Cisco CCNP Data Center 300-620 Practice Test Questions and Exam Dumps Part15 Q281-300

View Full Cisco CCNP Data Center 300-620 Exam Dumps and Practice Test Dumps.

 

Question 281

Which ACI policy object associates an EPG with a collection of access policies that define its connectivity requirements?

  1. Contract
  2. Domain
  3. Filter
  4. Route control policy

Correct Answer: 2

Explanation

An ACI domain associates an EPG with the infrastructure connectivity requirements needed for endpoint attachment. Depending on the environment, this can be a physical domain or a VMM domain. The domain is associated with resources such as VLAN pools and provides the relationship between logical policy and physical or virtual connectivity. Contracts define communication rules, filters specify traffic characteristics, and route-control policies influence external routing. When an EPG cannot be deployed to an expected port or virtualization environment, administrators should verify its domain association, VLAN pool configuration, and relevant access policies. Correct domain configuration is essential for successful endpoint deployment.

Question 282

Which ACI feature allows an administrator to immediately deploy an EPG configuration to a leaf when the policy is resolved?

  1. Resolution immediacy
  2. Endpoint retention
  3. Deployment immediacy
  4. Preferred group

Correct Answer: 4

Explanation

Deployment immediacy controls when an EPG policy is programmed on the leaf switches after the policy is resolved. It determines whether configuration is pushed immediately or based on endpoint-related events and other deployment conditions. Resolution immediacy addresses how quickly the system resolves the policy dependencies required for deployment. Endpoint retention controls learned endpoint information, while preferred groups influence communication policy. Understanding these settings is important when troubleshooting why an EPG configuration does not appear on a leaf immediately. Administrators should review both resolution and deployment immediacy when analyzing policy installation behavior and endpoint connectivity.

Question 283

Which ACI component defines the collection of interfaces and interface policies associated with a leaf switch?

  1. Switch profile
  2. Contract
  3. External EPG
  4. Bridge domain

Correct Answer: 3

Explanation

A switch profile is used within the ACI access-policy model to associate configuration with one or more leaf switches. It works with interface profiles and selectors to determine which interfaces receive specific policies. Contracts control endpoint communication, External EPGs represent external destinations, and bridge domains provide Layer 2 forwarding and gateway functions. When administrators need to apply consistent interface-related configuration to multiple leaf switches, switch profiles provide the appropriate organizational structure. Troubleshooting should include checking the switch profile association, interface profiles, selectors, and policy groups to ensure the intended configuration reaches the correct physical interfaces.

Question 284

Which ACI feature allows administrators to assign an EPG to a specific VLAN encapsulation on a physical interface?

  1. Static path binding
  2. Route control
  3. vzAny
  4. Contract subject

Correct Answer: 1

Explanation

Static path binding allows an EPG to be explicitly associated with a specific physical path and VLAN encapsulation. This is commonly used when connecting bare-metal servers or other physical devices that require a defined VLAN on an ACI leaf interface. Route control manages external routing information, vzAny represents EPGs within a VRF for policy relationships, and contract subjects define filter-based communication rules. When configuring static path binding, administrators should verify the leaf path, interface, encapsulation VLAN, domain association, and deployment settings. Incorrect encapsulation or path selection can prevent an endpoint from obtaining the expected network connectivity.

Question 285

Which ACI setting controls whether ARP requests are flooded within a bridge domain?

  1. Unicast routing
  2. Endpoint retention
  3. ARP flooding
  4. Route control

Correct Answer: 4

Explanation

ARP flooding controls how ARP requests are handled within an ACI bridge domain. When enabled, ARP requests can be flooded according to the bridge-domain behavior, which may be necessary for applications or environments that rely on traditional Layer 2 ARP discovery. Unicast routing controls Layer 3 forwarding, endpoint retention manages learned endpoint information, and route control influences external route advertisement or learning. Administrators should understand the application’s ARP requirements before changing this setting. When hosts cannot resolve neighboring IP addresses, reviewing ARP flooding, endpoint learning, subnet configuration, and bridge-domain settings can help identify the cause.

Question 286

Which ACI object is used to define a set of IP prefixes that are permitted or advertised through an L3Out?

  1. VLAN pool
  2. Route control policy
  3. Interface policy group
  4. VMM domain

Correct Answer: 2

Explanation

A route control policy can be used to influence which routes are imported into or exported from an ACI L3Out. It provides policy-based control over external route advertisement and learning. VLAN pools provide encapsulation resources, interface policy groups define interface behavior, and VMM domains integrate virtualization platforms. Route-control policies are particularly useful when an external routing domain should receive only selected prefixes or when specific learned routes need to be filtered. During troubleshooting, administrators should examine route-control profiles, route maps, match criteria, actions, and the association between the policy and the relevant L3Out configuration.

Question 287

Which ACI component provides a logical representation of an external Layer 3 routing connection?

  1. L3Out
  2. Application profile
  3. VLAN pool
  4. Interface selector

Correct Answer: 1

Explanation

An L3Out provides the logical representation of external Layer 3 connectivity from an ACI fabric. It includes components such as a logical node profile, logical interface profile, routing configuration, and External EPGs. Application profiles organize internal EPGs, VLAN pools provide encapsulation resources, and interface selectors identify physical interfaces for access policies. When configuring external routed connectivity, administrators should verify the L3Out’s VRF association, node and interface profiles, routing protocol settings, external subnets, and route-control policies. Correct L3Out configuration enables ACI endpoints to communicate with external routed networks while maintaining policy-based control.

Question 288

Which ACI object organizes multiple EPGs that belong to the same application?

  1. VRF
  2. Application profile
  3. VLAN pool
  4. Physical domain

Correct Answer: 3

Explanation

An application profile provides a logical container for multiple EPGs that represent application tiers or related workloads. For example, an application profile might contain web, application, and database EPGs. Contracts can then define communication between those EPGs. A VRF provides the routing context, VLAN pools provide encapsulation resources, and physical domains associate EPGs with physical infrastructure. Organizing EPGs through application profiles helps administrators maintain an application-centric policy structure. It also simplifies management because related EPGs can be viewed and configured together while still retaining individual endpoint and security policies.

Question 289

Which ACI component is responsible for defining the physical leaf and interface path where an EPG is attached?

  1. External EPG
  2. Contract
  3. Static path binding
  4. VRF

Correct Answer: 3

Explanation

Static path binding defines the physical leaf and interface path where an EPG is attached. It can also specify the VLAN encapsulation used for the endpoint connection. This is particularly useful for physical servers and other bare-metal devices that do not use a virtualization integration. External EPGs represent external networks, contracts define communication relationships, and VRFs provide routing separation. When a physical endpoint does not receive the expected policy, administrators should verify the static path, encapsulation, domain association, interface policy, and deployment status. Accurate path binding ensures that the EPG policy is applied to the intended physical connection.

Question 290

Which protocol is commonly used by ACI L3Out to exchange link-state routing information with an external routing domain?

  1. CDP
  2. BGP
  3. OSPF
  4. LLDP

Correct Answer: 4

Explanation

OSPF is a link-state routing protocol that can be configured through an ACI L3Out to exchange routing information with an external routing domain. It uses areas, neighbors, and link-state information to build a routing topology. BGP is another routing option but uses a different path-vector model and autonomous-system relationships. CDP and LLDP are neighbor-discovery protocols rather than routing protocols. When troubleshooting OSPF through an L3Out, administrators should verify interface addressing, area configuration, neighbor state, authentication if configured, and route-control policies. A functioning adjacency alone does not guarantee that the desired routes are being exchanged.

Question 291

Which ACI object represents an external network destination that can participate in contract relationships?

  1. External EPG
  2. VLAN pool
  3. Interface profile
  4. Bridge domain

Correct Answer: 1

Explanation

An External EPG represents external network destinations connected through an L3Out or related external connectivity configuration. External subnets can be associated with the External EPG and then participate in contract-based policy relationships with internal EPGs. VLAN pools provide encapsulation resources, interface profiles organize interface policies, and bridge domains provide internal Layer 2 forwarding. External EPGs are therefore an important component of ACI north-south security policy. When external traffic is unexpectedly denied, administrators should check the External EPG subnet definitions, contracts, filters, L3Out configuration, and route-control policies to identify where the policy chain is failing.

Question 292

Which ACI technology provides the physical connection point for servers and network devices attached to leaf switches?

  1. Spine switch
  2. Leaf switch
  3. APIC cluster
  4. External router

Correct Answer: 2

Explanation

Leaf switches provide the physical connection point for servers, appliances, and other network devices attached to an ACI fabric. They enforce endpoint-related policies and forward traffic into the spine layer when communication must traverse the fabric. Spine switches primarily provide transit between leaf switches, APIC provides centralized management and policy functions, and external routers connect the fabric to outside routing domains. When an endpoint cannot connect, administrators should first examine the leaf interface, access-policy configuration, EPG attachment, VLAN encapsulation, and endpoint learning state. Correct leaf configuration is fundamental to endpoint connectivity within an ACI deployment.

Question 293

Which ACI feature provides a security policy that can be applied between EPGs without requiring direct endpoint-specific ACL configuration?

  1. Contract
  2. VLAN pool
  3. Interface selector
  4. Switch profile

Correct Answer: 3

Explanation

Contracts provide policy-based communication control between EPGs without requiring administrators to configure individual endpoint ACLs. A contract can contain subjects and filters that specify permitted protocols and ports. VLAN pools provide encapsulation resources, interface selectors identify interfaces, and switch profiles organize access-policy configuration. This EPG-centric approach allows security policies to follow workloads as their locations change within the fabric. When communication between EPGs is denied, administrators should verify consumer and provider relationships, contract association, subjects, filters, and the relevant VRF. This layered model provides centralized and reusable security policy throughout the ACI environment.

Question 294

Which ACI access-policy object groups multiple interface policies into a reusable configuration applied to an interface?

  1. External EPG
  2. Interface policy group
  3. Bridge domain
  4. Route control profile

Correct Answer: 1

Explanation

An interface policy group groups multiple interface policies into a reusable configuration that can be applied to physical interfaces. Depending on the design, it can contain policies for CDP, LLDP, link aggregation, speed, storm control, and other interface characteristics. External EPGs represent external destinations, bridge domains provide forwarding domains, and route-control profiles influence routing policy. The interface policy group is then referenced through the ACI access-policy hierarchy so the appropriate configuration reaches the selected interfaces. When troubleshooting interface behavior, administrators should inspect the policy group and confirm that its individual policies match the intended physical connectivity requirements.

Question 295

Which ACI setting determines whether unknown Layer 2 destination traffic is flooded within a bridge domain?

  1. Unicast routing
  2. Unknown unicast behavior
  3. Endpoint retention
  4. BFD

Correct Answer: 2

Explanation

Unknown unicast behavior determines how ACI handles Layer 2 traffic when the destination endpoint is not known. Depending on the configured behavior, such traffic may be flooded or handled according to the bridge-domain policy. Unicast routing controls Layer 3 forwarding, endpoint retention affects learned endpoint information, and BFD provides rapid failure detection for routing peers. When an endpoint cannot communicate because its destination MAC address is not known, administrators should review endpoint learning and the bridge-domain unknown-unicast setting. Understanding this behavior helps prevent unnecessary flooding while maintaining compatibility with applications that depend on traditional Layer 2 forwarding.

Question 296

Which ACI component provides a logical routing context that can contain multiple bridge domains?

  1. VRF
  2. Filter
  3. VLAN pool
  4. Interface selector

Correct Answer: 1

Explanation

A VRF provides the Layer 3 routing context for ACI and can contain multiple bridge domains. Each bridge domain associated with the VRF can have its own subnet and forwarding characteristics while sharing the same logical routing table. Filters define traffic conditions, VLAN pools provide encapsulation resources, and interface selectors identify physical interfaces. VRFs are fundamental to tenant segmentation because separate VRFs maintain independent routing contexts. When communication between bridge domains behaves unexpectedly, administrators should verify their VRF associations, subnet configuration, routing settings, and contracts. Correct VRF design ensures that routes remain within the intended logical environment.

Question 297

Which ACI feature can be used to monitor system-generated messages for operational troubleshooting?

  1. Static path binding
  2. Syslog
  3. VLAN pool
  4. Preferred group

Correct Answer: 4

Explanation

Syslog can be used to collect and monitor system-generated messages from network infrastructure, helping administrators investigate operational events and failures. In an ACI environment, centralized logging can complement APIC faults, health scores, and other monitoring mechanisms. Static path binding controls endpoint attachment, VLAN pools provide encapsulation resources, and preferred groups influence EPG communication policy. When troubleshooting intermittent problems, administrators can correlate syslog messages with APIC faults, interface status, endpoint events, and configuration changes. Centralized logging improves visibility into events that may not be obvious from a single configuration screen or current device state.

Question 298

Which ACI feature provides a rapid mechanism for detecting failures between routing peers?

  1. CDP
  2. LLDP
  3. BFD
  4. VXLAN

Correct Answer: 3

Explanation

Bidirectional Forwarding Detection, or BFD, provides rapid failure detection between supported network peers. It can detect forwarding-path failures much faster than waiting for some routing protocol timers to expire. CDP and LLDP provide neighbor-discovery information, while VXLAN is an overlay encapsulation technology. BFD can be particularly useful with routing protocols where rapid convergence is important. During troubleshooting, administrators should verify that BFD is supported and enabled on both peers, that the session reaches the expected state, and that underlying connectivity is functioning. Proper BFD configuration can reduce the time required to detect a failed forwarding path.

Question 299

Which ACI management approach uses the production fabric for communication with management endpoints?

  1. Out-of-band management
  2. In-band management
  3. Console-only management
  4. External EPG management

Correct Answer: 1

Explanation

In-band management uses the ACI fabric itself to carry management traffic between managed devices and management endpoints. This differs from out-of-band management, which uses a separate dedicated management network. In-band management can simplify connectivity by using the existing fabric infrastructure, but it also means management access can be affected by certain fabric or policy failures. Administrators should verify the management EPG or related configuration, routing, contracts, and connectivity when management access is unavailable. Understanding the distinction between in-band and out-of-band management is important when designing resilient operational access to the ACI environment.

Question 300

Which ACI component represents the centralized controller cluster responsible for policy management and fabric orchestration?

  1. APIC
  2. Leaf switch
  3. Spine switch
  4. External router

Correct Answer: 3

Explanation

APIC represents the centralized controller platform used to manage policy, fabric configuration, monitoring, and orchestration in Cisco ACI. An APIC deployment normally operates as a controller cluster to provide management availability and maintain the policy database. Leaf switches provide endpoint connectivity and policy enforcement, spine switches provide fabric transit, and external routers provide connectivity beyond the ACI fabric. When troubleshooting controller-related issues, administrators should examine cluster health, controller connectivity, fabric membership, faults, and policy synchronization. APIC does not normally act as the primary data-plane forwarding device for endpoint traffic; the fabric switches perform that function.