Cisco CCNP Data Center 300-635 Practice Test Questions and Exam Dumps Part12 Q221-240

View Full Cisco CCNP Data Center 300-635 Exam Dumps and Practice Test Dumps

 

Question 221.

Which Cisco ACI object is used to define a group of endpoints that share the same policy requirements?

  1. Endpoint Group
    2. Bridge Domain only
    3. Contract Filter
    4. Fabric Node

Correct Answer: 1

Explanation:

An Endpoint Group, or EPG, is a logical collection of endpoints that share common policy requirements within Cisco ACI. Endpoints in the same EPG are typically associated with similar application roles or security requirements. Communication between EPGs is controlled through contracts. An EPG is usually created within an Application Profile and associated with a Bridge Domain for network connectivity. Bridge Domains provide forwarding context, while filters describe traffic characteristics used by contracts. Understanding how EPGs fit into the ACI object model is important for API-driven automation because EPGs are represented as managed objects that can be created, queried, and modified programmatically.

Question 222.

Which Cisco ACI object provides the Layer 2 forwarding domain used by one or more EPGs?

  1. Contract
    2. Bridge Domain
    3. Tenant only
    4. Filter only

Correct Answer: 2

Explanation:

A Bridge Domain provides the Layer 2 forwarding context in Cisco ACI. EPGs are associated with Bridge Domains, which can also contain subnet configuration and connect to a Layer 3 routing context through a VRF. Bridge Domains include settings for flooding, endpoint learning, and routing behavior. Contracts define communication policy, while filters specify traffic characteristics. In automation workflows, Bridge Domains are often created before EPGs so the required forwarding structure already exists when the application policy is deployed.

Question 223.

Which ACI object provides the Layer 3 routing context for Bridge Domains?

  1. Application Profile
    2. Contract
    3. VRF
    4. Physical Domain

Correct Answer: 3

Explanation:

A VRF provides the Layer 3 routing context in Cisco ACI. One or more Bridge Domains can be associated with the same VRF while remaining distinct Layer 2 domains. This allows ACI to separate forwarding contexts and maintain routing isolation between tenants or applications. Application Profiles organize EPGs, contracts regulate communication, and physical domains associate policy with physical infrastructure. Automation scripts commonly create or identify the VRF before creating dependent Bridge Domains and application objects.

Question 224.

Which ACI construct defines permitted communication between EPGs?

  1. VLAN Pool
    2. Interface Profile
    3. Physical Domain
    4. Contract

Correct Answer: 4

Explanation:

Contracts define communication policy between Endpoint Groups in Cisco ACI. One EPG can provide a contract while another consumes it. Contract subjects reference filters that describe allowed protocols, ports, or other traffic characteristics. This application-centric approach allows communication policy to be expressed in terms of logical endpoint relationships rather than only IP addresses. VLAN pools and interface profiles serve access-policy functions, while physical domains connect policy constructs to physical infrastructure. Contracts are frequently created and associated programmatically through APIC APIs.

Question 225.

Which ACI object defines traffic-matching criteria such as TCP destination port 443?

  1. Filter
    2. Tenant
    3. Bridge Domain
    4. Application Profile

Correct Answer: 1

Explanation:

An ACI filter defines traffic characteristics such as protocol, source or destination port, and EtherType. Filters are referenced by contract subjects to describe which traffic should be permitted or processed between EPGs. For example, a filter may match TCP destination port 443 for HTTPS traffic. Tenants, Bridge Domains, and Application Profiles provide broader structural functions. In automated deployments, filters can be standardized and reused to ensure consistent application policy across environments.

Question 226.

Which Cisco ACI object groups EPGs that belong to the same application?

  1. VRF
    2. Application Profile
    3. VLAN Pool
    4. Interface Selector

Correct Answer: 2

Explanation:

An Application Profile logically groups Endpoint Groups associated with an application. For example, a three-tier application might have separate web, application, and database EPGs contained within one Application Profile. Contracts then control communication between those groups. VRFs provide routing context, while VLAN pools and interface selectors are associated with fabric access policy. Application Profiles are represented as managed objects in APIC and can be deployed consistently through REST APIs, SDKs, Ansible, or Terraform.

Question 227.

Which APIC API query should an automation script use when it knows the exact distinguished name of an ACI object?

  1. Class query only
    2. DNS lookup
    3. Distinguished-name query
    4. ARP query

Correct Answer: 3

Explanation:

A distinguished-name query is appropriate when the script knows the exact DN of the managed object it wants to retrieve. The DN uniquely identifies the object’s position in the ACI management information tree. A class query is more appropriate when the automation needs to retrieve multiple objects of the same managed-object class. DNS and ARP are unrelated to APIC’s object model. DN-based retrieval is useful when modifying or validating a specific object because it avoids returning unrelated records.

Question 228.

What is the main benefit of using an APIC class query instead of repeatedly querying many individual distinguished names?

  1. It bypasses authentication
    2. It disables object hierarchy
    3. It converts JSON to CLI
    4. It can retrieve multiple objects of the same class efficiently

Correct Answer: 4

Explanation:

A class query can retrieve multiple managed objects belonging to the same class in one operation. This is useful for inventory collection, compliance analysis, and bulk inspection of objects such as EPGs, Bridge Domains, or contracts. Query filters can further narrow the returned results. Repeatedly querying individual distinguished names may generate unnecessary API traffic and increase execution time. Class queries still require appropriate authentication and do not alter the underlying ACI hierarchy.

Question 229.

Which Cisco UCS construct can define server identity, boot configuration, network settings, and firmware policies independently of physical hardware?

  1. Service Profile
    2. ACI Contract
    3. Nexus Port Channel
    4. VRF

Correct Answer: 1

Explanation:

A Cisco UCS Service Profile defines a server’s logical identity and operational configuration independently of a specific physical server. It can include UUID information, MAC address assignments, boot order, firmware policies, network interfaces, storage connectivity, and other settings. This policy-driven design makes server replacement and provisioning more consistent. Contracts and VRFs belong to networking environments, while a Nexus port channel aggregates physical links. Service Profiles are especially valuable for automation because they can be created from templates and associated with servers programmatically.

Question 230.

Which Cisco UCS capability allows multiple Service Profiles to inherit a common standardized configuration?

  1. VLAN trunk
    2. Service Profile template
    3. ARP table
    4. Syslog server

Correct Answer: 2

Explanation:

A Service Profile template provides a reusable standardized definition from which multiple Service Profiles can be created. This helps ensure that server configurations remain consistent and reduces manual configuration effort. Templates can include policy references and other common server settings. Depending on the template type, derived profiles may remain associated with the template for future updates. VLAN trunks, ARP tables, and Syslog servers serve unrelated functions. Template-based provisioning is well suited to large-scale server automation.

Question 231.

Which Cisco tool provides PowerShell cmdlets for automating UCS infrastructure?

  1. Cisco UCS PowerTool
    2. Wireshark
    3. EEM
    4. Ansible Vault

Correct Answer: 1

Explanation:

Cisco UCS PowerTool provides PowerShell cmdlets that enable administrators to automate UCS management tasks. Engineers can connect to UCS environments, retrieve inventory, manage policies, create or modify Service Profiles, and perform repetitive operations through scripts. PowerTool is particularly useful in organizations that already use PowerShell extensively. Wireshark performs packet analysis, EEM provides event-driven device automation, and Ansible Vault protects secrets. PowerTool exposes UCS management functionality in a form that integrates naturally with PowerShell workflows.

Question 232.

Which Cisco UCS automation approach provides Python classes for interacting with UCS managed objects?

  1. SNMP traps only
    2. Cisco UCS Python SDK
    3. FTP scripts
    4. ICMP automation

Correct Answer: 2

Explanation:

The Cisco UCS Python SDK provides Python classes and methods that represent UCS managed objects and simplify programmatic interaction with UCS Manager. Developers can use it to query inventory, create policies, configure Service Profiles, and manage other UCS resources. The SDK abstracts much of the underlying XML API complexity while retaining access to the UCS object model. SNMP traps primarily provide notifications, while FTP and ICMP do not provide equivalent UCS configuration capabilities.

Question 233.

Which Cisco Intersight feature allows automation clients to retrieve only objects that match specified criteria?

  1. Filtering
    2. Packet capture
    3. STP convergence
    4. LACP negotiation

Correct Answer: 1

Explanation:

Filtering allows an Intersight API client to request only resources that match specific properties such as model, status, organization, or name. This reduces response size and processing overhead, particularly in large infrastructure environments. Without filtering, a script might retrieve thousands of records and discard most of them locally. Packet capture, STP, and LACP are unrelated to API data selection. Efficient filtering improves both performance and clarity in automation workflows.

Question 234.

Which API technique must an automation script implement if Intersight returns a large collection in multiple result sets?

  1. DNS recursion
    2. Pagination
    3. Route summarization
    4. ARP suppression

Correct Answer: 2

Explanation:

Pagination divides large API result sets into smaller groups of records. The client must request subsequent pages using the mechanism supported by the API, such as offsets, limits, page values, or continuation tokens. If pagination is ignored, the script may work with an incomplete inventory and make incorrect decisions. DNS, routing, and ARP functions are unrelated to REST API pagination. Good automation should continue processing pages until the required dataset has been retrieved fully.

Question 235.

Which Ansible feature is best suited to dynamically generate Nexus configuration text using device-specific variables?

  1. Jinja2 template
    2. Fact cache only
    3. Callback plugin
    4. Inventory file only

Correct Answer: 1

Explanation:

Jinja2 templates generate text dynamically using variables, loops, and conditionals. A single template can produce different Nexus configurations based on device-specific values such as hostnames, interfaces, VLANs, or IP addresses. This improves consistency and reduces duplicated configuration. Inventory can store variables, but the template performs the actual rendering. Callback plugins affect Ansible execution output, and fact caches store gathered information. Templates are particularly valuable when the desired end result is structured CLI configuration.

Question 236.

Which Ansible keyword allows a task to run only if a condition is satisfied?

  1. notify
    2. register
    3. loop
    4. when

Correct Answer: 4

Explanation:

The when keyword provides conditional execution in Ansible. It allows a task to run only when a Boolean expression evaluates as true. For example, a task may execute only when a queried VLAN does not already exist or when the target platform matches a required device type. register stores task results, loop repeats a task, and notify triggers handlers. Conditions make playbooks more flexible and help reduce unnecessary changes.

Question 237.

Which Terraform command should an engineer use first to see whether a configuration would create, modify, or destroy resources?

  1. terraform plan
    2. terraform destroy
    3. terraform state rm
    4. terraform output

Correct Answer: 1

Explanation:

terraform plan shows the proposed difference between the current known state and the declared desired configuration. It identifies which resources would be created, updated, replaced, or destroyed. Reviewing this output is an important safeguard before production deployment. terraform destroy removes resources, while state-management and output commands serve different purposes. In mature workflows, plans can be stored and reviewed through CI/CD systems before terraform apply is authorized.

Question 238.

Which Terraform feature allows reusable infrastructure logic to be packaged and called from multiple configurations?

  1. State lock only
    2. Module
    3. Output variable only
    4. Backend only

Correct Answer: 2

Explanation:

A Terraform module packages a collection of resources and supporting logic into a reusable component. A module can accept input variables and expose outputs, allowing teams to standardize common infrastructure patterns while still supporting environment-specific values. This reduces duplicated code and improves consistency. Backends store state, while state locking controls concurrent changes. Outputs expose selected values but do not package reusable infrastructure logic. Well-designed modules are a fundamental part of scalable infrastructure-as-code practices.

Question 239.

Which NETCONF operation retrieves only configuration data from a selected datastore?

  1. <get-config>
    2. <commit>
    3. <lock>
    4. <close-session>

Correct Answer: 1

Explanation:

The NETCONF <get-config> operation retrieves configuration data from a selected datastore such as running or candidate, depending on device support. It differs from <get>, which can retrieve both configuration and operational state information. Filters can be used to limit the response. <commit> activates candidate changes, <lock> reserves a datastore, and <close-session> ends the NETCONF session. Choosing the correct retrieval operation helps automation obtain only the information needed for the task.

Question 240.

A team wants infrastructure changes to be tested automatically, reviewed, and deployed to production only after all required checks pass. Which approach is most appropriate?

  1. Run scripts directly from personal laptops
    2. Disable version control
    3. Use a CI/CD pipeline with testing, policy checks, and approval gates
    4. Store production passwords directly in the repository

Correct Answer: 3

Explanation:

A CI/CD pipeline can enforce a controlled promotion process for infrastructure automation. Early stages can perform syntax validation, linting, unit tests, integration tests, security checks, and policy validation. High-impact production changes can then require peer review or explicit approval before deployment. This creates a repeatable and auditable workflow while reducing the risk of untested changes. Direct execution from personal workstations lacks consistent controls, and storing credentials in source code creates unnecessary security exposure.