Cisco CCNP Data Center 300-610 Practice Test Questions and Exam Dumps Part7 Q121-140

View Full Cisco CCNP Data Center 300-610 Exam Dumps and Practice Test Dumps.


Question 121. What is the default scope of a standard ACI contract

  1. Application profile
  2. VRF
  3. Tenant
  4. Global

Correct Answer: 2. VRF

Explanation:

The default scope of a standard Cisco ACI contract is the VRF scope. This means endpoint groups associated with the same VRF can use the contract even when those EPGs belong to different application profiles. Contract scope determines how broadly a policy can be applied and is therefore important when designing segmentation and shared connectivity. Other available scopes include application profile, tenant, and global. Designers should avoid selecting a scope that is broader than required because doing so can unintentionally permit communication between endpoint groups that were expected to remain isolated.

Question 122. Which ACI contract scope can apply across different tenants

  1. VRF
  2. Application profile
  3. Tenant
  4. Global

Correct Answer: 4. Global

Explanation:

Global is the broadest Cisco ACI contract scope. A contract with global scope can apply between endpoint groups across different tenants in the fabric when the contract is visible to the participating tenants. Cisco advises using this scope carefully because an overly broad global contract can create unintended communication between otherwise separated environments. Intertenant contracts are commonly defined in the common tenant or exported through a contract interface so both sides can reference the contract. Global scope should therefore be selected only when cross tenant communication is an intentional design requirement.

Question 123. Which contract scope restricts use to EPGs in one application profile

  1. Application profile
  2. VRF
  3. Tenant
  4. Global

Correct Answer: 1. Application profile

Explanation:

Application profile scope limits a Cisco ACI contract to endpoint groups defined within the same application profile. Even if another EPG is located in the same VRF, it cannot use that contract when it belongs to a different application profile. This scope is useful when the designer wants contract policy to remain tightly associated with one logical application. Selecting application profile scope provides stronger policy containment than the default VRF scope. Cisco recommends choosing the narrowest scope that satisfies the intended connectivity because broader scopes can allow additional EPG relationships that were not originally required.

Question 124. Which ACI contract scope can support EPGs in different VRFs of the same tenant

  1. Application profile
  2. VRF
  3. Tenant
  4. Context only

Correct Answer: 3. Tenant

Explanation:

Tenant scope allows a contract to be used by endpoint groups located in different VRFs as long as those EPGs belong to the same tenant. This makes tenant scope useful for inter VRF communication requirements within one administrative domain. Cisco notes that route leaking must also be configured correctly between the consumer and provider VRFs for inter VRF communication to operate. The contract alone does not create routing reachability. Designers therefore need to plan both policy scope and route leaking behavior when connecting application groups that belong to different routing contexts within one tenant.

Question 125. What is the primary purpose of an ACI taboo contract

  1. Permit all IP traffic
  2. Deny selected traffic
  3. Create a bridge domain
  4. Configure VXLAN tunnels

Correct Answer: 2. Deny selected traffic

Explanation:

A taboo contract is a Cisco ACI policy construct used to deny specific traffic that might otherwise be permitted by a standard contract. A filter defines the traffic that should be blocked as it travels toward the EPG associated with the taboo policy. Cisco also describes taboo contracts as useful for logging denied traffic. This mechanism allows designers to create broad permit contracts while explicitly excluding certain protocols or ports. Because taboo rules have higher priority than ordinary contract permits, they can provide targeted deny behavior without redesigning all existing communication contracts.

Question 126. Which contract takes precedence when a standard contract permits traffic that a taboo contract denies

  1. Taboo contract
  2. Standard contract
  3. The oldest contract
  4. The largest filter

Correct Answer: 1. Taboo contract

Explanation:

A taboo contract takes precedence when its deny criteria match traffic that a standard ACI contract would otherwise permit. Cisco assigns taboo policies a higher priority so the explicit deny can override the normal permit relationship. For example, a standard contract can permit general IP communication between two endpoint groups while a taboo contract blocks SSH traffic toward one of those EPGs. This allows administrators to create exceptions to broad connectivity policies while maintaining the original permit contract. Taboo contracts are therefore useful for implementing specific restrictions without completely restructuring existing application communication rules.

Question 127. What is a benefit of defining reusable ACI filters in the common tenant

  1. They can be shared by other tenants
  2. They disable VRFs
  3. They remove contracts
  4. They create SAN zones

Correct Answer: 1. They can be shared by other tenants

Explanation:

The common tenant provides Cisco ACI objects that can be visible and reusable from other tenants. A commonly used filter can therefore be defined once in the common tenant instead of being recreated independently in every user tenant. This can simplify operations and improve configuration consistency. Cisco cautions that contracts defined in the common tenant require careful scope planning because overly broad contract use can accidentally enable communication across tenants. Reusing filters is often simpler and safer because the filter describes traffic matching criteria while each tenant can still define its own appropriate contract relationships and scope.

Question 128. Where can an intertenant ACI contract be defined so all tenants can see it

  1. Management tenant only
  2. Infrastructure tenant only
  3. Common tenant
  4. APIC local user database

Correct Answer: 3. Common tenant

Explanation:

An intertenant contract can be defined in the common tenant, making the contract visible to other tenants that need to consume or provide it. Cisco also supports defining a contract in a user tenant and exporting it to another tenant through a contract interface. The common tenant approach is convenient for shared services and reusable policy, but designers must select the correct scope. A global contract used by several tenants can create cross tenant communication if that behavior is not carefully planned. Contract visibility and contract scope therefore need to be considered together in intertenant designs.

Question 129. What does NDFC bootstrap use for day zero switch provisioning

  1. POAP
  2. HSRP
  3. FSPF
  4. LACP

Correct Answer: 1. POAP

Explanation:

Cisco Nexus Dashboard Fabric Controller bootstrap functionality uses NX OS PowerOn Auto Provisioning to simplify day zero deployment of new switches into an existing fabric. POAP can provide initial management addressing and configuration so a new switch can be brought under fabric management with minimal manual setup. NDFC can use either a local DHCP service or an external DHCP server for automatic address assignment during bootstrap. This automation reduces the repetitive console configuration normally required when installing multiple switches and helps ensure devices enter the fabric with consistent initial settings.

Question 130. Which address assignment methods can NDFC bootstrap use for POAP

  1. DNS only
  2. Static routing only
  3. RADIUS only
  4. Local or external DHCP

Correct Answer: 4. Local or external DHCP

Explanation:

NDFC bootstrap can use either a local DHCP server function or an external DHCP server to provide automatic management addresses during POAP. When local DHCP is enabled, the administrator defines the appropriate DHCP scope information in Nexus Dashboard. If local DHCP is not selected, the deployment can reference an external DHCP infrastructure. POAP then uses the supplied network information as part of the automated day zero switch bring up process. This flexibility allows designers to integrate bootstrap operations with an existing enterprise DHCP service or use NDFC supplied DHCP functionality when appropriate for the deployment.

Question 131. What is the main purpose of NDFC Image Management

  1. Create ACI EPGs
  2. Automate switch software lifecycle tasks
  3. Configure server BIOS
  4. Create Fibre Channel zones only

Correct Answer: 2. Automate switch software lifecycle tasks

Explanation:

Nexus Dashboard Fabric Controller Image Management automates software lifecycle operations for supported Cisco Nexus switches. Cisco describes workflows for planning upgrades, scheduling operations, downloading or staging software, validating compatibility, monitoring compliance, and performing supported upgrade procedures. Managing these tasks centrally reduces the time and potential human error associated with manually upgrading switches one at a time. Image policies can specify the expected software version and patch level for groups of switches so administrators can quickly identify devices that do not match the intended software baseline.

Question 132. What does image staging copy to a Nexus switch

  1. ACI contracts
  2. Service profiles
  3. Software image files
  4. Fibre Channel zones only

Correct Answer: 3. Software image files

Explanation:

Image staging copies the required software image files to the switch bootflash before the actual software upgrade takes place. Cisco allows staging and validation work to be performed before the maintenance window so the disruptive portion of an upgrade can be shorter and more predictable. Validation can confirm that the image is complete and suitable for the target hardware and can help determine whether a supported nondisruptive upgrade is possible. Separating staging from activation also gives administrators time to resolve image transfer or compatibility issues before production maintenance begins.

Question 133. What does an NDFC image policy compliance check compare

  1. Actual and expected software versions
  2. MAC and IP addresses
  3. EPG and bridge domain names
  4. GPU and CPU utilization

Correct Answer: 4. Actual and expected software versions

Explanation:

NDFC image policy compliance determines whether the software running on a managed switch matches the version and patch level defined by the attached image policy. When a switch is out of compliance, administrators can review the current and expected software versions and plan an upgrade or downgrade as appropriate. This provides a centralized method for maintaining consistent NX OS software baselines across groups of switches. Software consistency can simplify operations, reduce feature mismatches, and help make maintenance planning more predictable in large data center fabrics.

Question 134. What should be disabled before an NDFC managed Nexus software upgrade

  1. POAP boot mode
  2. BGP
  3. vPC
  4. All VLANs

Correct Answer: 1. POAP boot mode

Explanation:

Cisco Image Management guidance states that POAP boot mode should be disabled on supported Nexus 9000 and Nexus 3000 switches before performing the software upgrade. The setting can be enabled again after the upgrade is complete when POAP functionality is still required. This precaution prevents the switch from unintentionally entering the automated provisioning process during maintenance or reload operations. Administrators should also ensure that the appropriate device credentials are configured in Nexus Dashboard Fabric Controller before attempting workflows such as in service software upgrade operations.

Question 135. What does an NDFC fabric template generate

  1. GPU firmware
  2. Server operating systems
  3. Intended fabric switch configuration
  4. SAN disk volumes

Correct Answer: 3. Intended fabric switch configuration

Explanation:

An NDFC fabric template contains the logic and rules required to generate intended switch configuration for an entire managed fabric. Cisco fabric templates integrate with elements such as device roles, topology information, resource management, and configuration compliance. NDFC includes predefined templates for common architectures such as Data Center VXLAN EVPN, Enhanced Classic LAN, BGP Fabric, and external connectivity environments. Because fabric templates encode Cisco recommended deployment logic, administrators generally select an appropriate built in template rather than creating a complete fabric template from the beginning.

Question 136. What does an NDFC profile template primarily provision

  1. Physical chassis power
  2. Overlay networks and VRFs
  3. Server UUID pools
  4. Fibre Channel domain IDs only

Correct Answer: 2. Overlay networks and VRFs

Explanation:

Cisco distinguishes profile templates from broader fabric templates. A profile template is used primarily to provision overlay objects such as networks and VRFs, while a fabric template contains the larger rules and logic needed to create the overall fabric architecture. This separation allows administrators to use one fabric design while repeatedly creating application networks and routing segments according to standardized overlay templates. NDFC therefore combines infrastructure level automation with reusable service level provisioning so the physical and logical elements of a data center fabric can be managed consistently.

Question 137. What is the default power redundancy mode for a UCS X9508 chassis

  1. N plus 1
  2. Grid
  3. Not Redundant
  4. N plus 2

Correct Answer: 1. N plus 1

Explanation:

Cisco specifies N plus 1 as the default power redundancy mode for the UCS X9508 chassis under the documented initial discovery and recommissioning conditions. In N plus 1 mode, Power Manager turns on the minimum number of power supplies required to support the chassis load and keeps one additional PSU available for redundancy. This provides protection against a single power supply failure while avoiding the greater power reserve required by N plus 2 operation. Designers should select the redundancy mode according to power source architecture, availability requirements, and available chassis power capacity.

Question 138. What does Grid power redundancy require

  1. One PSU only
  2. No standby capacity
  3. One power source
  4. Two power sources

Correct Answer: 4. Two power sources

Explanation:

Grid redundancy is designed around two independent power sources. Cisco explains that if one source fails, the power supplies connected to the surviving source must be able to provide sufficient power for the chassis. This design protects against failure of an entire upstream power feed rather than only the loss of one individual PSU. Grid redundancy is therefore appropriate when the data center supplies two independent electrical feeds and the server architecture must continue operating after either feed fails. Power capacity on each side must be designed to support the required chassis load independently.

Question 139. What is the default UCS thermal fan control mode described by Cisco

  1. Low Power
  2. Balanced
  3. Maximum Power
  4. Acoustic

Correct Answer: 2. Balanced

Explanation:

Balanced is the default fan control mode in the documented Cisco thermal policy. In Balanced mode, fan speed increases when additional cooling is required based on server heat output and returns toward the minimum necessary speed when thermal demand falls. This mode seeks a practical balance between cooling effectiveness, power consumption, and acoustics. Cisco notes that particular server configurations, such as systems containing certain PCIe cards, can require different cooling behavior. Thermal policy should therefore reflect the actual server hardware, workload, rack cooling design, and environmental conditions rather than relying automatically on the default for every deployment.

Question 140. What does Low Power thermal mode do

  1. Runs fans at maximum speed
  2. Disables all chassis fans
  3. Uses lower minimum fan speeds
  4. Removes power redundancy

Correct Answer: 3. Uses lower minimum fan speeds

Explanation:

Low Power thermal mode operates fans at slightly lower minimum speeds when the server can safely remain within its thermal limits. The goal is to reduce power consumption when maximum cooling is unnecessary. Cisco contrasts this with High Power and Maximum Power modes, which maintain higher fan speeds and prioritize cooling or performance at the cost of greater power use. Designers should not select Low Power solely to reduce energy consumption without considering installed components and workload characteristics. Insufficient cooling can increase component temperatures and potentially affect performance or hardware reliability.