Cisco CCNP Data Center 300-620 Practice Test Questions and Exam Dumps Part8 Q141-160

View Full Cisco CCNP Data Center 300-620 Exam Dumps and Practice Test Dumps.

 

Question 141

Which ACI component provides centralized policy orchestration and management for the fabric?

  1. Spine switch
  2. APIC
  3. Leaf switch
  4. External router

Correct Answer: 4

Explanation

The Application Policy Infrastructure Controller, or APIC, provides centralized policy orchestration and management for Cisco ACI. Administrators use APIC to configure tenants, VRFs, bridge domains, EPGs, contracts, access policies, and external connectivity. APIC communicates policy information to the fabric switches, which then implement the required forwarding and policy behavior. Leaf switches provide endpoint connectivity, spine switches provide transit, and external routers connect the fabric to outside networks. A healthy APIC cluster is important for reliable management and configuration operations. Administrators should monitor controller health, cluster membership, faults, and communication status when maintaining the ACI environment.

Question 142

Which ACI object is used to provide a Layer 3 gateway address to endpoints?

  1. Contract
  2. VLAN pool
  3. Bridge-domain subnet
  4. Filter

Correct Answer: 3

Explanation

A bridge-domain subnet provides the Layer 3 gateway address used by endpoints associated with that bridge domain. The subnet is configured under the bridge domain and operates within the VRF associated with it. When unicast routing is enabled, endpoints can use the configured gateway to communicate with destinations outside their local subnet. Contracts control policy between EPGs, VLAN pools provide encapsulation resources, and filters define traffic rules. When troubleshooting gateway connectivity, administrators should verify the bridge-domain subnet, gateway address, VRF association, routing settings, and endpoint attachment. Incorrect subnet configuration can prevent endpoints from reaching remote networks.

Question 143

Which ACI policy is responsible for defining the communication relationship between consumer and provider EPGs?

  1. Contract
  2. VRF
  3. VLAN pool
  4. Interface selector

Correct Answer: 1

Explanation

A contract defines the communication relationship between consumer and provider EPGs in Cisco ACI. The contract contains subjects and references filters that specify the traffic permitted between the participating EPGs. This allows administrators to express application dependencies through policy rather than configuring individual forwarding rules manually. VRFs provide routing contexts, VLAN pools provide encapsulation resources, and interface selectors identify physical interfaces for access policies. When an application cannot communicate with another EPG, administrators should verify that the correct contract exists, the consumer and provider roles are correct, and the contract subject and filters permit the required traffic.

Question 144

Which ACI object is used to associate an EPG with a physical or virtual connectivity environment?

  1. Filter
  2. Domain
  3. Contract
  4. VRF

Correct Answer: 2

Explanation

A domain associates an EPG with a specific connectivity environment in ACI. Physical domains are used for bare-metal infrastructure, while VMM domains integrate supported virtualization environments. Domains are associated with VLAN pools and other required policies so that EPGs can be deployed to the intended endpoints. Filters define traffic characteristics, contracts control communication, and VRFs provide routing contexts. If an EPG cannot be deployed to a server or virtual machine environment, administrators should verify the EPG’s domain association and confirm that the domain has a valid VLAN pool and appropriate access configuration. Correct domain configuration is essential for endpoint attachment.

Question 145

Which ACI feature allows two leaf switches to provide redundant connectivity to a dual-connected endpoint?

  1. L3Out
  2. vPC
  3. SNMP
  4. Route control

Correct Answer: 2

Explanation

Virtual Port Channel, or vPC, allows two ACI leaf switches to provide coordinated connectivity to a dual-connected endpoint. This design improves availability by allowing the endpoint to maintain connectivity through links connected to both leaf switches. vPC configurations require appropriate interface policy and physical connectivity settings. L3Out provides external Layer 3 connectivity, SNMP supports monitoring, and route-control policies influence route exchange. When troubleshooting a dual-connected server, administrators should verify the vPC configuration, interface policy group, physical links, EPG association, and endpoint learning state. Correctly configured vPC connectivity can reduce the impact of an individual leaf or link failure.

Question 146

Which ACI protocol can be used to dynamically exchange routes with an external router?

  1. LLDP
  2. CDP
  3. OSPF
  4. SNMP

Correct Answer: 3

Explanation

OSPF can be configured through an ACI L3Out to dynamically exchange routing information with an external router. As a link-state routing protocol, OSPF establishes neighbor relationships and exchanges routing information within the configured area. LLDP and CDP are discovery protocols, while SNMP provides management and monitoring capabilities. Administrators configuring OSPF should verify interface addressing, area configuration, adjacency state, and route advertisement policies. If an expected external route is missing, both the OSPF neighbor relationship and ACI route-control configuration should be examined. Proper OSPF configuration allows the fabric to dynamically learn and advertise supported external prefixes.

Question 147

Which ACI component is used to represent external Layer 3 destinations for contract-based policy?

  1. External EPG
  2. Application profile
  3. Physical domain
  4. VLAN pool

Correct Answer: 1

Explanation

An External EPG represents external destinations connected through an L3Out. Administrators can define external subnet prefixes under an external EPG and then use contracts to control communication between internal EPGs and those external destinations. Application profiles organize internal EPGs, physical domains provide connectivity for physical endpoints, and VLAN pools supply encapsulation resources. External EPGs are important for applying policy at the boundary between the ACI fabric and outside networks. When troubleshooting external access, administrators should verify the external subnet definition, L3Out association, contract relationship, routing configuration, and route-control policies.

Question 148

Which ACI feature controls whether endpoint information is retained after an endpoint is no longer actively detected?

  1. Endpoint retention policy
  2. Filter
  3. Contract subject
  4. VLAN pool

Correct Answer: 1

Explanation

An endpoint retention policy controls how learned endpoint information is handled when an endpoint is no longer actively detected. This can affect how quickly stale endpoint entries are removed or retained in the fabric. Proper endpoint retention behavior is important in environments where workloads move between interfaces or where endpoints frequently disconnect and reconnect. Filters and contract subjects control communication policy, while VLAN pools provide encapsulation resources. When troubleshooting stale endpoint information, administrators should review the endpoint table, retention settings, interface state, and learning behavior. Correct retention configuration helps the fabric maintain accurate endpoint information while avoiding unnecessary stale entries.

Question 149

Which ACI object contains EPGs representing different tiers of an application?

  1. Application profile
  2. Bridge domain
  3. VLAN pool
  4. Interface selector

Correct Answer: 1

Explanation

An application profile contains EPGs representing logical components or tiers of an application. A common design may include separate EPGs for web, application, and database workloads. The EPGs can then use contracts to define the allowed communication between those tiers. Bridge domains provide forwarding domains, VLAN pools provide encapsulation resources, and interface selectors identify physical ports for access policies. Application profiles help administrators organize policy around application requirements instead of physical network topology. When designing an ACI environment, application profiles should reflect meaningful application boundaries and should be combined with contracts that accurately represent the required service dependencies.

Question 150

Which ACI access-policy object identifies a group of leaf switches where an interface profile should be applied?

  1. Switch profile
  2. Filter
  3. External EPG
  4. Contract

Correct Answer: 4

Explanation

A switch profile identifies the leaf switches to which a particular access-policy configuration applies. It works with interface profiles and selectors to determine where interface policies should be deployed. This hierarchical structure allows administrators to configure access settings consistently across selected leaf switches and interfaces. Filters define contract traffic, external EPGs represent outside networks, and contracts define communication relationships. When an interface policy does not appear on a leaf, administrators should verify the switch profile, interface profile, selector, and policy-group relationships. Proper access-policy hierarchy ensures that configuration is applied only to the intended switches and interfaces.

Question 151

Which ACI object defines a logical grouping of physical interfaces for applying interface policies?

  1. Interface profile
  2. VRF
  3. EPG
  4. L3Out

Correct Answer: 1

Explanation

An interface profile provides a logical grouping of interfaces within the ACI access-policy model. It works with interface selectors to identify the specific ports where an interface policy group should be applied. This structure allows administrators to organize interface configuration efficiently across leaf switches. VRFs provide routing contexts, EPGs group endpoints, and L3Outs provide external Layer 3 connectivity. When configuring access interfaces, administrators should verify the relationship between the switch profile, interface profile, interface selector, and policy group. An incorrect interface profile can cause the intended policy to be applied to the wrong ports or prevent it from being deployed.

Question 152

Which ACI bridge-domain setting controls the treatment of ARP requests that cannot be resolved through endpoint information?

  1. Unicast routing
  2. ARP flooding
  3. Endpoint retention
  4. Route control

Correct Answer: 2

Explanation

The ARP flooding setting controls how ARP requests are handled when the destination information is not available through endpoint learning. When appropriate, ARP requests can be flooded within the bridge domain so that the intended destination can respond. Unicast routing controls Layer 3 forwarding, endpoint retention manages learned endpoint information, and route control policies influence external route exchange. Administrators should select ARP behavior according to the application requirements and traffic design. If hosts cannot resolve each other’s IP-to-MAC mappings, checking the bridge-domain ARP configuration, endpoint learning state, subnet configuration, and connectivity can help identify the problem.

Question 153

Which ACI feature is used to control the routes that an L3Out advertises to an external network?

  1. Route control policy
  2. VLAN pool
  3. Application profile
  4. Interface selector

Correct Answer: 1

Explanation

Route control policies provide control over which routes are advertised or accepted through an ACI L3Out. They can be used to filter or influence route exchange with external routing domains. This is particularly useful when an organization needs to limit external advertisements or control which prefixes are imported into the fabric. VLAN pools provide encapsulation resources, application profiles organize EPGs, and interface selectors identify physical interfaces. When troubleshooting missing or unexpected external routes, administrators should examine route-control configuration along with the routing protocol, external subnet definitions, and L3Out settings. Correct route control helps maintain predictable external routing behavior.

Question 154

Which ACI technology provides logical segmentation of tenant traffic over the physical fabric?

  1. CDP
  2. VXLAN
  3. SNMP
  4. LLDP

Correct Answer: 2

Explanation

VXLAN provides the overlay mechanism used to transport logically segmented traffic across the ACI fabric. It allows different tenants, EPGs, and logical networks to share the same physical leaf-and-spine infrastructure while maintaining separate forwarding contexts. Leaf switches encapsulate traffic for transport across the fabric, and the appropriate destination leaf performs the required processing. CDP and LLDP are discovery protocols, while SNMP is used for monitoring and management. Understanding VXLAN is useful when troubleshooting inter-leaf traffic because administrators can examine endpoint learning, encapsulation, fabric paths, and policy deployment to determine why traffic is not reaching the expected destination.

Question 155

Which ACI object is used to provide Layer 2 external connectivity?

  1. L2Out
  2. L3Out
  3. VRF
  4. VMM domain

Correct Answer: 1

Explanation

L2Out provides Layer 2 connectivity between the ACI fabric and an external Layer 2 network. It is used when external devices need to participate in Layer 2 connectivity rather than establishing routed Layer 3 communication through an L3Out. An L3Out provides routed connectivity, a VRF defines a routing context, and a VMM domain integrates virtual environments. When deploying an L2Out, administrators should verify the external interface, encapsulation, bridge-domain association, and applicable policy. Troubleshooting should also include endpoint learning and interface status to ensure that Layer 2 traffic can move correctly between the ACI fabric and external network.

Question 156

Which ACI construct can simplify communication policy when multiple EPGs should have unrestricted communication within a defined group?

  1. Preferred group
  2. VLAN pool
  3. L3Out
  4. Interface profile

Correct Answer: 4

Explanation

A preferred group can simplify policy when selected EPGs within a VRF need to communicate without creating separate contracts for every individual EPG relationship. It allows administrators to define a group of EPGs that can communicate according to the preferred-group configuration. VLAN pools provide encapsulation resources, L3Outs provide external connectivity, and interface profiles organize physical interfaces. Preferred groups should be planned carefully because they can permit broader communication than a tightly defined contract model. Administrators should identify the intended members and verify that the resulting communication scope matches the application’s security requirements before applying this configuration.

Question 157

Which protocol provides vendor-neutral neighbor discovery information on an ACI interface?

  1. BGP
  2. OSPF
  3. LLDP
  4. SNMP

Correct Answer: 3

Explanation

LLDP provides vendor-neutral neighbor discovery information between directly connected network devices. It can identify neighboring systems, interfaces, and other device characteristics and is useful in multi-vendor environments. BGP and OSPF are routing protocols, while SNMP is used for monitoring and management. In ACI, LLDP can be enabled through interface policies and applied using interface policy groups. When validating physical connectivity, administrators can compare LLDP information with the expected topology. This helps identify incorrect cabling, unexpected neighbors, or interface connections that do not match the intended network design.

Question 158

Which ACI object defines the routing domain used by an L3Out?

  1. VRF
  2. Filter
  3. Application profile
  4. VLAN pool

Correct Answer: 2

Explanation

An L3Out is associated with a VRF, which determines the routing context used for external Layer 3 connectivity. The VRF provides the routing table in which external routes are learned and advertised. Filters define contract traffic, application profiles organize EPGs, and VLAN pools provide encapsulation resources. When configuring an L3Out, administrators should confirm that it is associated with the intended VRF because this determines which internal routing environment can use the external connection. Incorrect VRF association can cause external routes to be unavailable to the intended bridge domains or can create unintended routing relationships between separate environments.

Question 159

Which ACI feature allows a contract to permit communication only for specific TCP or UDP ports?

  1. Filter
  2. VLAN pool
  3. VRF
  4. Physical domain

Correct Answer: 1

Explanation

A filter allows administrators to specify protocols and port ranges that can be permitted by an ACI contract. For example, a filter can define TCP traffic for a particular application service rather than allowing all protocols between two EPGs. The filter is referenced by a contract subject, and the contract establishes the relationship between consumer and provider EPGs. VLAN pools provide encapsulation resources, VRFs provide routing contexts, and physical domains connect EPGs to physical endpoints. Using specific filters allows application communication to be controlled according to actual service requirements and helps avoid unnecessarily broad connectivity.

Question 160

Which ACI component provides direct physical connectivity for endpoints such as servers?

  1. APIC
  2. Spine switch
  3. Leaf switch
  4. External router

Correct Answer: 3

Explanation

Leaf switches provide the direct physical connectivity used by servers and other endpoints in Cisco ACI. Endpoint-facing interfaces are configured through the ACI access-policy model, and the appropriate EPG policy is deployed to those interfaces. Spine switches provide transit between leaf switches, APIC controllers provide centralized management and policy orchestration, and external routers provide connectivity beyond the fabric. When troubleshooting a server connection, administrators should inspect the relevant leaf interface, interface policy group, VLAN encapsulation, domain association, EPG deployment, and endpoint learning information. These components collectively determine whether the endpoint can successfully communicate through the ACI fabric.