Cisco CCNP Data Center 300-620 Practice Test Questions and Exam Dumps Part14 Q261-280

View Full Cisco CCNP Data Center 300-620 Exam Dumps and Practice Test Dumps.

 

Question 261

Which ACI component is responsible for discovering and bringing new fabric switches into the managed topology?

  1. VLAN pool
  2. Contract
  3. External EPG
  4. APIC

Correct Answer: 4

Explanation

APIC plays a central role in fabric discovery and onboarding. During fabric initialization, switches establish connectivity with the controller infrastructure and can be identified, assigned node IDs, and incorporated into the managed ACI fabric. VLAN pools provide encapsulation resources, contracts define communication policy, and External EPGs represent external destinations. Administrators should verify fabric membership, node IDs, controller connectivity, and switch status when a newly connected switch does not appear correctly in APIC. Proper discovery ensures that the switch becomes part of the intended fabric topology and receives the policies required for normal ACI operation.

Question 262

Which ACI object determines the Layer 3 routing context associated with a bridge domain?

  1. VRF
  2. Filter
  3. VLAN pool
  4. Contract

Correct Answer: 1

Explanation

A VRF determines the Layer 3 routing context associated with an ACI bridge domain. The bridge domain’s subnet participates in the routing table of its associated VRF, providing logical routing separation from other VRFs. Filters define permitted traffic characteristics, VLAN pools provide VLAN encapsulation resources, and contracts establish communication relationships. When troubleshooting routing between bridge domains, administrators should verify that both bridge domains belong to the intended VRF and that unicast routing and subnet configurations are correct. Proper VRF association is essential for maintaining tenant isolation and ensuring that routes are visible only within the appropriate routing context.

Question 263

Which ACI object can contain multiple filter entries that specify allowed protocols and ports?

  1. Application profile
  2. Bridge domain
  3. Contract subject
  4. VLAN pool

Correct Answer: 3

Explanation

A contract subject can reference filters that contain the specific protocols and ports permitted by the communication policy. The subject connects the contract to the relevant filter rules and therefore forms an important part of the ACI policy chain. Application profiles organize EPGs, bridge domains provide forwarding domains, and VLAN pools provide encapsulation resources. When troubleshooting contract-based communication, administrators should verify the subject, associated filters, consumer and provider EPGs, and contract scope. A correctly configured subject ensures that the intended filter rules are actually applied to the communication relationship between the participating EPGs.

Question 264

Which ACI policy is used to define how a physical interface behaves regarding features such as CDP and LLDP?

  1. Bridge-domain policy
  2. Interface policy
  3. Contract policy
  4. Route control policy

Correct Answer: 2

Explanation

An interface policy defines individual characteristics of a physical interface, including supported settings for protocols such as CDP and LLDP. These policies can be combined within an interface policy group and applied to selected ports through the ACI access-policy hierarchy. Bridge-domain policies control forwarding behavior, contract policies control communication relationships, and route-control policies manage external route behavior. When an interface does not behave as expected, administrators should inspect the interface policy, policy group, interface profile, and selector. This layered structure allows consistent interface configuration across many ports while keeping individual policy components reusable.

Question 265

Which ACI feature can be used to prevent direct endpoint-to-endpoint communication within the same EPG?

  1. Intra-EPG isolation
  2. Route control
  3. L3Out
  4. VMM domain

Correct Answer: 1

Explanation

Intra-EPG isolation prevents direct communication between endpoints that belong to the same EPG. This can be useful when workloads share similar policy characteristics but must remain isolated from one another for security or application reasons. Route-control policies manage external routes, L3Out provides routed external connectivity, and VMM domains integrate virtualization environments. Administrators should carefully evaluate application dependencies before enabling intra-EPG isolation because some services require direct communication between members of the same EPG. If unexpected connectivity exists between endpoints in one EPG, reviewing the isolation setting and endpoint policy is an important troubleshooting step.

Question 266

Which routing protocol can be configured on an ACI L3Out to exchange routes with an external autonomous system?

  1. LLDP
  2. OSPF
  3. BGP
  4. CDP

Correct Answer: 3

Explanation

BGP can be configured through an ACI L3Out to exchange routes with external autonomous systems. It uses autonomous system numbers and provides extensive policy controls for route advertisement and selection. OSPF is an interior link-state routing protocol, while LLDP and CDP provide neighbor-discovery functions. When configuring BGP, administrators should verify the local and remote AS numbers, peer IP addresses, interface reachability, session status, and route-control policies. Even when the BGP session is established, expected prefixes may not appear because of route filtering or policy configuration. Therefore, both session state and route exchange should be checked.

Question 267

Which ACI feature associates an EPG with a supported virtualization management platform?

  1. Physical domain
  2. VLAN pool
  3. VMM domain
  4. L2Out

Correct Answer: 3

Explanation

A VMM domain integrates an ACI EPG with a supported virtualization environment. It allows network policy to be associated with virtual workloads and provides the required connectivity between ACI and the virtualization management infrastructure. A physical domain is used for physical endpoint environments, a VLAN pool provides encapsulation resources, and L2Out provides external Layer 2 connectivity. When a virtual workload does not receive the expected network configuration, administrators should verify the VMM domain association, virtualization controller connectivity, VLAN or encapsulation configuration, EPG association, and related access policies. Correct VMM integration allows policy to follow virtual workloads across supported infrastructure.

Question 268

Which ACI object provides external Layer 2 connectivity from a bridge domain to another Layer 2 network?

  1. L3Out
  2. L2Out
  3. VMM domain
  4. External EPG

Correct Answer: 2

Explanation

L2Out provides external Layer 2 connectivity between an ACI bridge-domain environment and an external Layer 2 network. It is different from L3Out, which provides routed Layer 3 connectivity. A VMM domain integrates virtualization platforms, while an External EPG represents external network destinations for policy purposes. When implementing L2Out, administrators should verify the external interface, VLAN encapsulation, bridge-domain association, and related policy settings. Troubleshooting should also include physical interface status and endpoint learning. Correct L2Out configuration allows Layer 2 traffic to cross the ACI boundary while maintaining the intended VLAN and forwarding behavior.

Question 269

Which ACI feature controls how long learned endpoint information is retained after an endpoint becomes inactive?

  1. Endpoint retention policy
  2. Contract subject
  3. VLAN pool
  4. Interface selector

Correct Answer: 1

Explanation

The endpoint retention policy determines how ACI handles learned endpoint information after an endpoint becomes inactive. It helps control whether information remains available for a configured period before being removed or treated differently. Contract subjects organize communication rules, VLAN pools provide encapsulation resources, and interface selectors identify physical interfaces. Endpoint retention can be important in environments where endpoints frequently disconnect or move. When troubleshooting stale endpoint information, administrators should inspect the current endpoint state, retention policy, interface attachment, and learning behavior. This helps determine whether an apparent connectivity issue is related to stale information or another access-policy problem.

Question 270

Which ACI object provides the Layer 3 gateway address for endpoints in a bridge domain?

  1. Contract
  2. External EPG
  3. Bridge-domain subnet
  4. VLAN pool

Correct Answer: 3

Explanation

The bridge-domain subnet provides the gateway address used by endpoints within an ACI bridge domain. When unicast routing is enabled, this subnet allows endpoints to communicate with other routed networks through the bridge domain’s associated VRF. Contracts define communication policy, External EPGs represent external destinations, and VLAN pools provide encapsulation resources. If endpoints cannot reach their default gateway, administrators should verify the subnet configuration, unicast-routing setting, VRF association, endpoint attachment, and addressing scheme. A correctly configured gateway subnet is necessary for Layer 3 communication and provides the first routing hop for endpoints within the bridge domain.

Question 271

Which ACI management method uses a dedicated management network separate from the production fabric?

  1. In-band management
  2. VXLAN management
  3. Out-of-band management
  4. EPG management

Correct Answer: 4

Explanation

Out-of-band management uses dedicated management connectivity that is separate from the production data path. This approach can provide management access even when production fabric forwarding has problems. In-band management instead uses the ACI fabric and associated network infrastructure. VXLAN is an overlay data-plane technology, and EPG management is not a separate management transport. When designing out-of-band management, administrators should verify management interfaces, addressing, routing, and access controls. The separation can be particularly useful for troubleshooting because administrators may retain access to management functions even when production traffic or policy configuration is experiencing an outage.

Question 272

Which ACI object provides a logical container for external prefixes associated with an L3Out?

  1. External EPG
  2. VRF
  3. Application profile
  4. Physical domain

Correct Answer: 1

Explanation

An External EPG provides a logical policy container for external network prefixes associated with an L3Out. External subnets can be associated with the External EPG and then used in contract relationships with internal EPGs. A VRF provides the routing context, an application profile organizes internal EPGs, and a physical domain associates EPGs with physical infrastructure. External EPGs are important for applying policy to north-south traffic. When external communication fails, administrators should verify the External EPG prefixes, L3Out association, routing state, route-control policies, and contracts. These components collectively determine whether external traffic is correctly classified and permitted.

Question 273

Which ACI object defines the logical relationship between a consumer EPG and a provider EPG?

  1. VLAN pool
  2. Interface profile
  3. Contract
  4. Bridge domain

Correct Answer: 3

Explanation

A contract defines the logical communication relationship between a consumer EPG and a provider EPG. The contract can contain subjects that reference filters, allowing administrators to specify which protocols and ports are permitted. VLAN pools provide encapsulation resources, interface profiles organize access-policy configuration, and bridge domains provide forwarding domains. Contracts form a central part of the ACI application-centric security model. If communication between two EPGs is not working, administrators should verify both the consumer and provider assignments, contract association, subject configuration, filter entries, and relevant VRF and bridge-domain settings.

Question 274

Which ACI component provides centralized monitoring of faults, events, and health information?

  1. VLAN pool
  2. APIC
  3. Interface selector
  4. Static path binding

Correct Answer: 4

Explanation

APIC provides centralized monitoring and management of faults, events, health information, and configuration across the ACI fabric. Administrators can use APIC to inspect faults affecting switches, interfaces, EPGs, contracts, bridge domains, and other managed objects. VLAN pools provide encapsulation resources, interface selectors identify physical interfaces, and static path bindings associate EPGs with endpoint access paths. When investigating a problem, administrators should inspect the specific fault details and affected object rather than relying only on a general health indicator. APIC’s centralized visibility makes it easier to correlate related problems across multiple components of the fabric.

Question 275

Which ACI feature allows a common contract relationship to apply across multiple EPGs within a VRF?

  1. Static path binding
  2. Preferred group
  3. vzAny
  4. Endpoint retention

Correct Answer: 3

Explanation

vzAny represents all EPGs within a VRF for contract relationships and can simplify policies that need to apply broadly across multiple EPGs. It can reduce the need to create many individual contract relationships when the same policy should apply across a larger set of EPGs. Static path binding controls endpoint attachment, preferred groups provide another method of managing selected EPG communication, and endpoint retention controls learned endpoint information. Because vzAny can have a broad scope, administrators should carefully review its associated contracts and ensure that the resulting communication is appropriate for every affected EPG.

Question 276

Which ACI architecture layer provides high-speed transit between leaf switches?

  1. Spine
  2. Leaf
  3. APIC
  4. External network

Correct Answer: 4

Explanation

Spine switches provide the high-speed transit layer between leaf switches in the Cisco ACI architecture. Leaf switches connect to endpoints and forward traffic into the fabric, while spine switches provide the paths between leaf nodes. APIC provides management and policy functions rather than normal endpoint traffic forwarding. External networks provide connectivity beyond the fabric and are not part of the internal spine layer. When troubleshooting communication between endpoints attached to different leaves, administrators should verify the leaf-to-spine links, fabric membership, interface status, and endpoint information. A healthy spine layer is essential for reliable inter-leaf forwarding across the ACI fabric.

Question 277

Which ACI object is used to select the specific leaf interfaces where an interface policy group is applied?

  1. Contract
  2. Interface selector
  3. External EPG
  4. VRF

Correct Answer: 2

Explanation

An interface selector identifies the specific leaf interfaces or interface ranges where the configuration associated with an interface profile should be applied. It is part of the ACI access-policy hierarchy and works with switch profiles, interface profiles, and interface policy groups. Contracts control communication between EPGs, External EPGs represent external destinations, and VRFs provide routing contexts. If a physical port does not receive the expected policy, administrators should inspect the interface selector and verify its association with the correct interface profile and policy group. This ensures that interface settings are deployed to the intended physical ports.

Question 278

Which ACI data-plane technology encapsulates endpoint traffic across the leaf-and-spine fabric?

  1. BGP
  2. OSPF
  3. VXLAN
  4. CDP

Correct Answer: 3

Explanation

VXLAN provides the overlay data-plane encapsulation used to carry endpoint traffic across the ACI leaf-and-spine fabric. It allows logical network segmentation and endpoint information to be transported across the underlying infrastructure. BGP and OSPF provide routing functions, while CDP provides neighbor discovery. When troubleshooting inter-leaf communication, administrators can examine endpoint learning, fabric connectivity, bridge-domain settings, and encapsulation information. VXLAN allows traffic from endpoints connected to different leaves to traverse the fabric while preserving the logical context required for forwarding and policy enforcement. Understanding the overlay is useful when analyzing packet paths and connectivity problems.

Question 279

Which ACI feature determines whether a bridge domain provides Layer 3 forwarding?

  1. Unicast routing
  2. ARP flooding
  3. Unknown unicast
  4. Endpoint retention

Correct Answer: 1

Explanation

The unicast routing setting determines whether a bridge domain provides Layer 3 forwarding functionality. When enabled and combined with a configured subnet, the bridge domain can provide a gateway for endpoints and participate in routing through its associated VRF. ARP flooding controls ARP request handling, unknown-unicast settings control unresolved Layer 2 destinations, and endpoint retention manages learned endpoint information. If endpoints can communicate locally but cannot reach remote networks, administrators should verify unicast routing, the bridge-domain subnet, VRF association, and endpoint gateway configuration. These settings collectively determine whether Layer 3 forwarding is available for the bridge domain.

Question 280

Which ACI protocol provides vendor-neutral discovery information about directly connected devices?

  1. BGP
  2. LLDP
  3. OSPF
  4. SNMP

Correct Answer: 2

Explanation

LLDP is a vendor-neutral neighbor-discovery protocol that exchanges information between directly connected devices. It can provide details such as device identity, interface information, and capabilities and is particularly useful in multi-vendor environments. BGP and OSPF are routing protocols, while SNMP provides management and monitoring information. In an ACI fabric, LLDP can help administrators validate the physical topology and confirm whether the expected device is connected to an interface. During troubleshooting, LLDP information can be compared with interface status, access-policy configuration, and cabling information to identify unexpected or incorrect physical connections.