{"id":21220,"date":"2026-09-24T11:36:21","date_gmt":"2026-09-24T11:36:21","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=21220"},"modified":"2026-09-24T11:36:21","modified_gmt":"2026-09-24T11:36:21","slug":"cisco-ccnp-data-center-300-620-practice-test-questions-and-exam-dumps-part3-q41-60","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-data-center-300-620-practice-test-questions-and-exam-dumps-part3-q41-60\/","title":{"rendered":"Cisco CCNP Data Center 300-620 Practice Test Questions and Exam Dumps Part3 Q41-60"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-620-exam-dumps\"><b>Cisco CCNP Data Center 300-620 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 41<\/b><\/h3>\n<p><b>Which ACI component is responsible for forwarding traffic between leaf switches through the fabric?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">APIC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bridge domain<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spine switch<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Spine switches provide the transit infrastructure between leaf switches in a Cisco ACI fabric. The leaf-and-spine architecture connects every leaf to the spine layer, allowing traffic to move efficiently across the fabric. Leaf switches connect endpoints and external devices, while spine switches provide high-speed forwarding between leaf nodes. APIC manages the fabric policies but does not serve as the normal data-plane transit device. Endpoint groups and bridge domains are logical policy objects rather than physical switching components. Because spine switches form the central transit layer, administrators should monitor their connectivity and health carefully when troubleshooting traffic flow across different leaf switches.<\/span><\/p>\n<h3><b>Question 42<\/b><\/h3>\n<p><b>Which ACI object defines a group of endpoints that share common policy requirements?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VRF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EPG<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">L3Out<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN pool<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Endpoint Group, or EPG, groups endpoints that share common application or policy requirements. Endpoints can include physical servers, virtual machines, and other connected devices. EPGs are one of the central concepts in Cisco ACI because policies can be applied to groups of endpoints rather than individual devices. Contracts define communication between EPGs, while VRFs provide routing contexts. L3Out provides external Layer 3 connectivity, and VLAN pools define VLAN resources. Proper EPG design helps administrators create application-centric policies and simplifies security management. When troubleshooting connectivity, administrators should verify the endpoint&#8217;s EPG membership and associated policies.<\/span><\/p>\n<h3><b>Question 43<\/b><\/h3>\n<p><b>Which ACI object defines the communication policy between a consumer EPG and a provider EPG?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Contract<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bridge domain<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VRF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tenant<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A contract defines the communication policy between consumer and provider EPGs in Cisco ACI. Contracts can contain filters that specify which traffic is permitted between the participating EPGs. This model allows administrators to implement application-centric security and explicitly define communication relationships. A bridge domain provides a forwarding domain, a VRF provides a routing context, and a tenant provides an administrative boundary. When an EPG cannot communicate with another EPG, administrators should verify whether an appropriate contract relationship exists and whether the contract filters permit the required traffic. Correct contract configuration is therefore essential for controlled inter-EPG communication.<\/span><\/p>\n<h3><b>Question 44<\/b><\/h3>\n<p><b>What is the primary purpose of an ACI physical domain?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To connect APIC controllers<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To define routing protocols<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To associate EPGs with physical endpoints<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To create search policies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A physical domain allows ACI endpoint groups to be associated with physical infrastructure connected to leaf interfaces. It is commonly used for bare-metal servers, physical appliances, and other devices that connect directly to ACI leaf switches. Physical domains can be associated with VLAN pools and appropriate access policies. APIC controllers use separate management and cluster configuration, while routing protocols are configured through relevant routing objects such as L3Out. A search policy is unrelated to ACI endpoint attachment. Correct physical-domain configuration ensures that the intended EPG can be deployed on the required physical interfaces with the appropriate VLAN encapsulation.<\/span><\/p>\n<h3><b>Question 45<\/b><\/h3>\n<p><b>Which ACI feature provides connectivity between the fabric and an external Layer 3 network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">L3Out<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">L2Out<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EPG<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VMM domain<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An L3Out provides routed Layer 3 connectivity between an ACI fabric and an external network. It can support static or dynamic routing depending on the configured design and supported protocols. L2Out is used for extending Layer 2 connectivity, while EPGs group endpoints according to application policies. A VMM domain provides integration with supported virtualization environments. L3Out configuration normally involves external routed nodes, interfaces, routing configuration, and external endpoint groups. Administrators should verify the external interface, routing relationships, and advertised prefixes when troubleshooting connectivity between ACI workloads and networks outside the fabric.<\/span><\/p>\n<h3><b>Question 46<\/b><\/h3>\n<p><b>Which ACI object provides the Layer 3 routing context used by bridge domains?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Contract<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application profile<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EPG<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VRF<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A VRF provides the Layer 3 routing context for bridge domains in Cisco ACI. Bridge domains associated with the same VRF participate in the same routing domain, while different VRFs provide logical routing separation. This design allows administrators to isolate routing information between different applications, tenants, or environments. Contracts control communication policies, application profiles organize EPGs, and EPGs group endpoints. When troubleshooting Layer 3 connectivity, verifying the bridge domain&#8217;s VRF association is important. An incorrect VRF association can prevent expected communication even when endpoint attachment and physical connectivity appear to be functioning correctly.<\/span><\/p>\n<h3><b>Question 47<\/b><\/h3>\n<p><b>Which protocol is commonly used for dynamic routing between an ACI L3Out and an external router?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OSPF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CDP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LLDP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">STP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">OSPF can be configured as a dynamic routing protocol for an ACI L3Out. It allows ACI and an external router to exchange routing information dynamically rather than relying only on static routes. Administrators must configure compatible OSPF parameters on both sides, including the appropriate area and interface settings. CDP and LLDP are neighbor-discovery protocols, while STP is used for Layer 2 loop prevention. After configuring OSPF, administrators should verify adjacency status and routing tables to confirm that routes are being exchanged as expected. Proper routing configuration is essential for reliable communication between ACI workloads and external Layer 3 networks.<\/span><\/p>\n<h3><b>Question 48<\/b><\/h3>\n<p><b>What is the primary function of a VLAN pool in Cisco ACI?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To define a set of VLAN IDs available for allocation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To store endpoint MAC addresses<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To create routing tables<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To manage APIC users<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A VLAN pool defines VLAN IDs that ACI can allocate for appropriate connectivity domains. VLAN pools are commonly associated with physical domains, external connectivity, and virtualization-related domains depending on the design. They provide a controlled range of VLAN encapsulations that can be assigned to EPG connectivity requirements. VLAN pools do not create routing tables, store endpoint information, or manage APIC users. Administrators should ensure that the configured VLAN ranges match the network design and do not overlap inappropriately with other VLAN assignments. Correct VLAN pool configuration is important for successful endpoint attachment and domain deployment.<\/span><\/p>\n<h3><b>Question 49<\/b><\/h3>\n<p><b>Which ACI domain is designed to integrate ACI with a supported virtual machine manager?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Physical domain<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">L3Out<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VMM domain<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Management domain<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A VMM domain integrates Cisco ACI with a supported virtual machine manager such as VMware vCenter. This integration allows ACI policy to be associated with virtual workloads and virtual networking infrastructure. Administrators can map EPGs to virtual environments and coordinate network policy with virtual machine placement. A physical domain is used for physical endpoints, while L3Out provides external routed connectivity. Management domains address management connectivity rather than virtual workload integration. Proper VMM configuration requires coordination between APIC, the virtualization platform, VLAN or encapsulation resources, and EPG policies. This enables consistent application-centric policy for virtualized workloads.<\/span><\/p>\n<h3><b>Question 50<\/b><\/h3>\n<p><b>Which ACI object can specify protocols and Layer 4 ports that are permitted by a contract?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VRF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tenant<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bridge domain<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An ACI filter defines the traffic characteristics that can be matched by a contract. It can specify protocols and Layer 4 ports so that the contract permits only the traffic required by the application relationship. The filter is referenced by the contract between consumer and provider EPGs. VRFs provide routing contexts, tenants provide administrative boundaries, and bridge domains provide forwarding domains. Administrators should design filters carefully because overly broad rules can allow unnecessary traffic, while overly restrictive rules can prevent required application communication. Reviewing contract and filter configuration is an important step when troubleshooting inter-EPG connectivity.<\/span><\/p>\n<h3><b>Question 51<\/b><\/h3>\n<p><b>Which ACI object is used to organize related EPGs representing different application tiers?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application profile<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">L3Out<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Interface selector<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An application profile organizes related endpoint groups that represent application components or tiers. For example, an application profile can contain separate EPGs for web, application, and database workloads. Contracts can then define the permitted communication between those EPGs. VLAN pools provide VLAN resources, L3Out handles external routed connectivity, and interface selectors identify leaf interfaces. Application profiles provide a logical structure that aligns network policy with application architecture. This organization helps administrators understand how EPGs relate to one another and makes policy management easier. It also supports a consistent application-centric approach to security and connectivity within the ACI fabric.<\/span><\/p>\n<h3><b>Question 52<\/b><\/h3>\n<p><b>Which management approach uses a separate management network to reach ACI infrastructure?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">In-band management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Out-of-band management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VXLAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint learning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Out-of-band management uses a dedicated management network that is separate from the production data path. This approach can provide administrators with access to infrastructure management functions even when there are problems affecting the production fabric. In-band management uses the ACI network infrastructure for management traffic. VXLAN is associated with data-plane encapsulation, while endpoint learning is part of endpoint discovery and forwarding behavior. Administrators should select the management architecture according to operational and availability requirements. A properly designed out-of-band network can be particularly useful during troubleshooting because it can provide access when production forwarding or policy problems affect normal network connectivity.<\/span><\/p>\n<h3><b>Question 53<\/b><\/h3>\n<p><b>Which protocol is commonly used by Cisco devices to discover directly connected Cisco neighbors?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CDP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OSPF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cisco Discovery Protocol, or CDP, is a Cisco-proprietary protocol used to discover information about directly connected Cisco devices. It can provide details such as the neighboring device identity, interface, platform, and capabilities. CDP is useful during physical topology validation and troubleshooting. OSPF and BGP are routing protocols, while DHCP provides dynamic IP address configuration. In ACI, CDP behavior can be controlled through interface policies. Administrators can use CDP information to confirm that an interface is connected to the expected Cisco device. This can help identify cabling errors, incorrect connections, or unexpected neighboring infrastructure.<\/span><\/p>\n<h3><b>Question 54<\/b><\/h3>\n<p><b>Which standards-based protocol can provide neighbor information between devices from different vendors?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HSRP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LLDP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BFD<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Link Layer Discovery Protocol, or LLDP, is a standards-based neighbor discovery protocol that can operate across multivendor network environments. Devices use LLDP to advertise information about themselves and their interfaces to directly connected neighbors. This information can help administrators validate physical connectivity and identify neighboring infrastructure. HSRP provides gateway redundancy, BFD provides rapid failure detection, and VTP is associated with VLAN management. In ACI environments, LLDP can be enabled or controlled through interface policies. Administrators can use LLDP information during deployment and troubleshooting to confirm that physical connections correspond to the intended topology.<\/span><\/p>\n<h3><b>Question 55<\/b><\/h3>\n<p><b>Which ACI feature provides Layer 2 connectivity between the fabric and an external Layer 2 network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">L3Out<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">L2Out<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VRF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Contract<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">L2Out provides Layer 2 connectivity between the ACI fabric and an external Layer 2 network. It can extend Layer 2 communication beyond the ACI fabric while maintaining the required EPG and bridge-domain policy relationships. L3Out is intended for routed Layer 3 external connectivity, while VRFs provide routing contexts and contracts define communication policies. When configuring L2Out, administrators need to consider VLAN encapsulation, external interfaces, EPG associations, and Layer 2 control requirements. Proper configuration helps ensure that endpoints on the ACI side and external Layer 2 network can communicate according to the intended design.<\/span><\/p>\n<h3><b>Question 56<\/b><\/h3>\n<p><b>Which ACI feature can be used to filter routes exchanged with an external network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint retention policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route control policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application profile<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Route control policies provide mechanisms for controlling route advertisement and route acceptance associated with external connectivity. They can be used with appropriate L3Out configurations to influence which prefixes are exchanged with external networks. Endpoint retention policies affect endpoint information, VLAN pools manage VLAN resources, and application profiles organize EPGs. Administrators can use route control to implement selective routing requirements and prevent unwanted prefixes from being advertised or accepted. Careful testing is important because an incorrect route-control configuration can cause required networks to disappear from routing tables or unintentionally expose additional routes to an external environment.<\/span><\/p>\n<h3><b>Question 57<\/b><\/h3>\n<p><b>What does an ACI endpoint group primarily represent?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A physical spine switch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A collection of endpoints with common policy requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A routing protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">An APIC controller<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An endpoint group represents a collection of endpoints that share common policy requirements in Cisco ACI. The endpoints can be physical or virtual workloads, depending on the configured domain. EPGs allow administrators to apply application-centric policies to groups of endpoints rather than configuring each device separately. Contracts determine permitted communication between EPGs, while VRFs provide routing contexts. Spine switches and APIC controllers are physical or infrastructure components rather than endpoint groups. Correct EPG assignment is important for connectivity because the EPG determines which policies and contracts apply to an endpoint. Administrators should verify EPG membership when investigating unexpected access behavior.<\/span><\/p>\n<h3><b>Question 58<\/b><\/h3>\n<p><b>Which ACI object defines a Layer 2 forwarding domain and can provide a gateway subnet?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bridge domain<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Contract<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application profile<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN pool<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A bridge domain represents a Layer 2 forwarding domain in ACI and can contain a subnet that provides gateway functionality for connected endpoints. Bridge domains are associated with VRFs and can have settings that influence routing, flooding, and endpoint behavior. Contracts control communication between EPGs, application profiles organize EPGs, and VLAN pools provide VLAN resources. When designing an ACI network, administrators should associate bridge domains with the correct VRF and configure the appropriate subnet and forwarding settings. These elements work together to provide the Layer 2 and Layer 3 behavior required by applications connected to the ACI fabric.<\/span><\/p>\n<h3><b>Question 59<\/b><\/h3>\n<p><b>Which ACI component provides centralized policy management and fabric configuration?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spine switch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Leaf switch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">APIC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Border router<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Application Policy Infrastructure Controller, or APIC, provides centralized management and policy control for the Cisco ACI fabric. Administrators use APIC to configure tenants, VRFs, bridge domains, EPGs, contracts, domains, access policies, and other fabric objects. Leaf and spine switches implement the resulting forwarding behavior, while external routers provide connectivity outside the fabric. APIC therefore serves as the central management platform rather than a conventional data-plane forwarding device. In production environments, APIC controllers operate as a cluster to provide management resiliency. Administrators should monitor APIC cluster health and ensure that controllers maintain proper communication with the fabric.<\/span><\/p>\n<h3><b>Question 60<\/b><\/h3>\n<p><b>Which ACI architecture connects every leaf switch to every spine switch?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Three-tier architecture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hub-and-spoke architecture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ring architecture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Leaf-and-spine architecture<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cisco ACI uses a leaf-and-spine architecture in which each leaf switch connects to each spine switch. This provides multiple paths across the fabric and creates a predictable, scalable topology. Leaf switches connect endpoints and external networks, while spine switches provide transit between leaf switches. The architecture avoids the traditional hierarchical access-distribution-core model and instead uses a consistent fabric design. Adding leaf switches increases endpoint connectivity, while adding spine switches increases fabric capacity and path availability. Understanding this architecture is fundamental to ACI deployment because physical connectivity, forwarding behavior, and fabric scalability all depend on the leaf-and-spine model.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP Data Center 300-620 Exam Dumps and Practice Test Dumps. &nbsp; Question 41 Which ACI component is responsible for forwarding traffic between leaf switches through the fabric? APIC Endpoint group Bridge domain Spine switch Correct Answer: 4 Explanation Spine switches provide the transit infrastructure between leaf switches in a Cisco ACI fabric. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21220"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=21220"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21220\/revisions"}],"predecessor-version":[{"id":21221,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21220\/revisions\/21221"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=21220"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=21220"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=21220"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}