Cisco CCNP Data Center 300-620 Practice Test Questions and Exam Dumps Part7 Q121-140

View Full Cisco CCNP Data Center 300-620 Exam Dumps and Practice Test Dumps.

 

Question 121

Which ACI object is used to define a collection of traffic rules referenced by a contract subject?

  1. Filter
  2. VRF
  3. VLAN pool
  4. Bridge domain

Correct Answer: 1

Explanation

A filter defines specific traffic rules that can be referenced by a contract subject. Filter entries can identify protocols, source or destination ports, and other supported traffic characteristics. The contract then uses the subject and filter to determine which communication is permitted between consumer and provider EPGs. A VRF provides routing separation, a VLAN pool supplies encapsulation resources, and a bridge domain defines a Layer 2 forwarding domain. When troubleshooting contract behavior, administrators should verify the filter entries, contract subject, provider and consumer relationships, and EPG associations to determine whether the required traffic is actually permitted.

Question 122

Which ACI object is associated with a bridge domain to provide Layer 3 routing separation?

  1. EPG
  2. VRF
  3. Filter
  4. Interface selector

Correct Answer: 2

Explanation

A VRF provides the Layer 3 routing context associated with a bridge domain. Multiple bridge domains can use the same VRF and therefore share its routing table, while separate VRFs provide logical routing isolation. This is particularly useful for multi-tenant environments and applications requiring independent routing domains. EPGs group endpoints, filters define contract traffic, and interface selectors identify physical interfaces. When configuring or troubleshooting an ACI bridge domain, administrators should verify its VRF association along with its subnet and routing settings. An incorrect VRF association can prevent expected communication or place traffic into an unintended routing context.

Question 123

Which ACI access-policy object is used to associate an interface profile with a specific policy group?

  1. VLAN pool
  2. Interface selector
  3. External EPG
  4. Contract

Correct Answer: 2

Explanation

An interface selector identifies the specific interfaces to which an interface policy group should be applied. It works within the ACI access-policy hierarchy, where switch profiles identify leaf switches, interface profiles organize interfaces, selectors identify ports, and policy groups provide the required interface policies. VLAN pools provide encapsulation resources, external EPGs represent external networks, and contracts define communication policies. If an interface is not receiving its intended configuration, administrators should verify the selector range and its associated policy group. Correct selector configuration ensures that the appropriate interface settings are deployed to the intended physical ports.

Question 124

Which ACI object represents a collection of endpoints that share common policy requirements?

  1. EPG
  2. VRF
  3. L3Out
  4. VLAN pool

Correct Answer: 4

Explanation

An Endpoint Group, or EPG, represents a collection of endpoints that share common policy requirements. EPGs are central to ACI’s application-centric model because they allow administrators to classify workloads based on their communication and application roles. EPGs can be organized within application profiles and can communicate with other EPGs through contracts. VRFs provide routing contexts, L3Outs provide external Layer 3 connectivity, and VLAN pools supply encapsulation resources. When designing an application, administrators should identify logical endpoint groups and then define the contracts required between them. This creates a structured policy model for controlling application communication.

Question 125

Which ACI component is used to provide Layer 3 connectivity between the fabric and an external routed network?

  1. L3Out
  2. Physical domain
  3. Application profile
  4. VLAN pool

Correct Answer: 1

Explanation

An L3Out provides external Layer 3 connectivity from the ACI fabric to routed networks. It is associated with a VRF and can include logical node profiles, logical interface profiles, external EPGs, and routing protocol configurations. Depending on the network design, administrators can use static routing, OSPF, BGP, or other supported methods. A physical domain connects EPGs to bare-metal infrastructure, an application profile organizes EPGs, and a VLAN pool provides encapsulation resources. When troubleshooting external connectivity, administrators should verify the L3Out configuration, external interface, routing adjacency, external subnets, and associated route-control policies.

Question 126

Which ACI feature can be used to represent a group of external networks for applying contracts?

  1. Application profile
  2. External EPG
  3. Physical domain
  4. Interface profile

Correct Answer: 2

Explanation

An External EPG represents external destinations reachable through an L3Out and allows administrators to apply ACI policy to traffic involving those destinations. External subnets can be associated with an external EPG, and contracts can then control communication between internal EPGs and external networks. Application profiles organize internal EPGs, physical domains provide connectivity for physical endpoints, and interface profiles organize access interfaces. When implementing external security policies, administrators should ensure that the external EPG contains the correct prefixes and participates in the appropriate contracts. This provides controlled communication between internal application groups and external network destinations.

Question 127

Which ACI policy determines the VLAN encapsulation resources available to an associated domain?

  1. VLAN pool
  2. Contract
  3. VRF
  4. Filter

Correct Answer: 1

Explanation

A VLAN pool defines the VLAN encapsulation resources that can be allocated to an ACI domain. The pool can contain specific VLAN IDs or ranges and is associated with domains such as physical, VMM, or external connectivity domains. When an EPG is deployed through a domain, the appropriate encapsulation can be selected from the associated VLAN pool. Contracts control application communication, VRFs provide routing contexts, and filters define permitted traffic. Administrators should avoid overlapping VLAN assignments and ensure that the VLAN pool matches the requirements of the connected infrastructure. Incorrect pool configuration can prevent proper EPG deployment.

Question 128

Which ACI object is used to organize multiple EPGs that belong to the same application?

  1. Application profile
  2. Bridge domain
  3. Filter
  4. Route control policy

Correct Answer: 1

Explanation

An application profile organizes EPGs that represent different components or tiers of an application. For example, an application profile can contain web, application, and database EPGs. These EPGs can then use contracts to define their permitted communication. A bridge domain defines Layer 2 and Layer 3 forwarding characteristics, filters define traffic rules, and route-control policies influence external route exchange. Application profiles provide a logical structure for policy administration and make it easier to understand relationships between application components. Administrators should create application profiles according to application requirements rather than simply matching the physical topology of the network.

Question 129

Which ACI setting controls whether a bridge domain can route traffic between subnets?

  1. Endpoint retention
  2. Unicast routing
  3. CDP
  4. LLDP

Correct Answer: 2

Explanation

The unicast routing setting controls whether Layer 3 routing is enabled for a bridge domain. When enabled, the bridge domain can provide a gateway through its configured subnet and participate in routing through the associated VRF. This allows endpoints to communicate with destinations outside their local subnet according to the configured routing and policy. Endpoint retention controls learned endpoint information, while CDP and LLDP provide neighbor discovery. Administrators should verify unicast routing when an endpoint can communicate locally but cannot reach a different subnet. They should also check the bridge-domain subnet, VRF association, endpoint attachment, and applicable contracts.

Question 130

Which ACI protocol is commonly used to establish an external routing adjacency using a link-state interior gateway protocol?

  1. BGP
  2. OSPF
  3. CDP
  4. SNMP

Correct Answer: 2

Explanation

OSPF is a link-state interior gateway protocol that can be configured through an ACI L3Out to exchange routes with external routers. It establishes neighbor relationships and uses link-state information to calculate reachable paths within the configured routing domain. BGP is a path-vector protocol, CDP is used for Cisco neighbor discovery, and SNMP provides management and monitoring capabilities. When deploying OSPF with ACI, administrators should verify the L3Out configuration, area assignment, interface addressing, authentication if required, and external router settings. Checking the OSPF neighbor state and learned routes can help confirm that the external routing relationship is operational.

Question 131

Which ACI feature is used to apply a common contract policy to all EPGs in a VRF?

  1. vzAny
  2. L2Out
  3. Static path binding
  4. VLAN pool

Correct Answer: 1

Explanation

vzAny is an ACI construct that represents all EPGs within a VRF for certain contract relationships. It can simplify policy administration when the same communication rule needs to be applied broadly across multiple EPGs. Instead of creating many individual relationships, administrators can use vzAny to establish a common policy relationship. L2Out provides external Layer 2 connectivity, static path binding defines endpoint attachment, and VLAN pools provide encapsulation resources. Because vzAny can affect multiple EPGs, administrators should carefully evaluate the resulting policy scope before deployment. Broad contracts should be used only when the required communication boundary is clearly understood.

Question 132

Which ACI object provides the logical Layer 2 forwarding domain for endpoints?

  1. Contract
  2. External EPG
  3. Bridge domain
  4. VMM domain

Correct Answer: 3

Explanation

A bridge domain provides the logical Layer 2 forwarding domain used by endpoints within ACI. It can contain a subnet for Layer 3 gateway services and is associated with a VRF. Bridge-domain settings determine important behaviors such as unicast routing, ARP flooding, unknown unicast handling, and endpoint learning. Contracts define communication policy, external EPGs represent outside networks, and VMM domains integrate virtual infrastructure. When troubleshooting local endpoint communication, administrators should examine the bridge domain, its associated VRF, subnet configuration, and forwarding settings. These elements determine how traffic is handled within the logical network segment.

Question 133

Which ACI feature allows a physical server to be associated with an EPG through a specific leaf interface?

  1. Static path binding
  2. Route control
  3. BGP
  4. SNMP

Correct Answer: 1

Explanation

Static path binding allows administrators to associate an EPG with a specific physical interface or port-channel on an ACI leaf. It is commonly used for bare-metal servers where the endpoint location is known in advance. The configuration can specify the leaf path and VLAN encapsulation used for the endpoint. Route-control policies influence external routing, BGP exchanges routes, and SNMP provides monitoring information. When deploying a static path, administrators should confirm that the EPG is associated with the correct physical domain, VLAN pool, interface, and encapsulation. These settings must align for the endpoint to receive the intended policy and connectivity.

Question 134

Which ACI component provides the transit path between leaf switches?

  1. APIC
  2. Spine switch
  3. External EPG
  4. Physical server

Correct Answer: 2

Explanation

Spine switches provide the transit layer between leaf switches in the ACI fabric. Endpoints normally connect to leaf switches, and traffic destined for an endpoint on another leaf travels through the spine layer. The spine layer does not normally provide direct endpoint connectivity; instead, it supplies the high-speed fabric infrastructure that connects the leaf nodes. APIC manages policy and configuration, external EPGs represent external networks, and physical servers are endpoints. When troubleshooting inter-leaf traffic, administrators should check spine interfaces, fabric connectivity, node health, and endpoint learning information to determine whether the required forwarding path is available.

Question 135

Which ACI policy is used to specify the protocols and destination ports permitted between EPGs?

  1. VRF
  2. Filter
  3. VLAN pool
  4. Physical domain

Correct Answer: 2

Explanation

A filter specifies the traffic characteristics that can be permitted through an ACI contract. Filter entries can define protocols and ports, allowing administrators to create precise application communication rules. The filter is referenced by a contract subject, and the contract is then applied between consumer and provider EPGs. VRFs provide routing contexts, VLAN pools supply encapsulation resources, and physical domains connect EPGs to physical endpoints. When creating application policies, administrators should define filters according to actual service requirements. Restricting communication to required protocols and ports helps create more controlled and predictable application connectivity.

Question 136

Which ACI management method uses the production fabric for controller and node management traffic?

  1. Out-of-band management
  2. In-band management
  3. Console-only management
  4. External BGP

Correct Answer: 1

Explanation

In-band management uses the ACI fabric’s production network to carry management traffic. This differs from out-of-band management, which uses dedicated management interfaces and a separate management network. In-band management can be useful when organizations want to manage fabric nodes through the same infrastructure used for normal network communication. Administrators must carefully configure the required management contracts, bridge domains, routing, and external connectivity. If production forwarding is disrupted, in-band management access may also be affected. Therefore, management design should account for availability and troubleshooting requirements when selecting between in-band and out-of-band approaches.

Question 137

Which ACI feature is used to integrate a leaf switch with a hypervisor-based virtual networking environment?

  1. VMM domain
  2. L2Out
  3. Filter
  4. Route control policy

Correct Answer: 4

Explanation

A VMM domain is used to integrate ACI policy with supported virtual machine management environments. It allows ACI to coordinate network policy for virtual workloads and associate EPGs with the virtual networking infrastructure. VMM domains typically use VLAN pools and controller-specific configuration to establish the required integration. L2Out provides external Layer 2 connectivity, filters define contract traffic, and route-control policies manage external routing behavior. When troubleshooting virtual workload connectivity, administrators should verify the VMM controller connection, domain association, VLAN pool, EPG configuration, and virtual networking state to ensure that policy is being correctly deployed.

Question 138

Which ACI feature helps identify why a fabric object is reporting a degraded health state?

  1. VLAN pool
  2. Faults
  3. Application profile
  4. EPG contract

Correct Answer: 2

Explanation

Faults provide detailed information about problems affecting ACI fabric objects and policies. APIC can display faults associated with switches, interfaces, tenants, EPGs, contracts, bridge domains, and other managed objects. Fault information can include severity, description, affected object, and recommended corrective actions. VLAN pools and application profiles are configuration objects, while contracts define communication policies. When a health score decreases, administrators should inspect the associated faults and events to identify the underlying condition. Reviewing fault history can also help determine whether the problem is persistent, intermittent, or related to a recent configuration change.

Question 139

Which ACI object defines the logical routing table used by a group of bridge domains?

  1. VRF
  2. EPG
  3. Filter
  4. Interface policy

Correct Answer: 1

Explanation

A VRF defines the logical routing context and routing table used by associated bridge domains. Multiple bridge domains can share a VRF when they should participate in the same Layer 3 routing domain. Separate VRFs provide logical routing isolation for different environments and can support overlapping address spaces when appropriately designed. EPGs group endpoints, filters define permitted contract traffic, and interface policies configure physical interface behavior. When analyzing routing behavior in ACI, administrators should first confirm the VRF association of the relevant bridge domain. An incorrect VRF can cause routes to appear missing or traffic to remain isolated from the intended destinations.

Question 140

Which ACI technology provides the overlay encapsulation used to transport tenant traffic across the fabric?

  1. OSPF
  2. CDP
  3. VXLAN
  4. SNMP

Correct Answer: 3

Explanation

VXLAN provides the overlay encapsulation used by Cisco ACI to transport tenant and endpoint traffic across the fabric. The overlay allows logical network segmentation and endpoint communication to operate over the underlying leaf-and-spine infrastructure. Leaf switches perform endpoint-facing functions and encapsulate traffic for transport, while spine switches provide transit between leaf switches. OSPF is a routing protocol, CDP is a neighbor-discovery protocol, and SNMP is used for monitoring and management. Understanding VXLAN operation helps administrators troubleshoot inter-leaf forwarding, endpoint reachability, encapsulation issues, and traffic movement across different logical networks within the ACI fabric.