View Full Cisco CCNP Data Center 300-610 Exam Dumps and Practice Test Dumps.
Question 341. Which ACI protocol reports local endpoints to spine switches
- FSPF
- LACP
- COOP
- HSRP
Correct Answer: 3. COOP
Explanation:
Cisco ACI leaf switches report locally learned endpoint information to the spine switches by using the Council of Oracle Protocol. The spine switches maintain the fabric wide COOP endpoint database containing information about endpoint addresses and their locations. This database allows the ACI fabric to locate endpoints that are not already present in the forwarding information of the source leaf. Maintaining a centralized distributed endpoint directory on the spine layer is an important part of ACI forwarding. Local leaf switches remain responsible for discovering their directly attached endpoints and communicating those endpoint locations through COOP.
Question 342. What is a local endpoint from the perspective of an ACI leaf
- An endpoint directly attached to that leaf
- Any endpoint in another pod
- An external router
- An APIC controller
Correct Answer: 1. An endpoint directly attached to that leaf
Explanation:
A local endpoint is an endpoint physically or logically attached to the leaf switch that is examining the endpoint database. The leaf learns local endpoint information from traffic generated by the endpoint and then advertises that information toward the spine COOP database. Local endpoint information is authoritative because it identifies the leaf where the endpoint currently resides. Other leaf switches can later learn cached remote information about that same endpoint as traffic crosses the fabric. Correct local endpoint learning is therefore fundamental to ACI forwarding, endpoint mobility, and troubleshooting.
Question 343. What is a remote endpoint entry on an ACI leaf
- A permanent APIC record
- A Fibre Channel zone
- An external BGP route
- A cached endpoint on another leaf
Correct Answer: 4. A cached endpoint on another leaf
Explanation:
A remote endpoint entry is a locally cached record describing an endpoint attached to another leaf switch. Cisco explains that remote endpoint entries are not the main authoritative source of endpoint information for the complete ACI fabric. The authoritative endpoint location is reported by the leaf where the endpoint is locally attached and stored in the spine COOP database. Remote caching improves forwarding efficiency because a leaf can send traffic directly toward the known destination leaf instead of requesting a spine proxy lookup for every packet destined to that endpoint.
Question 344. What does ACI spine proxy provide when a leaf does not know a remote endpoint
- Server boot configuration
- Endpoint forwarding lookup
- Fibre Channel routing
- Power management
Correct Answer: 2. Endpoint forwarding lookup
Explanation:
Spine proxy allows a leaf switch to forward traffic toward the spine when the leaf does not have a cached remote endpoint entry. The spine uses its COOP endpoint database to identify the destination endpoint location and forward the traffic toward the appropriate destination leaf. This means ACI forwarding can continue even when every leaf has not learned every remote endpoint. Remote endpoint caching improves efficiency, but spine proxy provides the underlying fabric wide lookup capability. This architecture reduces the requirement for every leaf to maintain complete information about every endpoint in a large fabric.
Question 345. What bridge domain setting is required for normal ACI endpoint IP learning
- Unicast routing
- Port security
- Fibre Channel routing
- vPC peer switch
Correct Answer: 1. Unicast routing
Explanation:
Cisco ACI learns endpoint IP information in the normal routed fabric design when unicast routing is enabled on the bridge domain. The leaf can learn endpoint IP addresses through mechanisms such as ARP, Gratuitous ARP, Neighbor Discovery, and routed data plane traffic. If unicast routing is disabled, the fabric still learns endpoint MAC addresses but does not perform the same normal IP endpoint learning behavior. This distinction is important when designing Layer 2 only bridge domains compared with bridge domains where ACI provides distributed Layer 3 gateway and routing services.
Question 346. What endpoint information does ACI learn even when bridge domain unicast routing is disabled
- IP routes only
- BGP communities
- MAC addresses
- Fibre Channel IDs
Correct Answer: 3. MAC addresses
Explanation:
Cisco ACI continues to learn endpoint MAC addresses even when unicast routing is disabled on the bridge domain. MAC learning is fundamental to Layer 2 forwarding and therefore does not depend on the bridge domain providing Layer 3 routing services. IP learning behaves differently because normal IP endpoint learning is tied more closely to routed fabric behavior and endpoint activity such as ARP or routed data traffic. Understanding this difference helps designers distinguish between Layer 2 only application connectivity and bridge domains where ACI also acts as the distributed default gateway for endpoints.
Question 347. What happens to ARP requests when ACI bridge domain routing is disabled
- They are discarded
- They are flooded
- They become BGP routes
- They are converted to COOP
Correct Answer: 2. They are flooded
Explanation:
Cisco states that when unicast routing is disabled for a bridge domain, ARP requests are flooded rather than handled through the normal routed endpoint learning mechanisms. This behavior occurs even when the normal ARP flooding option would otherwise suggest different processing. A Layer 2 only bridge domain lacks the distributed gateway function that would normally support optimized ARP processing. Designers should therefore consider the effect of broadcast and ARP behavior when creating Layer 2 only segments, particularly when large endpoint populations share the same bridge domain.
Question 348. Where is the fabric wide ACI endpoint database maintained
- APIC only
- Border leaf only
- Spine switches
- External router
Correct Answer: 4. Spine switches
Explanation:
The fabric wide endpoint database used by the COOP process is maintained on ACI spine switches. Each leaf switch reports its locally attached endpoints to this database so the fabric can determine where every known endpoint resides. Leaf switches do not need to retain every remote endpoint permanently because they can use the spine proxy function when a destination is unknown locally. This architecture provides scalable endpoint location services while still allowing remote endpoint caching on leaf switches to optimize frequently used communication paths. The spine COOP database is therefore fundamental to ACI endpoint reachability.
Question 349. Which APIC log records user configuration changes
- Health score log
- Event log
- Audit log
- Endpoint log
Correct Answer: 3. Audit log
Explanation:
The APIC audit log records user initiated events that need to be auditable. Cisco examples include user login and logout activity as well as configuration modifications. Keeping these events separate from ordinary system generated events provides a clearer trail of administrative actions. Audit information is valuable when investigating who changed a configuration, reviewing operational procedures, or meeting governance requirements. APIC uses separate logs for audit activity, health score changes, and general system generated events, allowing administrators to focus on the type of information relevant to the investigation.
Question 350. Which APIC log records changes in component health scores
- Health score log
- Audit log
- Event log only
- COOP log
Correct Answer: 1. Health score log
Explanation:
The APIC health score log records changes in the health score of system components. Cisco ACI calculates health information from faults and operational state so administrators can quickly identify parts of the fabric whose condition is degrading. Recording health changes over time also helps operators understand whether a problem is persistent or temporary. This log is separate from the audit log, which tracks user initiated actions, and the event log, which records other system generated events. The separation helps operators navigate large amounts of fabric operational information efficiently.
Question 351. Which APIC log records events such as link state transitions
- Endpoint log
- Contract log
- Audit log
- Event log
Correct Answer: 4. Event log
Explanation:
The APIC event log stores system generated events such as interface link state transitions. Event records include information such as the event code, affected managed object, probable cause, generating activity, severity, creation time, and descriptive text. Cisco separates these events from user actions recorded in the audit log and from health score changes recorded in the health score log. Event history gives operators useful context when troubleshooting connectivity or fabric behavior because it shows when relevant system transitions occurred and which managed objects were affected.
Question 352. What severity do APIC event records use according to Cisco documentation
- Critical only
- Info
- Major only
- Warning only
Correct Answer: 2. Info
Explanation:
Cisco documentation states that APIC event records use the informational severity level. Events are records of system activity rather than persistent fault objects requiring their own changing severity states. Each event is created as a stateless record and remains in its event log until normal log rotation eventually removes it when capacity is needed for newer entries. Administrators should distinguish events from faults because faults represent detected conditions with their own lifecycle, while events provide historical information about changes and activities that occurred in the system.
Question 353. What does an NDFC LAN fabric backup include
- Fabric intent and configuration information
- Only switch passwords
- Only operational statistics
- Server operating systems
Correct Answer: 1. Fabric intent and configuration information
Explanation:
An NDFC LAN fabric backup includes fabric configuration and intent information. Cisco defines intent as configuration saved in Nexus Dashboard Fabric Controller, whether or not every part of that configuration has already been deployed to the switches. The backup also maintains associated resource manager state for resources used by the fabric. This allows administrators to restore the fabric toward a previously saved intended state rather than relying only on individual device running configurations. Fabric backups are therefore an important part of NDFC operational recovery and change management planning.
Question 354. What is the main purpose of marking an NDFC fabric backup as golden
- Encrypt the backup
- Deploy it immediately
- Convert it to SAN mode
- Protect it from automatic removal
Correct Answer: 4. Protect it from automatic removal
Explanation:
A golden fabric backup is intended to be preserved rather than automatically deleted when older backup files are removed to make space for newer backups. This makes the designation useful for known good baseline configurations that administrators may want to retain for an extended period. A golden mark can later be removed if the backup is no longer required, after which normal deletion behavior can apply. Maintaining a trusted baseline gives operations teams a stable recovery reference when troubleshooting configuration changes or recovering from an undesirable fabric state.
Question 355. What can NDFC Delta Config show during a fabric restore preview
- Power supply health
- Configuration differences
- GPU memory usage
- Fibre Channel cable length
Correct Answer: 2. Configuration differences
Explanation:
During an NDFC LAN fabric restore workflow, Delta Config allows administrators to review configuration differences between the selected backup state and the current fabric state. This gives the operator an opportunity to understand the effect of the restore before configuration is pushed to devices. Cisco also provides backup metadata such as switch names and serial numbers so the administrator can verify that the selected backup matches the expected environment. Reviewing differences before restoration reduces the risk of unintentionally reverting valid changes that occurred after the backup was created.
Question 356. What must occur after NDFC restores the intended fabric state
- Replace every switch
- Delete all VRFs
- Deploy the restored configuration
- Recreate the Nexus Dashboard cluster
Correct Answer: 3. Deploy the restored configuration
Explanation:
Restoring NDFC fabric intent does not end with selecting a backup. Cisco provides a workflow where the selected intent is restored, configuration differences are previewed, switches can be resynchronized, and the restored configuration is then deployed. This separation allows administrators to verify the intended state before pushing configuration to the managed devices. Treating restore as a controlled workflow reduces the chance that a backup is applied blindly. It also allows operators to focus on specific switches that require resynchronization before completing the overall fabric recovery process.
Question 357. Where is unified Nexus Dashboard backup and restore performed in current releases
- Nexus Dashboard level
- Individual leaf CLI
- APIC tenant only
- UCS Manager
Correct Answer: 4. Nexus Dashboard level
Explanation:
Beginning with NDFC Release 12.2.2, Cisco provides unified backup and restore at the Nexus Dashboard level. A Nexus Dashboard backup can include the platform configuration together with supported services running on that Dashboard instance, such as NDFC, NDI, or NDO. This replaced the older upper level NDFC backup workflow previously performed directly through the NDFC interface. Individual fabric backup and restore functions remain available where supported, but broader platform and service recovery is coordinated through the Nexus Dashboard backup framework.
Question 358. Where are individual NDFC LAN fabric backups still managed
- APIC only
- NDFC fabric interface
- UCS Central
- Server CIMC
Correct Answer: 1. NDFC fabric interface
Explanation:
Although Nexus Dashboard provides unified platform level backup and restore, individual LAN and SAN fabric backups remain available through Nexus Dashboard Fabric Controller. Administrators can select a managed fabric and perform manual or scheduled backup operations according to the supported fabric type. This lower level workflow preserves fabric configuration intent and can later be used for fabric specific restoration. The distinction allows operations teams to protect both the overall Nexus Dashboard platform and individual managed network fabrics according to the required recovery scope.
Question 359. When does an hourly NDFC VXLAN EVPN fabric backup normally occur
- Only after a configuration deployment since the previous backup
- Every minute regardless of changes
- Only after a controller reboot
- Only after a hardware replacement
Correct Answer: 3. Only after a configuration deployment since the previous backup
Explanation:
For a managed Data Center VXLAN EVPN fabric, Cisco describes hourly fabric backup as being triggered when there has been a relevant configuration deployment since the previous backup. This prevents unnecessary creation of identical backups when no configuration state has changed. NDFC also supports scheduled backups that can track configuration changes and manual backup operations when an administrator wants an immediate recovery point. A deliberate backup strategy should combine automated protection with known good manual checkpoints before major network changes or maintenance activities.
Question 360. What limitation applies when restoring an external NDFC fabric in monitor only mode
- It can restore only VRFs
- It cannot be restored while remaining in monitor only mode
- It can restore only spine switches
- It must use Fibre Channel
Correct Answer: 2. It cannot be restored while remaining in monitor only mode
Explanation:
Cisco documentation explains that an external fabric operating in monitor only mode can have backup information available, but restoration is not performed while the fabric remains in monitor only mode. The backup can be restored after the external fabric is placed into a mode where NDFC is permitted to manage and deploy configuration. This restriction is logical because monitor only operation is intended to observe rather than change the managed network. Administrators should therefore understand the operational mode of an external fabric before relying on NDFC for configuration restoration or recovery actions.