Cisco CCNP Data Center 300-610 Practice Test Questions and Exam Dumps Part11 Q201-220

View Full Cisco CCNP Data Center 300-610 Exam Dumps and Practice Test Dumps.


Question 201. What does an ACI contract subject contain

  1. Filters
  2. VRFs
  3. Bridge domains
  4. Spine interfaces

Correct Answer: 1. Filters

Explanation:

A contract subject contains one or more filters that define the traffic matching criteria for communication between Cisco ACI endpoint groups. A filter is itself composed of filter entries that can match characteristics such as protocol and transport port. The subject can also define actions such as whether a Layer 4 through Layer 7 service graph is applied and what quality of service priority should be used. Organizing contracts into subjects and filters gives ACI a reusable and structured policy model that is easier to manage than large manually maintained access control lists.

Question 202. What does an ACI filter entry define

  1. Server UUID
  2. Traffic match criteria
  3. Fibre Channel domain ID
  4. VXLAN underlay address

Correct Answer: 2. Traffic match criteria

Explanation:

A filter entry defines the actual traffic fields used to match packets in a Cisco ACI contract. These fields can include information such as protocol type, source port, and destination port. Several filter entries can be grouped into one filter, and one or more filters can then be referenced by a contract subject. This layered policy structure allows administrators to build reusable traffic definitions and apply them consistently across application relationships. The result is a policy model that separates traffic classification from the endpoint groups and applications that consume the contract.

Question 203. Where is the decision to apply an ACI service graph configured

  1. Filter entry
  2. Bridge domain
  3. Contract subject
  4. VRF

Correct Answer: 3. Contract subject

Explanation:

Cisco ACI associates a Layer 4 through Layer 7 service graph with a contract subject. The subject references the traffic filters and can also specify that matching traffic should traverse a firewall, load balancer, or other service device represented by the service graph. This keeps service insertion aligned with application policy rather than physical cabling. A service graph can contain one appliance or a sequence of several service functions. Policy Based Redirect can further enhance this design by actively steering matching traffic toward the selected service node.

Question 204. What must exist before a PBR service graph can be deployed

  1. Logical L4 L7 device
  2. UCS service profile
  3. Fibre Channel zone
  4. FSPF route

Correct Answer: 1. Logical L4 L7 device

Explanation:

A logical Layer 4 through Layer 7 device must be defined before Cisco ACI can deploy a service graph using Policy Based Redirect. Cisco documents a workflow that includes creating the logical device, creating the service graph, defining the PBR policy, building the device selection policy, and associating the graph with a contract subject. The logical device represents the actual firewall, load balancer, or other network service that will process traffic. Without this object, APIC has no service endpoint to select when rendering the graph into the fabric.

Question 205. What is required for inter VRF route leaking in ACI

  1. Contracts and shared subnet settings
  2. STP and LACP
  3. OTV and FSPF
  4. vPC and HSRP

Correct Answer: 1. Contracts and shared subnet settings

Explanation:

Cisco ACI performs inter VRF route leaking through policy abstraction rather than requiring administrators to manually configure traditional route targets and VPN address families. The design uses contracts together with specific shared subnet settings. Cisco notes that the appropriate endpoint group or subnet options must permit the route to be shared between VRFs. APIC then handles the underlying route leaking configuration automatically. Designers must still define the correct provider and consumer policy relationship because a route can be leaked only when the necessary contract and subnet sharing behavior are both present.

Question 206. Which subnet option is required for inter VRF route leaking

  1. Advertised Externally only
  2. Shared Between VRFs
  3. Private to VRF only
  4. No Default SVI Gateway

Correct Answer: 2. Shared Between VRFs

Explanation:

The Shared Between VRFs subnet option is required when a Cisco ACI subnet must participate in inter VRF route leaking. This setting tells the fabric that the prefix can be imported into another VRF when a valid contract relationship exists. Cisco Multi Site design guidance also uses this setting for shared service patterns that span routing domains. The route leaking process is policy driven, so the subnet option alone is not sufficient. An appropriate contract must also exist between the consumer and provider to permit communication across the VRF boundary.

Question 207. Which contract scope is required for inter tenant inter VRF PBR policy

  1. Application profile
  2. VRF
  3. Global
  4. Tenant

Correct Answer: 3. Global

Explanation:

Cisco specifies global contract scope for inter tenant inter VRF service graph policy enforcement. A narrower scope such as VRF or tenant would not allow the contract to span both the tenant and routing boundaries involved in this design. Cisco also requires the consumer and provider subnets to be configured for sharing between VRFs. In Multi Site service integration, the service graph template and contract must be placed so they can be referenced correctly by the provider and consumer environments. Global scope should be used carefully because it creates the broadest contract visibility.

Question 208. What happens if an ACI service graph contract lacks a consumer or provider EPG

  1. The graph may fail to deploy
  2. The APIC reboots
  3. The fabric becomes Layer 2 only
  4. The firewall becomes transparent automatically

Correct Answer: 1. The graph may fail to deploy

Explanation:

A deployed service graph instance may fail to appear if the associated contract does not have a valid consumer and provider endpoint group relationship. Cisco also lists a missing filter or an incorrect contract scope as common reasons why graph deployment fails. APIC must be able to determine which traffic relationship the contract represents before it can render the service graph into the fabric. When service graph instantiation fails, APIC raises faults that can be reviewed under the deployed graph instance to identify the underlying configuration problem.

Question 209. Which service graph mode is used for a routed firewall

  1. Go Through
  2. Go To
  3. Sniffer
  4. Bridge Only

Correct Answer: 2. Go To

Explanation:

Go To is the Cisco ACI service graph function type used for a routed Layer 3 service device such as a routed firewall. In this model, the service node participates in Layer 3 forwarding rather than simply bridging traffic transparently. Cisco Multi Site service integration examples also use the Go To function type for routed firewall designs. This mode differs from Go Through, where the service device acts transparently between network segments. Choosing the correct function type is important because APIC renders different forwarding and service connectivity behavior depending on the selected service mode.

Question 210. Which service graph mode is used for a transparent firewall

  1. Go To
  2. One Arm only
  3. Go Through
  4. VRF Lite

Correct Answer: 3. Go Through

Explanation:

Go Through mode is designed for transparent Layer 2 service insertion in Cisco ACI. A firewall operating in transparent mode bridges traffic instead of becoming the Layer 3 routing point between the connected segments. APIC creates the contract and service graph relationships needed so permitted traffic passes through the service device. Cisco contrasts this with Go To mode, which is intended for routed Layer 3 service nodes. Selecting the appropriate graph mode allows the ACI fabric to represent the real forwarding behavior of the attached firewall or other service appliance.

Question 211. What does an Intersight Storage Policy primarily define

  1. Local disk layout
  2. BGP route policy
  3. EVPN route targets
  4. ACI contract scope

Correct Answer: 1. Local disk layout

Explanation:

An Intersight Storage Policy defines how local disks on supported UCS servers are organized and presented. The policy can create RAID drive groups, virtual drives, and M2 boot drive configuration. It can also define behaviors such as write policy, read policy, strip size, and whether a virtual drive is bootable. Because the policy is reusable, it can be attached through server profiles and templates to provide consistent local storage configuration across many servers. This approach fits the broader Intersight model of managing compute infrastructure through reusable policy objects.

Question 212. Which RAID level is the default in the referenced Intersight drive group model

  1. RAID 0
  2. RAID 1
  3. RAID 5
  4. RAID 10

Correct Answer: 2. RAID 1

Explanation:

The referenced Cisco Intersight storage policy data model lists RAID 1 as the default RAID level for a drive group. RAID 1 mirrors data across drives and provides redundancy against the failure of one drive in the mirrored pair. Cisco Intersight also supports other RAID options such as RAID 0, RAID 5, RAID 6, RAID 10, RAID 50, and RAID 60 depending on the hardware and policy requirements. Designers should choose RAID level according to the workload need for capacity, performance, write overhead, and fault tolerance rather than relying automatically on the default.

Question 213. Which RAID level provides striping without redundancy

  1. RAID 0
  2. RAID 1
  3. RAID 5
  4. RAID 6

Correct Answer: 1. RAID 0

Explanation:

RAID 0 stripes data across multiple drives but does not provide redundancy. It can improve performance and combine drive capacity efficiently, but the loss of any member drive can make the entire virtual disk unavailable. Cisco Intersight storage policies support RAID 0 among several configurable drive group options. RAID 0 may be appropriate for temporary, replicated, or noncritical data where performance and capacity are more important than local fault tolerance. It is generally not a suitable choice for important data that has no other redundancy or recovery mechanism.

Question 214. Which RAID level mirrors data across two drives

  1. RAID 5
  2. RAID 6
  3. RAID 10
  4. RAID 1

Correct Answer: 4. RAID 1

Explanation:

RAID 1 provides mirroring by maintaining identical copies of data across two drives. If one drive fails, the other copy can continue serving the data. The tradeoff is that usable capacity is roughly half of the raw capacity used by the mirror. Cisco Intersight includes RAID 1 as a supported drive group level and lists it as the default in the referenced storage policy model. RAID 1 is commonly selected for boot volumes and other workloads where simple redundancy and predictable recovery are more important than maximizing usable disk capacity.

Question 215. Which RAID level uses distributed parity and tolerates one drive failure

  1. RAID 0
  2. RAID 5
  3. RAID 1
  4. RAID 10

Correct Answer: 2. RAID 5

Explanation:

RAID 5 stripes data and parity across multiple drives and can tolerate the failure of one member drive. It offers greater usable capacity efficiency than mirroring because parity rather than a full duplicate copy provides redundancy. The tradeoff is additional parity calculation and rebuild overhead. Cisco Intersight storage policies support RAID 5 drive groups and virtual drive creation. Designers should evaluate workload write intensity, rebuild time, drive size, and failure tolerance before selecting RAID 5 for production use because the optimal RAID level varies significantly by application and hardware characteristics.

Question 216. Which RAID level can tolerate two drive failures using dual parity

  1. RAID 1
  2. RAID 10
  3. RAID 6
  4. RAID 0

Correct Answer: 3. RAID 6

Explanation:

RAID 6 uses dual distributed parity and can tolerate the failure of two member drives in the same array. This provides stronger fault tolerance than RAID 5, which normally tolerates one drive failure. The additional parity comes with greater write overhead and reduced usable capacity compared with less redundant layouts. Cisco Intersight storage policy models support RAID 6 as one of the available drive group levels. RAID 6 is often considered when large capacity drives and long rebuild times make protection against a second concurrent failure especially important.

Question 217. What is the purpose of a hot spare in a RAID design

  1. Automatically replace capacity after a drive failure
  2. Increase Ethernet bandwidth
  3. Provide BGP redundancy
  4. Replace a Fabric Interconnect

Correct Answer: 1. Automatically replace capacity after a drive failure

Explanation:

A hot spare is an unused drive reserved so the storage controller can begin rebuilding a degraded RAID group automatically when a member drive fails. Cisco Intersight storage policies support dedicated hot spare definitions for manual drive groups. Using a hot spare can reduce the time a RAID group remains in a degraded state because rebuilding does not have to wait for an administrator to physically replace the failed drive first. The spare still consumes drive capacity, so designers must balance additional resiliency against the number of drives available for normal storage use.

Question 218. What does a virtual drive represent in an Intersight Storage Policy

  1. Logical volume presented from a RAID group
  2. Physical switch interface
  3. Fibre Channel VSAN
  4. VXLAN tunnel

Correct Answer: 1. Logical volume presented from a RAID group

Explanation:

A virtual drive is a logical storage volume created from a RAID drive group and presented to the operating system or boot environment. Intersight Storage Policy can define properties such as size, boot drive status, access policy, read policy, write policy, cache behavior, and strip size. Multiple virtual drives can be created from a suitable drive group depending on the storage controller and policy design. Separating the physical drive layout from the logical virtual drive presentation allows administrators to create reusable local storage configurations through server profiles and templates.

Question 219. Which Intersight virtual drive setting marks a volume for boot use

  1. Boot Drive
  2. Read Ahead
  3. Drive Cache
  4. Strip Size

Correct Answer: 1. Boot Drive

Explanation:

The Boot Drive setting identifies a virtual drive as intended for boot use within the Intersight storage policy model. Cisco also requires the server boot order policy to reference the appropriate local storage device so the system actually attempts to boot from that volume. Storage Policy and Boot Order Policy therefore work together in a local boot design. The Storage Policy creates the local RAID and virtual disk layout, while the Boot Order Policy tells the server firmware which device should be used during system startup.

Question 220. Which policy works with Storage Policy to boot a UCS server from local disks

  1. Boot Order Policy
  2. Flow Control Policy
  3. NTP Policy
  4. Multicast Policy

Correct Answer: 1. Boot Order Policy

Explanation:

A Boot Order Policy works together with an Intersight Storage Policy when a UCS server must boot from locally attached storage. The Storage Policy creates the required RAID drive group and virtual drive, while the Boot Order Policy defines the local disk device in the server boot sequence. Cisco documents both policies as necessary parts of a local storage boot workflow. The completed policies are then applied through the server profile before the operating system is installed. This separation keeps storage layout and firmware boot behavior modular and reusable across servers.