{"id":21250,"date":"2026-09-24T11:41:35","date_gmt":"2026-09-24T11:41:35","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=21250"},"modified":"2026-09-24T11:41:35","modified_gmt":"2026-09-24T11:41:35","slug":"cisco-ccnp-data-center-300-620-practice-test-questions-and-exam-dumps-part18-q341-360","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-data-center-300-620-practice-test-questions-and-exam-dumps-part18-q341-360\/","title":{"rendered":"Cisco CCNP Data Center 300-620 Practice Test Questions and Exam Dumps Part18 Q341-360"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-620-exam-dumps\"><b>Cisco CCNP Data Center 300-620 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 341<\/b><\/h3>\n<p><b>Which ACI component is responsible for providing the default gateway function for endpoints within a bridge domain?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Contract<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bridge-domain subnet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Interface selector<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A bridge-domain subnet can provide the default gateway address used by endpoints associated with that bridge domain. The subnet is configured under the bridge domain and provides Layer 3 connectivity for attached workloads. Contracts control communication between EPGs, VLAN pools provide encapsulation resources, and interface selectors identify physical interfaces. When an endpoint cannot communicate beyond its local network, administrators should verify that the bridge-domain subnet exists, is associated with the correct VRF, and has the expected gateway configuration. They should also check endpoint attachment, routing behavior, and applicable contracts to ensure that the complete policy chain is functioning correctly.<\/span><\/p>\n<h3><b>Question 342<\/b><\/h3>\n<p><b>Which ACI component provides the transit layer between leaf switches in the fabric?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spine switch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">APIC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">External router<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Border leaf interface<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Spine switches provide the transit layer between leaf switches in the ACI fabric. Endpoints normally connect to leaf switches, while the spine layer provides high-speed connectivity between leaves. APIC provides centralized management and policy orchestration rather than serving as the normal endpoint data-plane transit layer. External routers provide connectivity beyond the fabric. The leaf-and-spine architecture gives ACI predictable connectivity and scalable forwarding. During troubleshooting, administrators should verify that leaf switches have healthy spine connections and that fabric links are operational. A failure in the spine layer can affect communication between endpoints attached to different leaf switches.<\/span><\/p>\n<h3><b>Question 343<\/b><\/h3>\n<p><b>Which ACI policy object controls communication by specifying permitted protocols and port ranges?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Contract<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VRF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN pool<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A filter defines specific traffic characteristics such as protocols and source or destination ports that can be permitted by an ACI contract. The contract establishes the communication relationship, while the filter provides the detailed traffic criteria. A VRF defines a routing context, and a VLAN pool provides VLAN encapsulation resources. When an application flow is unexpectedly blocked, administrators should inspect the contract subject and verify that the associated filter contains the correct protocol and port definitions. A mismatch between the application&#8217;s actual traffic and the configured filter can result in denied communication even when the consumer and provider EPG relationships are correctly configured.<\/span><\/p>\n<h3><b>Question 344<\/b><\/h3>\n<p><b>Which ACI feature provides integration between the fabric and a supported virtualization platform?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Physical domain<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">L3Out<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VMM domain<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">External EPG<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A VMM domain provides integration between Cisco ACI and a supported virtualization platform. It allows ACI policy to be associated with virtual workloads and virtualization networking resources. Physical domains are intended for physical endpoint connectivity, L3Outs provide external Layer 3 connectivity, and External EPGs represent external network destinations. VMM domains commonly work with VLAN pools and EPG configurations to provide the required virtual network connectivity. If virtual machines do not receive expected policy, administrators should verify the VMM domain association, virtualization controller connection, VLAN pool, EPG deployment, and endpoint learning information.<\/span><\/p>\n<h3><b>Question 345<\/b><\/h3>\n<p><b>Which ACI feature determines how long learned endpoint information is retained after an endpoint becomes inactive?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deployment immediacy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint retention policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP flooding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The endpoint retention policy controls how endpoint information is retained after an endpoint is no longer actively detected. This can affect how quickly stale endpoint information is removed and how the fabric responds to endpoint movement or disappearance. Deployment immediacy controls policy programming, ARP flooding controls ARP handling, and route control influences external routing information. When troubleshooting stale endpoint entries, administrators should review endpoint retention settings along with endpoint learning, interface state, and recent endpoint movement. Proper retention behavior helps the fabric maintain an accurate representation of where workloads are currently connected.<\/span><\/p>\n<h3><b>Question 346<\/b><\/h3>\n<p><b>Which ACI access-policy object combines multiple individual interface policies into a reusable configuration?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Interface policy group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bridge domain<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">External EPG<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VRF<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An interface policy group combines multiple individual interface policies into a reusable configuration. Policies for features such as CDP, LLDP, speed, storm control, and link aggregation can be included according to the required interface behavior. Bridge domains provide forwarding characteristics, External EPGs represent external destinations, and VRFs provide routing contexts. The interface policy group is then associated with interface selectors through the ACI access-policy hierarchy. When troubleshooting a physical interface, administrators should verify that the intended policy group is selected and that each included interface policy is correctly configured and deployed to the target leaf port.<\/span><\/p>\n<h3><b>Question 347<\/b><\/h3>\n<p><b>Which ACI object is used to represent networks outside the fabric that are connected through an L3Out?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">External EPG<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application profile<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Physical domain<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An External EPG represents external network destinations reachable through an L3Out. External subnets can be associated with the External EPG, and contracts can control communication between internal EPGs and those external destinations. Application profiles organize internal EPGs, VLAN pools provide encapsulation resources, and physical domains define physical endpoint connectivity. When configuring north-south communication, administrators should verify the External EPG subnet definitions, L3Out association, VRF, routing configuration, and contract relationships. External EPGs provide an important policy boundary for controlling traffic between workloads inside the ACI fabric and networks located outside the fabric.<\/span><\/p>\n<h3><b>Question 348<\/b><\/h3>\n<p><b>Which ACI routing protocol is a path-vector protocol commonly used for external connectivity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OSPF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BFD<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LLDP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">BGP is a path-vector routing protocol commonly used for external connectivity through an ACI L3Out. It can exchange routing information between the ACI fabric and external autonomous systems or other BGP-speaking routers. OSPF is a link-state routing protocol, BFD provides rapid failure detection, and LLDP provides neighbor discovery. When troubleshooting BGP connectivity, administrators should verify the local and remote autonomous-system configuration, neighbor IP addresses, interface status, authentication if configured, and route-control policies. A successfully established BGP session does not necessarily mean that all required routes are being advertised or accepted, so routing policy should also be examined.<\/span><\/p>\n<h3><b>Question 349<\/b><\/h3>\n<p><b>Which ACI component logically organizes multiple EPGs that belong to an application?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application profile<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Interface selector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">L3Out<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An application profile provides a logical container for multiple EPGs that together represent an application or service. For example, web, application, and database EPGs can be grouped within one application profile. VLAN pools provide encapsulation resources, interface selectors identify physical ports, and L3Outs provide external routed connectivity. Application profiles help administrators organize policy according to application structure rather than physical location. When reviewing an application deployment, administrators can use the application profile to locate related EPGs and then examine their bridge domains, contracts, domains, and endpoint attachments to understand how the application is implemented across the ACI fabric.<\/span><\/p>\n<h3><b>Question 350<\/b><\/h3>\n<p><b>Which ACI feature controls the handling of Layer 2 frames when the destination MAC address is unknown?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint retention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unknown unicast behavior<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Intra-EPG isolation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Unknown unicast behavior controls how ACI handles Layer 2 frames when the destination MAC address is not present in the known endpoint information. Depending on the bridge-domain configuration, unknown unicast traffic can be handled through the configured flooding behavior. Endpoint retention controls how learned information is retained, intra-EPG isolation controls communication between endpoints within an EPG, and route control influences external routing. When troubleshooting unexpected Layer 2 flooding or missing connectivity, administrators should inspect endpoint learning, bridge-domain settings, unknown-unicast behavior, and endpoint location. These settings help determine how the fabric handles traffic when the destination is not yet known.<\/span><\/p>\n<h3><b>Question 351<\/b><\/h3>\n<p><b>Which ACI object provides the routing context that separates traffic between different logical environments?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VRF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Contract<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN pool<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A VRF provides an independent Layer 3 routing context that separates routes between different logical environments. Multiple bridge domains can exist within a VRF, while separate VRFs provide routing isolation. Filters define traffic characteristics, contracts control communication policy, and VLAN pools provide encapsulation resources. VRF separation is important in multi-tenant ACI deployments because it prevents routes from different logical environments from being automatically combined. When troubleshooting unexpected routing behavior, administrators should verify the bridge-domain VRF association, subnet configuration, L3Out relationships, and route tables. Correct VRF assignment is fundamental to maintaining the intended network segmentation.<\/span><\/p>\n<h3><b>Question 352<\/b><\/h3>\n<p><b>Which ACI access-policy component identifies a range of physical interfaces to which an interface policy group is applied?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Contract subject<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Interface selector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">External EPG<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route control profile<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An interface selector identifies the specific physical interfaces or ranges of interfaces that receive an interface policy group. It is part of the access-policy hierarchy and provides the connection between logical policy configuration and actual leaf ports. Contract subjects define how filters are applied, External EPGs represent external destinations, and route-control profiles influence routing policy. If a policy is not appearing on the expected port, administrators should verify the switch profile, interface profile, selector, and associated policy group. They should also confirm that the correct leaf switch and interface range were selected during configuration.<\/span><\/p>\n<h3><b>Question 353<\/b><\/h3>\n<p><b>Which ACI feature can be used to limit communication between endpoints that belong to the same EPG?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Intra-EPG isolation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Preferred group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BFD<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Intra-EPG isolation limits direct communication between endpoints that belong to the same EPG. It is useful when workloads are grouped together for administrative or application reasons but should not have unrestricted lateral connectivity. Preferred groups address communication between selected EPGs, VLAN pools provide VLAN resources, and BFD detects forwarding failures. Before enabling isolation, administrators should confirm that the application&#8217;s traffic requirements will not be disrupted. When same-EPG communication fails unexpectedly, the isolation setting should be reviewed together with endpoint learning, bridge-domain configuration, and any required policy relationships. This helps distinguish intentional segmentation from an accidental connectivity problem.<\/span><\/p>\n<h3><b>Question 354<\/b><\/h3>\n<p><b>Which ACI component is used to define a logical connection between a leaf node and an external Layer 3 device?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application profile<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Logical node profile<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Contract filter<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A logical node profile identifies the external nodes participating in an ACI L3Out and provides the logical relationship between the ACI fabric and external Layer 3 devices. It works together with a logical interface profile, which defines the associated interface configuration. Application profiles organize internal EPGs, VLAN pools provide encapsulation resources, and contract filters define traffic characteristics. When troubleshooting an L3Out connection, administrators should verify the logical node profile, external node addresses, logical interface profile, physical path, routing protocol, and VRF association. Correct node-profile configuration is required for the ACI fabric to establish the intended external routed connectivity.<\/span><\/p>\n<h3><b>Question 355<\/b><\/h3>\n<p><b>Which ACI feature is used to control which external routes are imported or exported through an L3Out?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route control policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint retention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Interface selector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VMM domain<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Route-control policies influence which routes are imported into or exported from an ACI L3Out. They can be used to apply route filtering and policy actions to external routing information. Endpoint retention manages learned endpoint information, interface selectors identify physical interfaces, and VMM domains integrate virtualization platforms. Route-control configuration is especially important when an external routing environment should receive only selected prefixes or when only certain external routes should be accepted by ACI. During troubleshooting, administrators should examine the route-control profile, match criteria, actions, and association with the relevant L3Out or routing configuration.<\/span><\/p>\n<h3><b>Question 356<\/b><\/h3>\n<p><b>Which ACI protocol is used to exchange link-state routing information with an external OSPF router?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OSPF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CDP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LLDP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">OSPF is used to exchange link-state routing information between an ACI L3Out and an external OSPF-speaking router. OSPF establishes neighbor relationships and exchanges link-state information to build routing knowledge. BGP is a path-vector protocol, while CDP and LLDP are neighbor-discovery protocols. When configuring OSPF through an L3Out, administrators should verify the OSPF area, interface addressing, neighbor state, and routing policy. They should also confirm that the desired prefixes are being imported or exported. A functioning adjacency alone does not guarantee that the required application routes are available to endpoints inside the ACI fabric.<\/span><\/p>\n<h3><b>Question 357<\/b><\/h3>\n<p><b>Which ACI management option uses the production fabric to carry management traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Out-of-band management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Console management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">In-band management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">External router management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">In-band management uses the ACI production fabric to carry management traffic. This approach can provide management access without requiring a completely separate physical management network. Out-of-band management uses dedicated management connectivity, while console access provides direct device-level access and external router management is not an ACI management mode. When designing in-band management, administrators should consider the required management EPG, routing, contracts, and fabric availability. If the production fabric experiences a significant policy or forwarding failure, in-band access can also be affected. Understanding this dependency is important when planning operational access and troubleshooting procedures.<\/span><\/p>\n<h3><b>Question 358<\/b><\/h3>\n<p><b>Which ACI object is responsible for defining the logical relationship between a group of leaf switches and their interface profiles?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Switch profile<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">External EPG<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bridge domain<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Contract<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A switch profile is used within the ACI access-policy hierarchy to associate leaf switches with their relevant interface profiles. It helps organize configuration so that interface policies can be consistently applied to the intended switches and ports. External EPGs represent external destinations, bridge domains define forwarding contexts, and contracts define communication policy. When configuring access policies, administrators should trace the hierarchy from the switch profile through the interface profile and selector to the interface policy group. Incorrect switch-profile associations can result in policies being deployed to the wrong leaf switches or not being applied where expected.<\/span><\/p>\n<h3><b>Question 359<\/b><\/h3>\n<p><b>Which ACI component provides the physical connectivity for servers and other endpoints?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Spine switch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">APIC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Leaf switch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">External routing table<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Leaf switches provide the physical connectivity layer for servers, appliances, and other endpoints in an ACI fabric. They connect directly to endpoints and enforce the relevant policy before forwarding traffic through the spine layer. Spine switches provide transit between leaves, APIC provides centralized management and policy orchestration, and an external routing table is not a physical connectivity component. When an endpoint cannot communicate, administrators should inspect the leaf interface status, access-policy configuration, EPG attachment, VLAN encapsulation, and endpoint learning information. Correct leaf configuration is essential because endpoint traffic enters and exits the ACI fabric through leaf switches.<\/span><\/p>\n<h3><b>Question 360<\/b><\/h3>\n<p><b>Which ACI mechanism allows a provider EPG to expose services to a consumer EPG through defined policy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Contract<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Physical domain<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Interface selector<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A contract allows a provider EPG to expose permitted services to a consumer EPG through defined policy. The contract contains subjects and filters that specify the traffic that should be allowed. VLAN pools provide encapsulation resources, physical domains associate EPGs with physical connectivity, and interface selectors identify interfaces. A provider-consumer relationship must be correctly established for the contract to take effect. When a consumer cannot access a provider service, administrators should verify the EPG roles, contract association, subject configuration, filter entries, VRF relationship, and endpoint reachability. This structured policy model allows service access to be controlled without configuring individual endpoint ACLs.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP Data Center 300-620 Exam Dumps and Practice Test Dumps. &nbsp; Question 341 Which ACI component is responsible for providing the default gateway function for endpoints within a bridge domain? Contract VLAN pool Bridge-domain subnet Interface selector Correct Answer: 3 Explanation A bridge-domain subnet can provide the default gateway address used by [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21250"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=21250"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21250\/revisions"}],"predecessor-version":[{"id":21251,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21250\/revisions\/21251"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=21250"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=21250"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=21250"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}