View Full Cisco CCNP Data Center 300-620 Exam Dumps and Practice Test Dumps.
Question 301
Which ACI object defines the logical association between an EPG and the VLAN resources required for endpoint connectivity?
- Contract
- VLAN pool
- Route control policy
- Filter
Correct Answer: 2
Explanation
A VLAN pool defines the VLAN identifiers that can be allocated to EPGs and access domains when VLAN encapsulation is required. It is an important component of the ACI access-policy hierarchy because domains reference VLAN pools to provide usable encapsulation resources. Contracts define communication rules, route-control policies influence external routing, and filters identify traffic characteristics. If an EPG cannot deploy correctly to an interface, administrators should verify the domain association, VLAN pool, encapsulation range, and interface policy configuration. Proper VLAN pool design prevents conflicting assignments and ensures that the fabric has appropriate VLAN resources for connected physical or virtual workloads.
Question 302
Which ACI policy determines whether endpoints in the same EPG can communicate directly with each other?
- Intra-EPG isolation
- Route control
- Endpoint retention
- BFD
Correct Answer: 4
Explanation
Intra-EPG isolation controls whether endpoints belonging to the same EPG are permitted to communicate directly with one another. By default, endpoints in an EPG can generally communicate according to the EPG policy model, but isolation can be enabled when workloads require stronger segmentation. Route-control policies affect routing, endpoint retention controls learned endpoint information, and BFD provides rapid failure detection. This feature is useful for environments where endpoints should communicate only through controlled policy relationships. When troubleshooting same-EPG connectivity, administrators should verify the EPG configuration, intra-EPG isolation setting, contracts where applicable, and the endpoint learning state.
Question 303
Which ACI object contains subjects that determine how a contract’s filters are applied?
- Bridge domain
- Application profile
- Contract
- Physical domain
Correct Answer: 3
Explanation
A contract contains subjects that define how its associated filters are applied to communication between EPGs. The subject can reference one or more filters and specify the traffic characteristics that the contract permits. Bridge domains provide Layer 2 and gateway functions, application profiles organize related EPGs, and physical domains associate EPGs with physical connectivity. Contracts are central to ACI’s policy-based security model because they allow administrators to define reusable communication rules rather than configuring endpoint-specific ACLs. When a permitted application flow fails, administrators should inspect the contract relationship, subject, filter entries, and consumer-provider associations.
Question 304
Which ACI feature provides endpoint connectivity to a hypervisor or virtualization platform?
- Physical domain
- VMM domain
- External EPG
- L3Out
Correct Answer: 1
Explanation
A VMM domain provides the integration between ACI and a supported virtualization environment. It allows ACI policy to be associated with virtual machines and virtualization networking constructs. A physical domain is intended for physical endpoint connectivity, while an External EPG represents external destinations and an L3Out provides routed connectivity outside the fabric. When virtual workloads fail to receive expected network policy, administrators should verify the VMM domain association, VLAN pool, virtualization controller integration, EPG deployment, and endpoint learning. Correct VMM domain configuration allows ACI to maintain policy consistency while virtual workloads move between supported hosts.
Question 305
Which ACI protocol can be enabled to discover directly connected neighboring devices on Ethernet interfaces?
- CDP
- OSPF
- BGP
- BFD
Correct Answer: 4
Explanation
CDP, the Cisco Discovery Protocol, can provide information about directly connected Cisco devices, including device identity, interface information, and capabilities. It is useful during ACI interface troubleshooting because administrators can confirm whether the expected neighbor is physically connected to a leaf interface. OSPF and BGP are routing protocols, while BFD provides rapid failure detection. CDP is configured through interface policies and policy groups in ACI. When a neighboring device is not detected, administrators should check the interface policy configuration, physical link status, CDP state, and whether the connected device supports and has enabled the relevant discovery protocol.
Question 306
Which ACI component provides Layer 2 and Layer 3 forwarding characteristics for a group of endpoints?
- Contract
- Bridge domain
- Filter
- External EPG
Correct Answer: 1
Explanation
A bridge domain defines important Layer 2 and Layer 3 forwarding characteristics for endpoints associated with an EPG. It can contain a subnet used as a default gateway and includes settings related to ARP flooding, unknown unicast handling, endpoint learning, and routing. Contracts control communication policy, filters define traffic conditions, and External EPGs represent external destinations. When endpoint connectivity behaves unexpectedly, administrators should review the bridge domain’s VRF association, subnet configuration, routing settings, and flooding behavior. Correct bridge-domain configuration provides the forwarding context required for workloads to communicate within and across application environments.
Question 307
Which ACI component provides centralized policy and configuration management for the entire fabric?
- APIC
- Leaf switch
- Spine switch
- External router
Correct Answer: 2
Explanation
APIC provides centralized policy and configuration management for Cisco ACI. Administrators use APIC to define tenants, VRFs, bridge domains, EPGs, contracts, access policies, external connectivity, and monitoring configurations. Leaf switches enforce policy and forward endpoint traffic, while spine switches primarily provide fabric transit. External routers connect the ACI fabric to outside networks. APIC also maintains the policy repository and coordinates configuration across the fabric. When configuration changes are made through APIC, administrators should monitor faults, health scores, and policy deployment status to confirm that the intended configuration has been successfully applied to the appropriate fabric components.
Question 308
Which ACI object identifies a specific physical interface or range of interfaces for policy application?
- Interface selector
- VRF
- Contract
- Route control policy
Correct Answer: 3
Explanation
An interface selector identifies the physical interfaces or interface ranges where an access policy should be applied. It works within the ACI access-policy hierarchy and is commonly associated with interface policy groups. VRFs provide routing contexts, contracts define communication policy, and route-control policies influence external routing. Interface selectors are important because they connect the logical access-policy configuration to specific physical switch ports. During troubleshooting, administrators should verify the switch profile, interface profile, selector, policy group, domain, and VLAN pool. A mismatch at any of these levels can prevent an EPG or endpoint from receiving the intended configuration.
Question 309
Which ACI architecture uses leaf switches as the endpoint attachment layer and spine switches as the fabric transit layer?
- Three-tier architecture
- Hub-and-spoke architecture
- Leaf-and-spine architecture
- Ring architecture
Correct Answer: 4
Explanation
The ACI fabric uses a leaf-and-spine architecture. Leaf switches connect to endpoints such as servers, appliances, and external devices, while spine switches provide the high-speed transit layer between leaf switches. Endpoints normally do not connect directly to spine switches. This architecture provides predictable connectivity and supports the ACI policy model by separating endpoint attachment from fabric transit. When troubleshooting traffic between endpoints attached to different leaves, administrators should examine endpoint learning, leaf forwarding, spine connectivity, and policy configuration. Understanding the leaf-and-spine structure is fundamental to interpreting ACI forwarding behavior and fabric connectivity.
Question 310
Which ACI routing protocol is commonly used when an L3Out must establish an external BGP peering relationship?
- BGP
- CDP
- LLDP
- STP
Correct Answer: 1
Explanation
BGP is used when an ACI L3Out must establish a Border Gateway Protocol peering relationship with an external router. BGP can exchange routing information between the ACI fabric and an external autonomous system or another BGP-speaking routing domain. CDP and LLDP provide neighbor discovery rather than route exchange, while STP is a Layer 2 loop-prevention mechanism. When troubleshooting BGP through an L3Out, administrators should verify local and remote autonomous-system settings, neighbor addressing, interface configuration, routing policy, and route-control policies. A BGP session being established does not automatically mean that all desired prefixes are being advertised or accepted.
Question 311
Which ACI policy object is used to represent a collection of application endpoints that share common policy requirements?
- EPG
- L3Out
- VLAN pool
- Spine profile
Correct Answer: 3
Explanation
An Endpoint Group, or EPG, represents a collection of endpoints that share common policy requirements. Endpoints can be physical servers, virtual machines, or other connected devices. EPGs are organized within application profiles and are associated with bridge domains and contracts according to the application design. L3Out represents external routed connectivity, VLAN pools provide encapsulation resources, and spine profiles are not used to represent endpoint groups. EPGs are central to ACI’s policy model because contracts can be applied between them to control communication. Proper EPG design helps administrators organize application workloads according to security and connectivity requirements.
Question 312
Which ACI feature can identify faults and provide a summarized indication of the operational condition of fabric objects?
- VLAN pool
- Health score
- Static path binding
- Contract subject
Correct Answer: 2
Explanation
ACI health scores provide a summarized indication of the operational condition of fabric objects based on faults and other detected conditions. Administrators can use health information to quickly identify areas requiring investigation. A VLAN pool provides encapsulation resources, static path binding attaches EPGs to physical paths, and contract subjects define how filters are applied. A health score does not replace detailed troubleshooting because the underlying faults still need to be examined. When a score decreases, administrators should inspect the associated fault codes, affected objects, recent configuration changes, interface status, and endpoint behavior to determine the actual cause of the problem.
Question 313
Which ACI component provides a logical grouping of related EPGs within a tenant?
- Application profile
- VLAN pool
- Interface policy group
- External subnet
Correct Answer: 4
Explanation
An application profile logically groups related EPGs within a tenant. For example, separate web, application, and database EPGs can be organized under the same application profile while maintaining independent policies. VLAN pools provide VLAN resources, interface policy groups define interface behavior, and external subnets identify networks associated with external connectivity. Application profiles help administrators structure ACI configuration according to applications rather than physical topology. When reviewing an application deployment, the application profile provides a useful organizational level for identifying the EPGs, contracts, and bridge domains involved in the workload’s policy configuration.
Question 314
Which ACI feature allows multiple EPGs within the same VRF to communicate without requiring individual contracts between every pair?
- BFD
- Preferred group
- Endpoint retention
- VLAN pool
Correct Answer: 1
Explanation
The preferred group feature can simplify communication between selected EPGs within the same VRF by allowing preferred-group members to communicate according to the configured preferred-group behavior without requiring individual contracts for every relationship. This can reduce the number of explicit contracts required in environments with many closely related EPGs. BFD provides failure detection, endpoint retention manages learned endpoint information, and VLAN pools provide encapsulation resources. Administrators should carefully define preferred-group membership because it changes how communication policy is applied. The VRF association and EPG membership should always be verified when troubleshooting unexpected connectivity.
Question 315
Which ACI feature is responsible for maintaining learned information about connected endpoints?
- Endpoint learning
- Route control
- Contract filtering
- VLAN allocation
Correct Answer: 2
Explanation
Endpoint learning allows ACI leaf switches to maintain information about endpoints connected to the fabric, including endpoint location and relevant addressing information. This information is essential for forwarding traffic toward the correct leaf and interface. Route control manages external routing, contract filtering controls policy-based communication, and VLAN allocation provides encapsulation resources. If an endpoint is missing from the expected endpoint table, administrators should investigate the physical connection, EPG deployment, VLAN encapsulation, endpoint learning state, and interface configuration. Accurate endpoint learning allows the fabric to forward traffic efficiently without relying on unnecessary flooding.
Question 316
Which ACI protocol is commonly used to exchange routes between an L3Out and an external OSPF-speaking router?
- VXLAN
- CDP
- OSPF
- LLDP
Correct Answer: 3
Explanation
OSPF is used when an ACI L3Out needs to exchange routes with an external OSPF-speaking router. It establishes neighbor relationships and exchanges link-state information to build routing knowledge. VXLAN provides the fabric overlay encapsulation, while CDP and LLDP provide neighbor discovery. When configuring OSPF on an L3Out, administrators should verify the OSPF area, interface configuration, router identifiers where relevant, neighbor state, and route-control policies. A successful OSPF adjacency is only one part of the configuration. Administrators should also verify that the intended routes are actually being imported into or exported from the ACI fabric.
Question 317
Which ACI access-policy object determines the behavior of a physical Ethernet interface, such as CDP or LLDP settings?
- Interface policy
- External EPG
- Bridge domain
- VRF
Correct Answer: 4
Explanation
Interface policies define individual behaviors for physical Ethernet interfaces. Examples include CDP, LLDP, speed, link aggregation, storm control, and other interface-specific characteristics. These policies can be combined into interface policy groups and then applied through the ACI access-policy hierarchy. External EPGs represent external destinations, bridge domains define forwarding contexts, and VRFs provide routing separation. When a physical interface does not behave as expected, administrators should verify the relevant interface policy, policy group, selector, and switch profile. Correct policy association ensures that the desired interface behavior is consistently deployed across the appropriate leaf interfaces.
Question 318
Which ACI technology encapsulates tenant traffic across the leaf-and-spine fabric?
- STP
- VXLAN
- OSPF
- CDP
Correct Answer: 4
Explanation
VXLAN is used by ACI to encapsulate tenant traffic across the leaf-and-spine fabric. It provides the overlay mechanism that allows traffic associated with different logical networks and policy contexts to traverse the fabric while maintaining appropriate segmentation. STP is a Layer 2 loop-prevention protocol, OSPF is a routing protocol, and CDP is a neighbor-discovery protocol. ACI uses VXLAN together with its policy and forwarding architecture to provide scalable connectivity across the fabric. When troubleshooting traffic forwarding, administrators should understand both the overlay encapsulation and the endpoint policy information that determines how traffic is classified and forwarded.
Question 319
Which ACI component is used to connect the fabric to an external Layer 2 network?
- L2Out
- VRF
- Contract subject
- VMM domain
Correct Answer: 2
Explanation
An L2Out provides external Layer 2 connectivity between an ACI fabric and an external Layer 2 network. It allows an EPG to extend connectivity toward an external Layer 2 environment through the appropriate bridge-domain and access-policy configuration. A VRF provides a Layer 3 routing context, contract subjects define filter application, and VMM domains integrate virtualization environments. When configuring an L2Out, administrators should verify the associated bridge domain, external connectivity configuration, VLAN encapsulation, interface path, and relevant EPG policies. Correct configuration allows Layer 2 traffic to cross the fabric boundary while preserving the intended ACI policy model.
Question 320
Which ACI object is responsible for defining the IP subnet associated with a bridge domain?
- Contract
- Filter
- Bridge-domain subnet
- Interface selector
Correct Answer: 1
Explanation
A bridge-domain subnet defines the IP subnet associated with a bridge domain and can provide the default gateway used by connected endpoints. It is an important part of ACI Layer 3 forwarding because the subnet establishes the gateway address and routing context for the bridge domain. Contracts and filters control communication policy, while interface selectors identify physical interfaces. When endpoints cannot communicate at Layer 3, administrators should verify the bridge-domain subnet, VRF association, gateway configuration, endpoint attachment, and contracts. Correct subnet configuration ensures that endpoints receive the expected gateway and can participate in the intended routed communication environment.