View Full Cisco CCNP Data Center 300-635 Exam Dumps and Practice Test Dumps
Question 301.
Which Cisco ACI concept allows an automation script to identify a specific managed object by its complete hierarchical path?
- Distinguished Name
2. Relative Name
3. VLAN ID
4. Contract Subject
Correct Answer: 1
Explanation:
A Distinguished Name, or DN, identifies the complete path of an ACI managed object within the Management Information Tree. It reflects the parent-child hierarchy that leads to the object and is commonly used in APIC API requests when a script needs to retrieve, modify, or delete one specific object. A Relative Name identifies an object only relative to its parent. VLAN IDs and contract subjects serve different functions. Understanding DNs is important because automation often depends on precise object addressing, especially when validating or changing existing ACI configuration.
Question 302.
Which Cisco ACI identifier describes a managed object only relative to its parent object?
- DN
2. RN
3. UUID only
4. VRF ID
Correct Answer: 2
Explanation:
The Relative Name, or RN, identifies an ACI managed object relative to its immediate parent. A Distinguished Name is formed from the hierarchy of Relative Names leading from the root to the object. This distinction is useful when creating child objects programmatically because the parent context determines the full path. UUIDs and VRF identifiers serve other purposes. Automation engineers should understand both DNs and RNs when working directly with the APIC object model or using SDKs that map closely to that hierarchy.
Question 303.
Which top-level APIC API response field commonly contains managed-object data returned by a query?
- routeTable
2. cliData
3. imdata
4. switchObjects
Correct Answer: 3
Explanation:
APIC API responses commonly place returned managed objects inside the imdata array. Each entry normally includes the managed-object class and its attributes, and may include children depending on the query parameters. Automation scripts often parse imdata to retrieve tenants, EPGs, Bridge Domains, contracts, or operational objects. Understanding the expected response format allows scripts to validate whether a query returned the required object and avoid acting on empty or unexpected data.
Question 304.
Which APIC API response value commonly indicates how many objects were returned by a query?
- recordSize
2. objectTotal
3. returnedRows
4. totalCount
Correct Answer: 4
Explanation:
The totalCount field commonly indicates the number of managed objects returned or matched in an APIC API response. Automation can use this value to validate whether the result scope matches expectations. For example, a script expecting one tenant could stop if the query unexpectedly returns many objects. This is particularly important before update or deletion operations. Response metadata should be treated as part of the script’s validation logic rather than ignored.
Question 305.
Which Cisco ACI SDK is designed to provide Python classes corresponding to APIC managed objects?
- Cobra SDK
2. Scapy
3. Paramiko only
4. Flask
Correct Answer: 1
Explanation:
The Cisco ACI Cobra SDK provides Python classes that closely map to managed objects in the ACI information model. Developers can use these classes to create object hierarchies, query existing configuration, and commit changes without manually building every REST URL and payload. Scapy is primarily used for packet manipulation, Paramiko provides SSH functionality, and Flask is a web framework. Cobra can make complex ACI automation easier, but engineers still need to understand the underlying object relationships and hierarchy.
Question 306.
Which API query should be used when a script needs to retrieve every object belonging to a particular ACI class?
- DN query only
2. Class query
3. DNS query
4. ICMP query
Correct Answer: 2
Explanation:
A class query retrieves all managed objects belonging to a specified ACI class. This is useful for discovery, inventory, compliance checking, and bulk analysis. A DN query targets one exact object when its hierarchical path is known. DNS and ICMP are unrelated to the APIC object model. In large fabrics, class queries should often be combined with filters so the script retrieves only the relevant subset of objects and avoids unnecessary processing.
Question 307.
A script must find all EPGs with a particular naming pattern without retrieving every EPG in the entire fabric. Which capability should it use?
- Disable pagination
2. Query only the root object
3. Class query with an appropriate filter
4. Use ARP resolution
Correct Answer: 3
Explanation:
A filtered class query is the most efficient approach because it allows APIC to return only managed objects that match the specified criteria. This reduces response size, network overhead, and client-side processing. Retrieving every EPG and filtering locally may work but becomes inefficient in large environments. ARP has no relationship to APIC API object selection. Efficient server-side filtering is a core design principle for scalable automation.
Question 308.
Which safeguard is most important before an automation script performs bulk deletion of ACI objects found through a class query?
- Disable APIC logging
2. Delete all objects immediately
3. Ignore tenant context
4. Validate each object’s DN, tenant, and intended scope before deletion
Correct Answer: 4
Explanation:
Bulk deletion is potentially destructive, so the script should validate every target against explicit selection criteria before making changes. This can include checking the Distinguished Name, tenant, object type, environment identifier, ownership, and naming policy. Dry-run output, approval gates, and allowlists can provide further protection. Disabling logging or ignoring tenant context increases risk. Automation can make mistakes at scale very quickly, so destructive operations should include multiple layers of validation.
Question 309.
Which Cisco UCS object abstracts server identity and policies from the physical server hardware?
- Service Profile
2. VLAN Pool
3. Contract
4. Bridge Domain
Correct Answer: 1
Explanation:
A Cisco UCS Service Profile abstracts logical server identity and configuration from physical hardware. It can include UUID information, network identity, boot configuration, storage settings, firmware policies, and other attributes. This makes provisioning and hardware replacement more consistent because the logical identity can be associated with another compatible server. VLAN Pools, contracts, and Bridge Domains are networking constructs and do not provide server identity abstraction.
Question 310.
Which UCS construct is best suited for generating many Service Profiles from one standard configuration?
- Boot policy only
2. Service Profile template
3. Syslog policy
4. ARP table
Correct Answer: 2
Explanation:
A Service Profile template provides a reusable definition from which multiple Service Profiles can be created. This helps standardize server deployments and reduces repetitive manual configuration. Templates can reference common policies for BIOS, firmware, boot order, networking, and other settings. They are especially useful in automated provisioning workflows because a script can create many profiles from one approved baseline rather than building each server definition separately.
Question 311.
Which Cisco UCS automation interface is traditionally based on XML managed-object requests?
- UCS Manager API
2. RESTCONF only
3. EEM
4. CDP
Correct Answer: 1
Explanation:
Cisco UCS Manager traditionally exposes an XML-based API built around a managed-object hierarchy. Scripts can use the API directly or rely on higher-level tools such as the UCS Python SDK or UCS PowerTool. The XML API supports querying inventory, creating policies, managing Service Profiles, and performing other administrative operations. RESTCONF and EEM serve different purposes, while CDP is a neighbor-discovery protocol.
Question 312.
Which Cisco UCS tool is designed for PowerShell-based infrastructure automation?
- Cobra SDK
2. UCS PowerTool
3. Guest Shell
4. RESTCONF
Correct Answer: 2
Explanation:
Cisco UCS PowerTool provides PowerShell cmdlets for programmatically managing UCS infrastructure. Administrators can retrieve inventory, create or update Service Profiles, work with policies, and automate repetitive tasks using standard PowerShell constructs such as functions, loops, and pipelines. Cobra is associated with ACI, while Guest Shell and RESTCONF are used in other programmability contexts. PowerTool is especially useful in environments where PowerShell is already part of the operational toolset.
Question 313.
Which Cisco platform provides centralized cloud-based API access for managing supported UCS infrastructure?
- Cisco Intersight
2. Cisco ISE
3. Cisco CUCM
4. Cisco Expressway
Correct Answer: 1
Explanation:
Cisco Intersight provides cloud-based management for supported Cisco infrastructure and exposes APIs for automation. Scripts can retrieve inventory, manage policies and profiles, and integrate infrastructure information into larger workflows. This centralized model is useful when organizations manage multiple UCS domains or distributed infrastructure. Cisco ISE focuses on identity, while CUCM and Expressway are collaboration platforms. Intersight is therefore the relevant platform for cloud-based UCS-centric automation.
Question 314.
Which API mechanism is best for retrieving only Intersight objects that match a specific organization or model?
- Pagination only
2. Filtering
3. Route redistribution
4. VLAN pruning
Correct Answer: 2
Explanation:
Filtering allows an Intersight API request to return only objects matching selected criteria such as organization, model, name, or status. This minimizes response size and client-side processing. Pagination instead divides a large matching result set into smaller groups. The two mechanisms are often used together. Routing and VLAN concepts are unrelated to REST API result selection. Efficient filtering is important when scripts interact with large infrastructure inventories.
Question 315.
Which Ansible feature is most appropriate for organizing reusable tasks, handlers, templates, and variables into a structured package?
- Role
2. Vault password only
3. Inventory host only
4. Callback plugin only
Correct Answer: 1
Explanation:
An Ansible role packages reusable automation content in a standardized directory structure. It can include tasks, handlers, templates, defaults, variables, and supporting files. Roles help teams avoid duplicated playbook logic and make automation easier to maintain. For example, a role could define the standard configuration for Nexus interfaces or a repeatable compliance check. Inventory identifies targets, while Vault protects sensitive information. Roles are particularly valuable in larger automation projects.
Question 316.
Which Ansible feature runs a follow-up task only when another task reports that it made a change?
- Inventory
2. Loop
3. Register
4. Handler
Correct Answer: 4
Explanation:
Ansible handlers are special tasks triggered by notifications from other tasks that report a change. They are commonly used for actions that should occur only when necessary, such as restarting a service, reloading a configuration, or performing post-change validation. This supports idempotent workflows because the follow-up action is skipped when nothing changed. register stores task results, while loops repeat tasks and inventory identifies hosts.
Question 317.
Which Terraform construct packages multiple related resources into a reusable component?
- Module
2. Provider only
3. Backend only
4. State lock
Correct Answer: 1
Explanation:
A Terraform module groups resources and logic into a reusable building block. Modules can accept input variables and expose outputs, allowing the same implementation to be reused across multiple environments or projects. This supports consistency and reduces duplicated code. Providers define integrations with external APIs, backends manage state storage, and state locks help prevent concurrent changes. Modules are one of the primary techniques for structuring maintainable infrastructure-as-code projects.
Question 318.
Which Terraform command should be run to preview proposed infrastructure changes before applying them?
- terraform destroy
2. terraform plan
3. terraform state rm
4. terraform output
Correct Answer: 2
Explanation:
terraform plan shows the changes Terraform intends to make based on the current known state and the desired configuration. It identifies resources that would be created, changed, replaced, or destroyed. Reviewing this output before applying changes is an important safety step, particularly in production. A plan can also be evaluated in CI/CD pipelines for policy violations or unexpected destructive actions before approval.
Question 319.
Which NETCONF capability allows a client to stage configuration changes and then activate them together?
- Candidate datastore
2. Syslog buffer
3. ARP cache
4. DHCP binding table
Correct Answer: 1
Explanation:
The candidate datastore, when supported by the device, allows configuration changes to be prepared separately from the active running configuration. The client can make multiple edits, validate them, and then use a commit operation to activate the changes together. This reduces the risk of leaving a device in an inconsistent intermediate state. Automation should inspect the device’s advertised NETCONF capabilities before assuming candidate functionality is available.
Question 320.
A production automation pipeline detects that a proposed infrastructure change would remove a critical object even though all syntax tests pass. What should happen next?
- Deploy immediately because syntax is valid
2. Ignore the proposed deletion
3. Block deployment and require policy validation or explicit approval
4. Disable audit logging and continue
Correct Answer: 3
Explanation:
Syntax validation confirms that code is structurally correct, but it does not determine whether the proposed infrastructure change is operationally acceptable. A critical deletion should trigger a policy or approval gate that stops deployment until the change is reviewed. Mature CI/CD workflows combine automated testing with plan inspection, security controls, and human approval for high-impact actions. Ignoring destructive changes or disabling logging removes important safeguards and can result in severe production impact.