Cisco CCNP Data Center 300-620 Practice Test Questions and Exam Dumps Part17 Q321-340

View Full Cisco CCNP Data Center 300-620 Exam Dumps and Practice Test Dumps.

 

Question 321

Which ACI object provides a logical representation of a group of endpoints that share common policy requirements?

  1. VRF
  2. Bridge domain
  3. EPG
  4. L3Out

Correct Answer: 3

Explanation

An Endpoint Group, or EPG, represents a logical collection of endpoints that share common policy requirements. EPGs are fundamental to Cisco ACI because contracts, bridge domains, and access policies are associated with them to create application-centric connectivity. A VRF provides a routing context, a bridge domain provides forwarding characteristics, and an L3Out represents external routed connectivity. EPGs can contain physical servers, virtual machines, or other endpoint types. When designing an ACI application, administrators commonly create separate EPGs for different application tiers and then use contracts to control communication between those groups according to security requirements.

Question 322

Which ACI component provides the Layer 3 routing context used by bridge domains?

  1. VRF
  2. VLAN pool
  3. Contract
  4. Interface selector

Correct Answer: 1

Explanation

A VRF provides the Layer 3 routing context in which bridge domains operate. Each bridge domain is associated with a VRF, allowing its subnets and routes to participate in a specific logical routing table. Separate VRFs can provide routing isolation between tenants or application environments. VLAN pools provide encapsulation resources, contracts define communication policy, and interface selectors identify physical interfaces. When troubleshooting Layer 3 connectivity between bridge domains, administrators should first verify their VRF associations, subnet configuration, routing settings, and policy relationships. Correct VRF assignment is essential for maintaining the intended routing separation throughout an ACI fabric.

Question 323

Which ACI policy component specifies the traffic protocols and ports that a contract permits?

  1. Subject
  2. EPG
  3. Filter
  4. Bridge domain

Correct Answer: 4

Explanation

A filter defines the specific traffic characteristics that can be permitted by an ACI contract. Filter entries can specify protocols, source or destination ports, and related traffic conditions. A contract subject determines how filters are applied, while EPGs represent groups of endpoints and bridge domains provide forwarding characteristics. Filters allow administrators to implement application-specific communication policies instead of permitting all traffic between EPGs. During troubleshooting, administrators should verify that the filter entry matches the actual application traffic and that the filter is correctly associated with the contract subject. An incorrect protocol or port definition can cause legitimate traffic to be denied.

Question 324

Which ACI access-policy object associates an EPG with physical connectivity requirements?

  1. Contract
  2. Physical domain
  3. Route control policy
  4. External EPG

Correct Answer: 2

Explanation

A physical domain associates an EPG with the access-policy resources required for physical endpoint connectivity. It references a VLAN pool and can be associated with the appropriate physical access policies. Contracts define communication between EPGs, route-control policies influence external routing, and External EPGs represent external destinations. Physical domains are commonly used for bare-metal servers, appliances, and other devices connected directly to leaf interfaces. If a physical endpoint cannot be deployed correctly, administrators should verify the EPG’s physical domain association, VLAN pool, interface selector, policy group, static path binding, and encapsulation configuration.

Question 325

Which ACI feature allows a leaf switch to detect neighboring Cisco devices through Layer 2 discovery messages?

  1. CDP
  2. BGP
  3. OSPF
  4. BFD

Correct Answer: 3

Explanation

CDP, or Cisco Discovery Protocol, allows supported Cisco devices to exchange neighbor information over directly connected interfaces. In an ACI environment, CDP can help administrators identify connected devices and verify physical topology. BGP and OSPF are routing protocols, while BFD provides rapid failure detection. CDP behavior is controlled through ACI interface policies and policy groups. During troubleshooting, administrators can use CDP information to confirm that the expected neighbor is connected to the correct leaf interface. They should also verify interface status, policy deployment, and whether CDP is enabled on both the ACI interface and the neighboring device.

Question 326

Which ACI setting determines how quickly a resolved policy is programmed on the leaf switch?

  1. Endpoint retention
  2. ARP flooding
  3. Deployment immediacy
  4. Unknown unicast

Correct Answer: 4

Explanation

Deployment immediacy determines when a resolved EPG policy is programmed on the leaf switch. It influences the timing of policy deployment and can be important when administrators need predictable policy installation behavior. Endpoint retention controls learned endpoint information, ARP flooding affects ARP handling, and unknown-unicast settings influence Layer 2 traffic with unknown destinations. Deployment immediacy should be considered together with resolution immediacy because both affect policy processing and installation. When an EPG does not appear to have the expected configuration on a leaf, administrators should review the EPG domain, path binding, resolution settings, deployment settings, and relevant access policies.

Question 327

Which ACI object represents a collection of VLAN IDs that can be allocated to connected endpoints?

  1. VLAN pool
  2. Application profile
  3. Contract
  4. External EPG

Correct Answer: 1

Explanation

A VLAN pool contains the VLAN IDs that ACI can allocate for endpoint connectivity within the relevant access-policy configuration. VLAN pools are associated with physical, VMM, or other appropriate domains and provide the encapsulation resources required for deployment. Application profiles organize EPGs, contracts define communication policy, and External EPGs represent external destinations. If an EPG cannot be deployed to a physical or virtual domain, administrators should verify that the associated domain references the correct VLAN pool and that the required VLAN ID exists within the pool. Proper VLAN pool configuration prevents deployment failures caused by unavailable encapsulation resources.

Question 328

Which ACI access-policy component selects the interfaces on which an interface policy group is applied?

  1. Interface profile
  2. Interface selector
  3. Switch profile
  4. VLAN pool

Correct Answer: 2

Explanation

An interface selector identifies the specific physical interfaces or interface ranges where an interface policy group should be applied. It forms part of the ACI access-policy hierarchy and connects logical interface configuration to actual leaf switch ports. An interface profile organizes interface selectors, a switch profile associates configuration with leaf switches, and a VLAN pool supplies encapsulation resources. If an interface does not receive the expected policy, administrators should trace the configuration from the switch profile through the interface profile and selector to the interface policy group. This hierarchical approach helps identify incorrect or missing access-policy associations.

Question 329

Which ACI feature can be used to prevent endpoints within the same EPG from communicating directly?

  1. Preferred group
  2. Contract
  3. Intra-EPG isolation
  4. Route control

Correct Answer: 4

Explanation

Intra-EPG isolation prevents endpoints within the same EPG from communicating directly with each other when the feature is configured for that purpose. This provides an additional segmentation mechanism for workloads that belong to the same logical group but should not have unrestricted lateral communication. Preferred groups influence communication between EPGs, contracts define policy relationships between groups, and route control manages external routing information. When using intra-EPG isolation, administrators should understand the application’s communication requirements because enabling isolation can affect legitimate endpoint-to-endpoint traffic. Troubleshooting should include checking the EPG configuration, isolation setting, endpoint learning, and any required external policy relationships.

Question 330

Which ACI component provides connectivity between the fabric and an external Layer 3 network?

  1. L3Out
  2. VLAN pool
  3. VMM domain
  4. Application profile

Correct Answer: 1

Explanation

An L3Out provides routed connectivity between the ACI fabric and an external Layer 3 network. It can include logical node profiles, logical interface profiles, routing protocols, external subnets, and External EPGs. VLAN pools provide encapsulation resources, VMM domains integrate virtualization platforms, and application profiles organize internal EPGs. When configuring an L3Out, administrators must ensure that the correct VRF is associated and that the external interfaces, routing protocol, and policy configuration are consistent. Troubleshooting should also include checking route-control policies and External EPG contracts because successful physical connectivity alone does not guarantee that external traffic will be permitted.

Question 331

Which protocol provides neighbor discovery information for supported devices and is commonly configured through ACI interface policies?

  1. OSPF
  2. BGP
  3. LLDP
  4. BFD

Correct Answer: 3

Explanation

LLDP, or Link Layer Discovery Protocol, provides standardized neighbor discovery information between compatible network devices. In ACI, LLDP can be enabled and controlled through interface policies and policy groups. It helps administrators identify connected devices, interfaces, and advertised capabilities while troubleshooting physical connectivity. OSPF and BGP exchange routing information, while BFD provides rapid failure detection. If LLDP information is missing, administrators should verify the interface policy, policy group, selector, physical interface state, and LLDP configuration on the neighboring device. Neighbor discovery information can be especially useful when validating cabling and confirming that the expected device is connected to the correct interface.

Question 332

Which ACI policy controls the handling of ARP requests that cannot be resolved through normal endpoint information?

  1. Endpoint retention
  2. ARP flooding
  3. Deployment immediacy
  4. BFD

Correct Answer: 2

Explanation

ARP flooding controls how ARP requests are handled within an ACI bridge domain when normal endpoint information cannot satisfy the request. Enabling ARP flooding can be necessary for certain applications and environments that depend on traditional Layer 2 ARP behavior. Endpoint retention manages how long learned endpoint information is retained, deployment immediacy controls policy programming timing, and BFD provides rapid failure detection. When hosts cannot resolve neighboring IP addresses, administrators should inspect the bridge-domain ARP flooding configuration along with endpoint learning, subnet settings, and gateway configuration. Correct ARP behavior is important for maintaining compatibility with applications that rely on conventional address-resolution mechanisms.

Question 333

Which ACI policy object is used to define communication between a consumer EPG and a provider EPG?

  1. Contract
  2. VLAN pool
  3. Physical domain
  4. Interface selector

Correct Answer: 4

Explanation

A contract defines communication policy between a consumer EPG and a provider EPG. The contract can contain subjects and filters that specify which application traffic is permitted. VLAN pools provide encapsulation resources, physical domains define physical connectivity requirements, and interface selectors identify interfaces. ACI contracts allow security policy to remain independent of the physical location of endpoints, making the policy easier to maintain as workloads move. When communication between two EPGs fails, administrators should confirm the provider and consumer relationships, contract association, subject configuration, filter entries, and VRF relationships before investigating lower-level forwarding issues.

Question 334

Which ACI component is used to define a collection of external prefixes associated with an external network?

  1. Bridge domain
  2. External EPG
  3. VMM domain
  4. Interface policy group

Correct Answer: 3

Explanation

An External EPG represents external network destinations connected through an ACI external connectivity configuration. External subnets can be associated with the External EPG, allowing those destinations to participate in contract-based policy relationships with internal EPGs. Bridge domains provide internal forwarding contexts, VMM domains integrate virtualization environments, and interface policy groups define physical interface behavior. External EPG configuration is important for controlling north-south communication. When internal endpoints cannot reach an external prefix, administrators should verify the External EPG subnet definition, L3Out configuration, route-control policies, contracts, and routing protocol state. These components collectively determine whether external traffic can be exchanged.

Question 335

Which ACI feature allows selected EPGs within a VRF to communicate according to preferred-group policy?

  1. Preferred group
  2. Endpoint retention
  3. VLAN pool
  4. Interface selector

Correct Answer: 1

Explanation

Preferred groups allow selected EPGs within the same VRF to participate in a simplified communication model. EPGs included in the preferred group can communicate according to the preferred-group policy without requiring individual contracts for every relationship. Endpoint retention manages learned endpoint information, VLAN pools provide VLAN resources, and interface selectors identify physical interfaces. Preferred groups should be designed carefully because they can alter the normal contract-based communication model. When troubleshooting communication between preferred-group members, administrators should verify that the EPGs belong to the correct VRF and that preferred-group membership is configured consistently. Other external or isolated EPGs may still require explicit contracts.

Question 336

Which ACI object identifies the logical interface configuration used by an L3Out?

  1. Logical node profile
  2. External EPG
  3. Logical interface profile
  4. VLAN pool

Correct Answer: 4

Explanation

A logical interface profile defines the logical interface configuration used by an L3Out. It can contain interface-level information associated with the external routed connection, including the relevant interface configuration and protocol relationships. A logical node profile identifies the external nodes participating in the L3Out, an External EPG represents external destinations, and a VLAN pool provides encapsulation resources. When troubleshooting an L3Out interface, administrators should examine both the logical node and logical interface profiles along with the physical interface policy, IP addressing, routing protocol configuration, and route-control policies. Correct logical interface configuration is essential for establishing external routed connectivity.

Question 337

Which ACI technology provides the overlay encapsulation used to transport tenant traffic through the fabric?

  1. VXLAN
  2. CDP
  3. OSPF
  4. STP

Correct Answer: 1

Explanation

VXLAN provides the overlay encapsulation used by ACI to transport tenant traffic through the leaf-and-spine fabric. It allows logical networks and endpoint groups to be carried across the physical infrastructure while maintaining segmentation. CDP provides neighbor discovery, OSPF exchanges routing information, and STP is a Layer 2 loop-prevention mechanism. ACI combines VXLAN-based forwarding with policy information maintained by APIC and enforced by leaf switches. When troubleshooting forwarding problems, administrators should consider both the overlay information and the endpoint policy state. Correct endpoint learning, EPG deployment, and fabric connectivity are necessary for successful VXLAN-based traffic forwarding.

Question 338

Which ACI management method uses a separate management network instead of the production fabric?

  1. In-band management
  2. Out-of-band management
  3. Preferred-group management
  4. External EPG management

Correct Answer: 4

Explanation

Out-of-band management uses a dedicated management network that is separate from the production data-plane fabric. This approach can provide management access even when certain production-fabric forwarding or policy problems occur. In-band management uses the ACI fabric itself for management communication. Preferred groups and External EPGs are policy constructs rather than management methods. When designing operational access, administrators should understand the availability and failure characteristics of each management approach. If in-band access is unavailable because of a fabric or policy problem, out-of-band access can provide an alternative path for troubleshooting and configuration of supported infrastructure components.

Question 339

Which ACI protocol can provide rapid detection of forwarding-path failures between supported peers?

  1. CDP
  2. LLDP
  3. OSPF
  4. BFD

Correct Answer: 2

Explanation

BFD provides rapid detection of forwarding-path failures between supported network peers. It is designed to detect failures more quickly than relying solely on normal routing-protocol timers. CDP and LLDP are neighbor-discovery mechanisms, while OSPF is a link-state routing protocol. BFD can be used alongside routing protocols to improve convergence behavior when a forwarding path fails. During troubleshooting, administrators should verify that BFD is enabled on both peers, that the underlying interfaces are operational, and that the BFD session reaches the expected state. A failed BFD session can indicate an underlying connectivity problem that requires further investigation.

Question 340

Which ACI object represents a logical container for routing, bridge domains, and other tenant networking policies?

  1. VRF
  2. Contract
  3. Tenant
  4. Filter

Correct Answer: 3

Explanation

A tenant is a logical container used to organize networking and policy objects within ACI. It can contain VRFs, bridge domains, application profiles, EPGs, contracts, external connectivity configurations, and related policy objects. A VRF specifically provides a routing context, while contracts define communication policy and filters define traffic conditions. Tenants help administrators organize configurations according to organizational, application, or administrative boundaries. When troubleshooting a policy relationship, identifying the correct tenant first can help establish the hierarchy of associated objects. Proper tenant organization also makes large ACI deployments easier to manage and maintain.