Cisco CCNP Data Center 300-620 Practice Test Questions and Exam Dumps Part13 Q241-260

View Full Cisco CCNP Data Center 300-620 Exam Dumps and Practice Test Dumps.

 

Question 241

Which ACI object defines a logical collection of endpoints that share common policy requirements?

  1. Bridge domain
  2. EPG
  3. VRF
  4. L3Out

Correct Answer: 2

Explanation

An Endpoint Group, or EPG, is a logical collection of endpoints that share common policy requirements in Cisco ACI. EPGs can represent application tiers, security zones, or groups of workloads that require similar communication rules. They are commonly organized within an application profile and can communicate with other EPGs through contracts. Bridge domains provide forwarding domains, VRFs provide routing contexts, and L3Out provides external Layer 3 connectivity. EPG design should focus on policy requirements rather than simply physical location. This approach allows administrators to maintain consistent security and connectivity policies even when workloads move between different interfaces or hosts.

Question 242

Which ACI component provides centralized visibility into fabric faults and operational health?

  1. VLAN pool
  2. APIC
  3. Interface selector
  4. Static path binding

Correct Answer: 2

Explanation

The APIC provides centralized visibility into Cisco ACI fabric faults, health information, events, and operational status. Administrators can inspect faults associated with switches, interfaces, endpoints, policies, bridge domains, contracts, and other managed objects. VLAN pools provide encapsulation resources, interface selectors identify physical interfaces, and static path bindings associate EPGs with access paths. APIC health information can help administrators identify affected components and prioritize troubleshooting. When investigating an issue, administrators should examine the specific fault details, severity, timestamp, and affected object rather than relying only on an overall health score. This provides better information for identifying the actual configuration or connectivity problem.

Question 243

Which ACI setting determines whether ARP requests can be flooded within a bridge domain?

  1. ARP flooding
  2. Unicast routing
  3. Endpoint retention
  4. Route control

Correct Answer: 1

Explanation

The ARP flooding setting determines whether ARP requests can be flooded within an ACI bridge domain. This can be useful when an endpoint’s location is not yet known or when an application requires traditional ARP behavior. Unicast routing controls Layer 3 forwarding, endpoint retention affects learned endpoint information, and route control manages external route behavior. When troubleshooting gateway or address-resolution problems, administrators should inspect the bridge-domain subnet, ARP flooding configuration, endpoint learning, and associated VRF. Changing ARP behavior should be done according to application requirements because unnecessary flooding can increase traffic within the fabric.

Question 244

Which ACI routing protocol is a link-state protocol commonly used with L3Out?

  1. BGP
  2. CDP
  3. OSPF
  4. SNMP

Correct Answer: 3

Explanation

OSPF is a link-state routing protocol that can be configured through an ACI L3Out for communication with external routers. It forms neighbor relationships and exchanges link-state information to calculate routes. BGP is a path-vector protocol, while CDP and SNMP are not routing protocols. When configuring OSPF, administrators should verify the correct area, interface addressing, neighbor state, authentication if required, and route-control policies. A functioning OSPF adjacency does not necessarily mean all expected routes are available, so administrators should also inspect route advertisement and import or export behavior. These checks help distinguish routing adjacency problems from policy-related issues.

Question 245

Which ACI object is used to represent an external routed network for policy purposes?

  1. External EPG
  2. Application profile
  3. Physical domain
  4. VLAN pool

Correct Answer: 1

Explanation

An External EPG represents external network destinations connected through an ACI external connection such as an L3Out. External prefixes can be associated with the External EPG, allowing contracts to control communication between internal EPGs and external networks. Application profiles organize internal EPGs, physical domains associate EPGs with physical infrastructure, and VLAN pools provide encapsulation resources. When external connectivity is not working as expected, administrators should verify the External EPG prefixes, L3Out association, routing state, route-control policies, and contract relationships. Correct External EPG configuration is essential for applying ACI policy to north-south traffic.

Question 246

Which ACI feature allows two leaf switches to provide redundant connectivity to a dual-attached endpoint?

  1. L3Out
  2. vPC
  3. VMM domain
  4. L2Out

Correct Answer: 2

Explanation

Virtual Port Channel, or vPC, allows two ACI leaf switches to provide coordinated redundant connectivity to a supported dual-attached endpoint. The endpoint can use links toward both leaf switches while the leaf pair presents a coordinated logical connection. L3Out provides routed external connectivity, VMM domains integrate virtualization platforms, and L2Out provides external Layer 2 connectivity. When troubleshooting a vPC-connected server, administrators should verify both physical links, vPC status, interface policy groups, encapsulation, EPG association, and endpoint learning. Correct vPC configuration improves availability because the endpoint can continue communicating when one access path becomes unavailable.

Question 247

Which ACI object provides a collection of VLAN IDs that can be used by a domain?

  1. VLAN pool
  2. Contract
  3. Filter
  4. VRF

Correct Answer: 1

Explanation

A VLAN pool provides a collection of VLAN IDs or ranges that can be used as encapsulation resources by an associated domain. Physical and VMM domains can reference VLAN pools when EPGs are deployed. Contracts define communication relationships, filters define permitted traffic, and VRFs provide routing contexts. VLAN pools should be planned carefully to prevent conflicts with other network resources. If an EPG cannot deploy with the expected encapsulation, administrators should verify the domain association, VLAN pool configuration, and deployment settings. The available VLAN range must include the encapsulation required by the endpoint or virtualization environment.

Question 248

Which ACI object controls which protocols and ports are allowed by a contract?

  1. VRF
  2. Filter
  3. Bridge domain
  4. Domain

Correct Answer: 2

Explanation

A filter defines the protocols and ports that can be permitted through an ACI contract. Filters are referenced by contract subjects, which form part of the overall communication policy between consumer and provider EPGs. VRFs provide routing contexts, bridge domains provide Layer 2 forwarding domains, and domains associate EPGs with infrastructure. Administrators can use filters to implement precise application policies, such as allowing HTTPS while blocking unnecessary services. When troubleshooting an application connection, administrators should inspect the filter entries, contract subject, consumer/provider relationship, and EPG association to determine whether the required traffic is actually permitted.

Question 249

Which ACI object provides Layer 3 connectivity between the fabric and an external routed network?

  1. L3Out
  2. L2Out
  3. VMM domain
  4. Application profile

Correct Answer: 1

Explanation

An L3Out provides Layer 3 connectivity between the ACI fabric and an external routed network. It can use routing protocols such as OSPF or BGP and includes logical node and interface profiles along with external EPG configuration. L2Out provides Layer 2 external connectivity, VMM domains integrate virtual infrastructure, and application profiles organize internal EPGs. When implementing an L3Out, administrators should verify the associated VRF, logical node profile, logical interface profile, external EPG, external subnets, and routing configuration. These components work together to establish and control communication between internal ACI networks and external routed environments.

Question 250

Which ACI feature controls the behavior of traffic destined for an endpoint that has not been learned?

  1. Route control policy
  2. Unknown unicast behavior
  3. Contract subject
  4. Endpoint retention policy

Correct Answer: 2

Explanation

Unknown unicast behavior controls how ACI handles Layer 2 traffic when the destination endpoint is not present in the fabric’s known endpoint information. Depending on the bridge-domain configuration, the traffic can be flooded or handled according to the configured behavior. Route-control policies manage external routes, contract subjects define communication policy, and endpoint retention policies affect how learned endpoint information is retained. When unexpected flooding occurs, administrators should inspect unknown-unicast settings together with endpoint learning and bridge-domain configuration. The correct setting depends on application requirements and should be selected carefully to avoid unnecessary traffic across the fabric.

Question 251

Which ACI object provides the gateway subnet used by endpoints within a bridge domain?

  1. Contract
  2. Bridge-domain subnet
  3. VLAN pool
  4. Filter

Correct Answer: 2

Explanation

The bridge-domain subnet provides the Layer 3 gateway address used by endpoints in that bridge domain. When unicast routing is enabled, this subnet allows endpoints to communicate with other networks through the bridge domain’s associated VRF. Contracts define communication policy, VLAN pools provide encapsulation resources, and filters define permitted traffic. If endpoints cannot reach their default gateway, administrators should verify the bridge-domain subnet, unicast-routing setting, endpoint attachment, and VRF association. The configured gateway address must also match the network addressing plan. Correct subnet configuration is essential for Layer 3 connectivity from endpoints to remote destinations.

Question 252

Which ACI object is used to organize EPGs according to an application or service?

  1. Application profile
  2. External EPG
  3. Physical domain
  4. Interface selector

Correct Answer: 1

Explanation

An application profile provides a logical container for EPGs associated with an application or service. For example, separate web, application, and database EPGs can be organized within the same application profile. External EPGs represent external destinations, physical domains associate EPGs with physical infrastructure, and interface selectors identify physical interfaces. Application profiles make ACI policy easier to understand and manage because related EPGs can be grouped logically without depending on their physical location. Contracts and filters still determine communication permissions between EPGs. Administrators should design application profiles around meaningful application boundaries and policy requirements.

Question 253

Which ACI feature provides logical routing separation between different tenants?

  1. EPG
  2. VRF
  3. Filter
  4. VLAN pool

Correct Answer: 2

Explanation

A VRF provides logical Layer 3 routing separation between tenants or application environments. Each VRF maintains its own routing context and can isolate routes from other VRFs. Bridge domains are associated with VRFs, allowing their subnets to participate in the appropriate routing table. EPGs group endpoints, filters define traffic rules, and VLAN pools provide VLAN resources. VRF-based separation is important in multi-tenant designs because different tenants can maintain independent routing information. When troubleshooting tenant isolation, administrators should verify bridge-domain associations, external connections, route visibility, and contracts to ensure that the intended separation is maintained.

Question 254

Which ACI object identifies physical interfaces where an interface policy should be deployed?

  1. Contract
  2. Interface selector
  3. External EPG
  4. Route control policy

Correct Answer: 2

Explanation

An interface selector identifies the specific physical interfaces or interface ranges where the configuration associated with an interface profile should be deployed. It forms part of the ACI access-policy hierarchy and works with switch profiles, interface profiles, and interface policy groups. Contracts control communication between EPGs, External EPGs represent external networks, and route-control policies manage route exchange. If a port does not receive the expected access configuration, administrators should inspect the switch profile, interface profile, selector, and policy group. Correct selector configuration ensures that the intended interface policy is applied to the correct physical ports.

Question 255

Which ACI feature provides centralized event logging for troubleshooting fabric operations?

  1. Syslog
  2. BGP
  3. OSPF
  4. VXLAN

Correct Answer: 1

Explanation

Syslog provides centralized collection of event and message information from network devices and services. In an ACI environment, logging can help administrators investigate operational events, configuration changes, warnings, and other messages. BGP and OSPF provide routing functions, while VXLAN provides overlay data-plane encapsulation. When configuring centralized logging, administrators should define appropriate destinations and severity levels and ensure sufficient retention. During troubleshooting, timestamps and event messages can help correlate a problem with configuration changes or network events. Syslog is particularly useful when investigating intermittent conditions that may not be visible from the current operational state alone.

Question 256

Which ACI component provides transit connectivity between leaf switches?

  1. APIC
  2. Spine switch
  3. External EPG
  4. Physical domain

Correct Answer: 2

Explanation

Spine switches provide transit connectivity between leaf switches in the ACI leaf-and-spine architecture. Endpoint traffic normally enters the fabric through a leaf and can traverse one or more spine switches before reaching another leaf. APIC provides centralized management and policy functions, External EPGs represent external network destinations, and physical domains associate EPGs with physical infrastructure. Spine switches are not normally used as endpoint access switches. When troubleshooting inter-leaf communication, administrators should check leaf-to-spine links, fabric membership, interface status, endpoint learning, and relevant fabric health information to determine whether the transit path is operating correctly.

Question 257

Which ACI feature can rapidly detect forwarding failures for supported routing sessions?

  1. CDP
  2. BFD
  3. LLDP
  4. SNMP

Correct Answer: 2

Explanation

Bidirectional Forwarding Detection, or BFD, provides rapid detection of forwarding-path failures and can work with supported routing protocols. It can reduce failure-detection time compared with normal routing protocol timers. CDP and LLDP provide neighbor discovery, while SNMP provides monitoring and management information. When BFD is used, administrators should verify that both endpoints support the feature and that it is correctly associated with the intended routing protocol. Troubleshooting should include checking the BFD session state, underlying interface connectivity, and routing-session status. BFD is useful when rapid detection and convergence are important to application availability.

Question 258

Which ACI object defines a reusable collection of interface configuration behaviors?

  1. Interface policy group
  2. VRF
  3. Bridge domain
  4. External EPG

Correct Answer: 1

Explanation

An interface policy group combines multiple interface policies into a reusable configuration that can be applied to interfaces. It can include policies controlling features such as CDP, LLDP, speed, link aggregation, and other supported interface characteristics. VRFs provide routing contexts, bridge domains provide forwarding domains, and External EPGs represent external networks. Using interface policy groups helps administrators maintain consistent configuration across multiple ports. When troubleshooting an interface, administrators should verify the policy group contents and its relationship with the interface profile and selector. This helps determine whether the expected interface behavior is actually being deployed to the affected port.

Question 259

Which ACI feature allows communication among selected EPGs without creating individual contracts for every pair?

  1. Preferred group
  2. Endpoint retention
  3. L2Out
  4. VLAN pool

Correct Answer: 1

Explanation

Preferred groups can simplify communication between selected EPGs within a VRF by allowing group members to communicate according to the configured preferred-group behavior. This can reduce the number of individual contracts required for certain trusted application environments. Endpoint retention controls learned endpoint information, L2Out provides external Layer 2 connectivity, and VLAN pools provide encapsulation resources. Administrators should carefully define which EPGs belong to the preferred group because the resulting communication scope can be broader than a narrowly defined contract model. Preferred groups are most appropriate when the application requirements justify a common communication policy among the selected EPGs.

Question 260

Which ACI overlay technology encapsulates traffic as it travels between leaf switches?

  1. SNMP
  2. OSPF
  3. VXLAN
  4. CDP

Correct Answer: 3

Explanation

VXLAN is the overlay data-plane technology used to encapsulate endpoint traffic as it travels across the ACI fabric between leaf switches. It allows logical network segmentation to be maintained across the underlying leaf-and-spine infrastructure. SNMP provides monitoring, OSPF provides routing functionality, and CDP provides neighbor discovery. When troubleshooting traffic between endpoints connected to different leaves, administrators should inspect endpoint learning, bridge-domain settings, fabric connectivity, and encapsulation information. Understanding VXLAN helps explain how traffic moves through the fabric while preserving the logical network and policy context assigned to endpoints.