  1. VRF
  2. Contract
  3. VLAN pool
  4. Interface selector

Correct Answer: 1

Explanation

A VRF provides logical separation of routing information within Cisco ACI. Separate VRFs can maintain independent routing tables so that identical or overlapping IP address spaces can exist in isolated environments when the overall design permits it. Bridge domains are associated with VRFs to participate in the corresponding Layer 3 routing context. Contracts define communication policies between EPGs, VLAN pools manage VLAN allocation, and interface selectors identify physical interfaces. VRFs are therefore fundamental to tenant and application isolation. Administrators should verify VRF associations carefully when troubleshooting routing because an incorrect routing context can prevent otherwise reachable networks from communicating.

Question 40

Which ACI object is responsible for organizing multiple EPGs that represent components of an application?

  1. Bridge domain
  2. Application profile
  3. VLAN pool
  4. Contract filter

Correct Answer: 2

Explanation

An application profile organizes endpoint groups that represent different components or tiers of an application. For example, an application profile may contain web, application, and database EPGs. Contracts can then define which communication is allowed between those EPGs. A bridge domain provides a Layer 2 forwarding domain, a VLAN pool defines available VLAN encapsulations, and a contract filter specifies traffic characteristics. Application profiles help administrators structure ACI policies around application requirements rather than simply physical network locations. This organization also makes policy administration easier because related EPGs and their communication relationships can be managed within a clear application-oriented hierarchy.