View Full Cisco CCNP Data Center 300-635 Exam Dumps and Practice Test Dumps
Question 261.
Which Cisco ACI object provides the administrative boundary that contains objects such as VRFs, Bridge Domains, Application Profiles, and contracts?
- Tenant
2. Endpoint Group
3. Filter
4. Fabric Node
Correct Answer: 1
Explanation:
A tenant provides an administrative and policy boundary in Cisco ACI. Objects such as VRFs, Bridge Domains, Application Profiles, Endpoint Groups, contracts, and filters can exist within a tenant. This structure allows different business units, applications, or customers to maintain separate policy spaces. Automation scripts often begin by identifying or creating the appropriate tenant before deploying dependent objects. EPGs and filters exist deeper in the hierarchy, while fabric nodes represent physical infrastructure. Understanding object hierarchy is important because APIC API requests frequently depend on correct parent-child relationships.
Question 262.
Which ACI object should be created to provide a separate Layer 3 routing context within a tenant?
- Application Profile
2. VRF
3. Contract
4. Filter
Correct Answer: 2
Explanation:
A VRF defines a Layer 3 routing context in Cisco ACI. Bridge Domains are associated with VRFs so their subnets participate in the appropriate routing domain. Multiple VRFs can exist within a tenant to provide routing separation where required. Application Profiles group EPGs, contracts define communication policy, and filters identify traffic characteristics. In API-driven deployments, automation should ensure that dependent objects are created in the correct sequence and reference the intended VRF accurately.
Question 263.
Which ACI object typically contains one or more subnets and provides Layer 2 forwarding behavior?
- Contract Subject
2. Endpoint Group
3. Bridge Domain
4. Tenant only
Correct Answer: 3
Explanation:
A Bridge Domain defines Layer 2 forwarding behavior in ACI and may contain one or more subnets that provide Layer 3 gateway functionality. It is associated with a VRF and can be referenced by one or more EPGs. Bridge Domains also contain policies related to endpoint learning and flooding behavior. Contracts and contract subjects control communication policy rather than forwarding context. When automating ACI, a script may create the VRF, Bridge Domain, subnet, and EPG relationships as a coordinated set.
Question 264.
Which ACI object is most directly associated with defining application communication policy between EPGs?
- Bridge Domain
2. VLAN Pool
3. Physical Domain
4. Contract
Correct Answer: 4
Explanation:
A contract controls which communications are permitted between Endpoint Groups. EPGs provide or consume contracts, and contract subjects use filters to define matching traffic characteristics such as protocol and destination port. Bridge Domains provide forwarding context, while VLAN pools and physical domains are associated with access-policy constructs. Contracts are a central part of the policy model because they allow application relationships to be expressed independently of specific endpoint addresses.
Question 265.
Which ACI construct is used to define traffic criteria such as TCP port 443 for use within a contract?
- Filter
2. Application Profile
3. VRF
4. Tenant
Correct Answer: 1
Explanation:
A filter specifies traffic-matching characteristics such as EtherType, IP protocol, source port, and destination port. Contract subjects reference filters to define the communication that a contract permits. For example, a filter could match TCP destination port 443 to represent HTTPS traffic. Application Profiles, VRFs, and tenants serve broader structural functions. Reusable filters are useful in automation because the same traffic definition can be referenced consistently by multiple policy constructs.
Question 266.
Which ACI API query is most appropriate when the exact Distinguished Name of a managed object is already known?
- Class query
2. DN query
3. ARP query
4. DNS query
Correct Answer: 2
Explanation:
A Distinguished Name query directly targets a specific object in the ACI Management Information Tree. Because the DN represents the complete hierarchical path to the object, it allows precise retrieval or modification without searching an entire class. Class queries are more appropriate when automation needs multiple objects of the same type. ARP and DNS are unrelated to APIC object queries. DN-based operations are especially useful for validating one specific object before an update or deletion.
Question 267.
Which Cisco ACI API approach is best when an engineer wants to discover every EPG in a fabric or tenant scope?
- Repeated CLI scraping
2. ICMP scanning
3. Class query
4. SNMP trap collection only
Correct Answer: 3
Explanation:
A class query retrieves all managed objects belonging to a specified ACI class, making it appropriate for discovering multiple EPGs. Filters can narrow the returned objects to a particular tenant or set of attributes. Repeated CLI parsing is less efficient and more fragile than structured API queries. ICMP and SNMP traps do not provide the same object-model discovery capabilities. Class queries are commonly used for inventory, compliance, and configuration auditing.
Question 268.
Which safeguard should an automation script use before deleting objects returned by a broad APIC class query?
- Delete every returned object immediately
2. Disable APIC audit logging
3. Ignore the returned Distinguished Names
4. Validate object identity and scope against explicit criteria
Correct Answer: 4
Explanation:
Broad class queries can return many objects, so destructive automation must validate exactly which objects are intended targets. The script should verify Distinguished Names, tenant scope, object attributes, environment identifiers, and any other required criteria before deleting anything. Dry-run modes, explicit allowlists, and approval gates can provide further protection. Disabling logging or blindly deleting query results creates significant risk. A small filtering error in automation can otherwise cause widespread configuration loss.
Question 269.
Which Cisco UCS object is used to abstract server identity and configuration from physical hardware?
- Service Profile
2. ACI Contract
3. Nexus VRF
4. VLAN Pool
Correct Answer: 1
Explanation:
A Cisco UCS Service Profile defines a server’s logical identity and configuration independently of the physical hardware. It can include UUID, MAC addresses, boot settings, network connectivity, storage policies, and firmware-related configuration. This abstraction supports rapid server replacement and consistent provisioning. ACI contracts, VRFs, and VLAN pools are networking constructs and do not provide server identity abstraction. Service Profiles are particularly valuable in automated server deployment workflows.
Question 270.
Which Cisco UCS construct allows many Service Profiles to be created from one standardized definition?
- Firmware bundle only
2. Service Profile template
3. ARP table
4. Port channel
Correct Answer: 2
Explanation:
A Service Profile template provides a reusable configuration model for creating many similar Service Profiles. It can reference common server policies and identity settings, reducing manual configuration and improving consistency. Templates are especially useful when deploying large groups of servers with standardized roles. Depending on the template type, derived profiles may continue to inherit certain changes. Firmware bundles, ARP tables, and port channels do not provide this server-profile templating function.
Question 271.
Which Cisco UCS interface traditionally uses XML for programmatic management?
- Cisco UCS Manager API
2. RESTCONF only
3. EEM only
4. CDP
Correct Answer: 1
Explanation:
Cisco UCS Manager traditionally exposes an XML-based API built around a hierarchical managed-object model. Automation can use this API directly or through tools such as the Cisco UCS Python SDK and UCS PowerTool. The API enables querying and changing Service Profiles, policies, server inventory, and related infrastructure objects. RESTCONF, EEM, and CDP serve different functions. Understanding the XML API is helpful when troubleshooting or developing deeper UCS automation integrations.
Question 272.
Which Cisco UCS tool is designed primarily for PowerShell-based automation?
- Cobra SDK
2. UCS PowerTool
3. EEM
4. Guest Shell
Correct Answer: 2
Explanation:
Cisco UCS PowerTool provides PowerShell cmdlets for managing UCS infrastructure. It allows administrators to query inventory, create and modify policies, manage Service Profiles, and automate repetitive tasks using familiar PowerShell syntax. Cobra SDK is associated with Cisco ACI, while EEM and Guest Shell are more closely associated with network-device automation. PowerTool is useful for teams that already rely on Windows-based automation and PowerShell workflows.
Question 273.
Which Cisco platform provides cloud-based centralized infrastructure management with a REST API for supported UCS environments?
- Cisco Intersight
2. Cisco ISE
3. Cisco CUCM
4. Cisco Expressway
Correct Answer: 1
Explanation:
Cisco Intersight provides cloud-based management for supported infrastructure and exposes REST APIs for programmatic access. Automation can use the API to retrieve inventory, work with policies, manage server profiles, and integrate infrastructure data into orchestration workflows. Cisco ISE focuses on identity and access control, while CUCM and Expressway are collaboration platforms. Intersight is particularly relevant to modern data center automation because it provides a centralized API-driven operational model across multiple infrastructure domains.
Question 274.
Which API capability should be used when an Intersight query needs only resources belonging to a particular organization?
- Pagination only
2. Filtering
3. Packet capture
4. Route redistribution
Correct Answer: 2
Explanation:
Filtering allows an API client to restrict returned objects based on attributes such as organization, model, status, or name. This reduces response size and minimizes client-side processing. Pagination, by contrast, divides a large result set into multiple pages but does not inherently narrow which records match the query. Packet capture and route redistribution are unrelated networking functions. Efficient filters are particularly valuable when working with large centralized inventories.
Question 275.
Which Ansible feature is best suited to placing reusable tasks, templates, variables, and handlers into a standardized structure?
- Role
2. Inventory host only
3. Vault password file only
4. Callback plugin only
Correct Answer: 1
Explanation:
An Ansible role organizes related automation content into a standardized directory structure. A role can contain tasks, handlers, templates, files, defaults, and variables, making it easier to reuse the same logic across multiple playbooks and environments. This reduces duplication and improves maintainability. Inventory defines targets, Vault protects secrets, and callback plugins affect output or execution behavior. Roles are particularly useful as automation projects grow in size and complexity.
Question 276.
Which Ansible keyword should be used when a task must execute only if a previous query shows that a VLAN is absent?
- notify
2. when
3. register only
4. vars_files only
Correct Answer: 2
Explanation:
The when keyword provides conditional execution. A playbook can first query the current state, save the result with register, and then use when to create a VLAN only if the query shows that it is missing. This supports idempotent behavior because the playbook avoids unnecessary changes. notify triggers handlers, while register stores data rather than controlling execution by itself. Conditionals are fundamental for state-aware automation.
Question 277.
Which Terraform command initializes providers, modules, and backend configuration for a working directory?
- terraform init
2. terraform apply
3. terraform destroy
4. terraform output
Correct Answer: 1
Explanation:
terraform init prepares a Terraform working directory for use. It initializes the configured backend, downloads required provider plugins, and retrieves referenced modules where necessary. It typically runs before plan or apply operations. Initialization itself does not normally change managed infrastructure. terraform apply performs resource changes, terraform destroy removes managed resources, and terraform output displays selected values. Proper initialization ensures Terraform has the dependencies needed to evaluate configuration.
Question 278.
Which Terraform command provides a preview of proposed infrastructure changes before execution?
- terraform fmt
2. terraform plan
3. terraform state rm
4. terraform providers
Correct Answer: 2
Explanation:
terraform plan evaluates the declared configuration against the current known state and shows which resources would be created, updated, replaced, or destroyed. Reviewing this preview is a key safety control before making production changes. It helps engineers detect unexpected resource replacement or deletion before execution. terraform fmt formats configuration files, while state and provider commands serve other purposes. In controlled workflows, plan output can be incorporated into CI/CD review and approval stages.
Question 279.
Which NETCONF operation is used to retrieve both configuration and operational state information?
- <get>
2. <commit>
3. <lock>
4. <edit-config>
Correct Answer: 1
Explanation:
The NETCONF <get> operation retrieves configuration and operational state information from a device. Filters can be applied to limit the response to relevant portions of the YANG data model. <get-config> is used specifically for configuration information from a selected datastore. <edit-config> changes configuration, <lock> controls access to a datastore, and <commit> activates staged candidate configuration where supported. Structured retrieval makes NETCONF useful for model-driven automation.
Question 280.
A team wants production deployment to stop automatically whenever a Terraform plan shows an unauthorized resource deletion. Which control best supports this requirement?
- Disable audit logs
2. Ignore the plan output
3. Add a policy or quality gate in the CI/CD pipeline that blocks the deployment
4. Store production credentials directly in source code
Correct Answer: 3
Explanation:
A CI/CD quality or policy gate can inspect Terraform plan output and stop deployment when prohibited actions, such as unauthorized resource deletion, are detected. This allows organizations to enforce infrastructure policy automatically before terraform apply executes. The same workflow can require manual approval for high-impact changes. Ignoring the plan defeats an important safety mechanism, while disabling logs or embedding credentials weakens security. Policy-driven deployment gates combine automation speed with controlled production governance.