View Full Cisco CCNP Data Center 300-610 Exam Dumps and Practice Test Dumps.
Question 381. What does an Intersight Ethernet Network Control Policy configure
- RAID groups
- CDP and LLDP behavior
- VXLAN routing
- Fibre Channel zones
Correct Answer: 2. CDP and LLDP behavior
Explanation:
An Ethernet Network Control Policy defines Layer 2 network control behavior for supported Cisco UCS vNICs and appliance ports. It can enable Cisco Discovery Protocol and control whether Link Layer Discovery Protocol frames are transmitted and received. The policy also includes settings related to MAC address registration, forged MAC handling, and behavior when uplink connectivity is unavailable. Centralizing these settings in Cisco Intersight allows the same network control requirements to be applied consistently through LAN Connectivity Policies and server profiles instead of configuring individual interfaces manually.
Question 382. What is the default Intersight action when a vNIC loses all uplinks
- Warning
- Ignore
- Reboot
- Link Down
Correct Answer: 4. Link Down
Explanation:
Link Down is the default uplink failure action in an Intersight Ethernet Network Control Policy. When no suitable uplink remains available in End Host mode, the vNIC operational state is changed to down. This behavior can trigger supported fabric failover so traffic can use another available Fabric Interconnect path. Cisco also provides a Warning option, which keeps the vNIC operational for certain server to server connectivity scenarios. Choosing the correct behavior depends on whether maintaining local connectivity or immediately signaling uplink failure to the server is more important for the application design.
Question 383. What does the Warning uplink failure action preserve
- Server to server connectivity
- Fibre Channel zoning
- BGP sessions only
- RAID rebuilds
Correct Answer: 1. Server to server connectivity
Explanation:
The Warning uplink failure action keeps the vNIC operational even when no uplink is currently available from the Fabric Interconnect. Cisco documents this option as useful for preserving server to server connectivity through the local fabric when upstream connectivity is unavailable. The tradeoff is that fabric failover is disabled for the affected vNIC when this behavior is selected. Designers should therefore understand whether workloads depend more heavily on local east west communication or on automatic movement toward the alternate Fabric Interconnect when an uplink path fails.
Question 384. What is the default MAC registration mode in an Intersight Ethernet Network Control Policy
- All VLANs
- Disabled
- Native VLAN Only
- Dynamic VLAN Only
Correct Answer: 3. Native VLAN Only
Explanation:
Native VLAN Only is the default MAC registration mode in the Intersight Ethernet Network Control Policy. With this mode, MAC addresses are registered only against the native VLAN. Cisco notes that this option maximizes the available port and VLAN scale. The alternative All Host VLANs mode registers MAC addresses on all associated VLANs and can be appropriate when VLAN trunking behavior requires those addresses to be visible across several VLANs. Designers should select the registration model according to the server networking architecture and expected switching behavior.
Question 385. What does the MAC Security Forge setting control
- Whether forged MAC addresses are permitted
- Whether Fibre Channel is enabled
- Whether BGP is authenticated
- Whether RAID is mirrored
Correct Answer: 2. Whether forged MAC addresses are permitted
Explanation:
The MAC Security Forge setting determines whether frames using forged or unexpected source MAC addresses are allowed or denied when transmitted from the server toward the Fabric Interconnect. Denying forged MAC addresses can provide stronger Layer 2 security when workloads are expected to use only their assigned identities. Allowing them can be necessary for some virtualization or application designs that legitimately generate traffic using additional MAC addresses. Intersight places this setting in the Ethernet Network Control Policy so the required security behavior can be reused consistently across server vNICs.
Question 386. What does an Intersight Ethernet Network Group Policy define
- Allowed VLANs and native VLAN
- Server BIOS settings
- VXLAN route targets
- Fibre Channel domain IDs
Correct Answer: 1. Allowed VLANs and native VLAN
Explanation:
An Ethernet Network Group Policy defines which VLANs are available to a vNIC and which VLAN should operate as the native VLAN. Cisco also supports optional QinQ configuration through this policy. For Fabric Interconnect attached servers, the Ethernet Network Group Policy is associated with vNICs through a LAN Connectivity Policy. This provides a reusable way to standardize Ethernet segmentation across many servers. Instead of manually configuring VLAN membership for every interface, administrators can define the network group once and reference it from several vNIC configurations.
Question 387. How many Ethernet Network Group Policies can a vNIC use when QinQ is configured
- Fifty
- Ten
- Two
- One
Correct Answer: 4. One
Explanation:
Cisco states that only one Ethernet Network Group Policy can be associated with a vNIC when QinQ is configured. Without QinQ, supported vNIC configurations can reference multiple Ethernet Network Group Policies within the documented platform limits. QinQ adds an additional VLAN tagging layer, so the networking policy relationship must remain unambiguous. Cisco also requires consistent native VLAN behavior when several Ethernet Network Group Policies are associated with a vNIC. Designers should plan VLAN groups carefully before deploying QinQ or large trunk configurations through Intersight.
Question 388. What does an Intersight LAN Connectivity Policy primarily define
- APIC contracts
- Fibre Channel zones
- Server vNIC configuration
- Storage RAID level
Correct Answer: 3. Server vNIC configuration
Explanation:
A LAN Connectivity Policy defines Ethernet connectivity for a server by creating and configuring its virtual network interfaces. Each vNIC can reference policies for Ethernet adapter behavior, network control, QoS, VLAN groups, and MAC address allocation. The policy also specifies placement characteristics such as Fabric Interconnect path, adapter slot, and PCI link where required. Cisco Intersight then applies the LAN Connectivity Policy through server profiles or server profile templates. This creates a reusable and consistent model for server LAN connectivity across many UCS systems.
Question 389. What does enabling vNIC failover provide
- Automatic traffic failover to the alternate fabric
- Automatic RAID rebuild
- Automatic VXLAN deletion
- Automatic server shutdown
Correct Answer: 1. Automatic traffic failover to the alternate fabric
Explanation:
Enabling failover for a supported UCS vNIC allows traffic to move to the secondary Fabric Interconnect path when the primary fabric path becomes unavailable. Cisco notes that this capability applies to supported Cisco VIC adapters connected to a Fabric Interconnect cluster. Fabric failover can increase network resiliency without requiring the operating system to manage two independent interfaces for every network path. Designers should still evaluate application requirements and uplink architecture because some environments prefer active connections on both fabrics rather than depending on fabric failover for a single logical vNIC.
Question 390. What design improves vNIC path redundancy in a Fabric Interconnect pair
- Put all vNICs on Fabric A
- Use separate vNICs on Fabric A and Fabric B
- Disable Fabric B
- Use one MAC address for all servers
Correct Answer: 4. Use separate vNICs on Fabric A and Fabric B
Explanation:
A common high availability design places server vNICs across both Fabric Interconnect paths so loss of one fabric does not remove all Ethernet connectivity. For example, one vNIC can use Fabric A and another can use Fabric B. Operating system teaming, bonding, or application level redundancy can then use both paths according to the architecture. Cisco Intersight LAN Connectivity Policies allow fabric placement to be defined for each vNIC. Combining dual fabric placement with redundant upstream networking prevents one Fabric Interconnect or uplink failure from becoming a complete server connectivity outage.
Question 391. What must be disabled when using RSS with multiple transmit queues in the documented ESXi design
- LLDP
- VMQ
- CDP
- LACP
Correct Answer: 2. VMQ
Explanation:
Cisco requires VMQ to be disabled when configuring the documented VMware ESXi design that uses Receive Side Scaling together with multiple transmit queues on supported UCS VIC adapters. RSS is then enabled so receive processing can be distributed appropriately across processor resources. Cisco notes that when VMQ is enabled, receive queue reporting and RSS behavior differ because VMQ controls the queue model. The supported Ethernet Adapter Policy therefore enables RSS, disables VMQ, and configures suitable transmit, receive, completion, and interrupt resources for the ESXi host.
Question 392. How are completion queues sized in the documented Intersight RSS design
- One completion queue only
- Equal to receive queues only
- Transmit queues plus receive queues
- Equal to interrupt count only
Correct Answer: 3. Transmit queues plus receive queues
Explanation:
Cisco recommends setting the number of completion queues equal to the total number of transmit queues plus receive queues for the documented ESXi Ethernet Adapter Policy. Completion queues track completed network operations and therefore need to support both directions of interface activity. Cisco also provides guidance for determining the interrupt count from the completion queue value. Correct queue sizing is important because too few resources can limit throughput, while unnecessary queue allocation can waste adapter and CPU resources. Adapter policy values should be matched to supported VIC hardware and operating system requirements.
Question 393. Which NDFC option should remain selected for a brownfield switch import
- Preserve Config
- Erase Config
- Reload Device
- Disable Discovery
Correct Answer: 1. Preserve Config
Explanation:
Preserve Config should remain selected when an existing configured switch is being imported into Nexus Dashboard Fabric Controller as part of a brownfield deployment. NDFC learns and preserves the switch configuration instead of treating the device as a new greenfield switch whose existing configuration can be cleaned up. This allows an operational fabric to transition into centralized NDFC management with minimal disruption. Cisco recommends backing up switch configurations before migration and ensuring that the existing fabric follows supported best practices before beginning the brownfield import process.
Question 394. What should be done with Preserve Config for a greenfield NDFC import
- Force it on
- Leave it permanently selected
- Set it to read only
- Clear it
Correct Answer: 4. Clear it
Explanation:
For a greenfield switch import, Cisco instructs administrators to clear the Preserve Config option. Greenfield deployment assumes the switch is being incorporated into a fabric whose configuration will be generated and managed by Nexus Dashboard rather than preserving an existing production configuration. Clearing the option allows NDFC to clean up configuration as part of the import workflow according to the selected fabric template. This behavior contrasts with brownfield deployment, where preserving existing working configuration is essential to a nondisruptive migration into centralized management.
Question 395. What is the default NDFC discovery Max Hops value
- One
- Four
- Two
- Eight
Correct Answer: 3. Two
Explanation:
The default Max Hops value for Nexus Dashboard switch discovery is two. Administrators provide a seed switch address and credentials, and the discovery process can locate supported devices within the configured hop boundary. With the default value, the seed switch and switches up to two hops away can appear in discovery results. The hop setting helps control how broadly NDFC searches the connected network during switch onboarding. Designers should choose a value that discovers the intended fabric without unintentionally including unrelated devices beyond the desired management boundary.
Question 396. What discovery status indicates that an NDFC switch can be imported
- Manageable
- Deleted
- Unreachable
- Suspended
Correct Answer: 1. Manageable
Explanation:
After Nexus Dashboard successfully performs shallow discovery of a supported switch, the device can appear with a Manageable status. Administrators can then select the switch and add it to the intended fabric. Discovery requires appropriate reachability and credentials so NDFC can communicate with the switch. The discovery workflow can locate several switches through a seed device within the configured hop range. Cisco recommends discovering multiple intended fabric switches together where practical, particularly during brownfield migration, so the complete topology can be imported consistently.
Question 397. Which Nexus Dashboard fabric type does not support brownfield switch import according to current guidance
- External Fabric
- Routed Fabric
- Enhanced Classic LAN
- Data Center VXLAN EVPN
Correct Answer: 2. Routed Fabric
Explanation:
Current Nexus Dashboard guidance states that Routed Fabric does not support brownfield import of existing switches. Brownfield onboarding is supported for appropriate fabric types where existing switch configuration can be discovered and preserved. Designers should therefore verify the selected fabric template before planning a migration from an already configured network. Choosing a template that does not support brownfield operation can force a different migration method or require greenfield provisioning. Fabric type selection should account for current topology, desired automation model, and whether configuration must remain intact during migration.
Question 398. Which fabric template is used for a brownfield VXLAN EVPN import
- Data Center VXLAN EVPN
- SAN Classic
- UCS Domain
- External Storage
Correct Answer: 1. Data Center VXLAN EVPN
Explanation:
Cisco instructs administrators to create the target fabric using the Data Center VXLAN EVPN template when importing an existing brownfield VXLAN EVPN environment into NDFC. Existing switches are then added while preserving configuration, and NDFC learns the operational intent from the existing fabric. Cisco also provides guidance on switch import order and seed switch selection. A successful brownfield migration requires the existing network to be functional and aligned with supported Cisco best practices before centralized fabric management is assumed by Nexus Dashboard.
Question 399. Does an ACI microsegmented EPG appear in vCenter as a normal port group
- Always
- Only for physical servers
- Only with static VLANs
- No
Correct Answer: 4. No
Explanation:
A Cisco ACI microsegmented endpoint group does not appear in VMware vCenter as a normal port group. The regular application EPG is the object represented as a port group to the virtualization administrator. A microsegmented EPG instead uses attribute based criteria to identify matching virtual machines and dynamically classify those endpoints into a more specific policy group. This enables finer segmentation without requiring the virtualization administrator to manually move every virtual machine into a different virtual port group. The microsegmented EPG must be associated with the appropriate VMM domain for its criteria to take effect.
Question 400. What does an ACI microsegmented EPG use to classify virtual machines
- Fibre Channel domain IDs
- VM attribute matching criteria
- Server power priority
- BGP path cost
Correct Answer: 2. VM attribute matching criteria
Explanation:
A microsegmented EPG uses virtual machine attributes as matching criteria to identify endpoints that should receive a specific ACI policy. Cisco APIC evaluates configured criteria and dynamically moves matching endpoints from their normal application EPG classification into the microsegmented EPG. The application EPG continues to provide the port group visible to the virtualization platform, while the microsegmented policy works behind the scenes for finer security segmentation. If the microsegmented EPG is removed, the affected endpoints can return to their original application EPG classification.